CareerPlanGet AI match score →

Risk and Compliance Lead

Foster City, CA💼 Full-time🗓 2026-07-10 → 2026-07-31

Core

Lead the end-to-end security GRC function, owning certification and audit programs (SOC 2, ISO 27001, ISO 42001) and the master security risk register for an AI-native software platform.

Role type

Senior IC Risk and Compliance Lead

Builds

Security certifications, audit artifacts, and continuous compliance monitoring for an agentic software creation platform.

Domain

Cybersecurity, Governance, Risk, and Compliance (GRC) for AI-native developer tools.

Deliverable

Production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work

Required skills

SOC 2 and ISO 27001 certification ownership, security risk register management, ISMS/SSP documentation authoring, GRC automation platform usage, external auditor management, technical control evidence review, GDPR/privacy fundamentals.

Preferred skills

ISO 42001 scoping, FedRAMP experience, developer tools/AI/ML product background, CISA/CISSP/ISO 27001 Lead Auditor certifications, early-stage program setup.

Technologies

Anecdotes, Vanta, Drata, NIST CSF, SOC 2, ISO 27001, ISO 42001, FedRAMP.

Responsibilities

Own the end-to-end certification roadmap including scoping, gap assessments, remediation, and audit execution; manage relationships with external auditors and drive the annual audit calendar; own and maintain the company's master security risk register including risk identification, scoring, and reporting; build and maintain continuous compliance monitoring; own core audit artifacts including ISMS documentation and Statements of Applicability; run regular audits and readiness assessments and track remediation of findings.

Seniority

Senior, hands-on IC

Sourced via ashby · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.
Apply on Ashby ↗