Remote job
Compliance and Security Lead
Job details
About this role
Role overview This Compliance and Security Lead owns the end-to-end security compliance program for an AI customer service platform, spanning audits, customer trust, vendor risk, vulnerability management, and the underlying control framework. The mandate is to take a program historically run manually and push it toward automation and year-round audit readiness, while serving as the external face of the security posture in customer and prospect conversations. The role also tracks emerging agentic AI regulation, starting with the AIUC framework, and translates movement into platform-team requirements.
Responsibilities - Own security audits end-to-end across AIUC, PCI, and SOC 2, including evidence collection, control mapping, and auditor coordination through a compliance automation platform. - Drive vulnerability management at scale, taking a large backlog through prioritization, ownership, and SLAs for critical findings. - Run vendor security and privacy reviews as a standing process with clear SLAs rather than ad-hoc scrambles. - Maintain the control framework and its documentation, including policies, data handling, retention, and evidence controls actually operate. - Serve as the point of contact for customer security, privacy, and legal teams, and as the internal source of truth on compliance status. - Track regulatory and framework movement relevant to agentic AI and translate it into concrete internal requirements for the platform team.
Requirements - Deep audit experience across SOC 1, SOC 2, PCI DSS, NIST frameworks, AICPA standards, and PII/privacy requirements, including end-to-end evidence collection, control mapping, and auditor coordination. - Direct experience working with major audit firms, and a track record of inheriting manual compliance programs and automating them using platforms like Drata. - Vulnerability management at scale, taking a large backlog of findings and driving it down through prioritization and ownership. - Customer-facing confidence owning security posture conversations with enterprise prospects, plus experience owning RFP security sections, questionnaires, and trust centers. - Strong technical literacy in modern infrastructure, Kubernetes, Terraform, and CI/CD, enough to engage credibly with engineers and auditors. - Strong policy and control writing skills and a bias toward process, documentation, and tooling that outlast any individual owner.
Nice to have - Background tracking regulatory and framework movement in agentic AI governance, including AIUC and emerging frameworks.
Benefits and work setup - Remote-first environment with in-person options at a local hub and flexible scheduling. - Unlimited vacation, extended health, dental, vision, travel, and life insurance, plus a wellness account and an employee and family assistance plan. - Learning and development budget, work-from-home budget, and access to cutting-edge AI tools and large language models.