Remote job
Security & Compliance Manager
Job details
About this role
Role overview The Security & Compliance Manager takes ownership of an established information security, privacy, and data governance program within a cloud-first organization. Reporting to senior leadership, the role partners with engineering, product, operations, legal, and administrative functions to keep systems, processes, and policies aligned with evolving regulatory and security requirements.
Responsibilities - Maintain SOC 2 Type II compliance, including day-to-day control operation, evidence collection, and annual audit readiness. - Lead the ISO 27001 certification effort from gap assessment through certification and ongoing surveillance audits. - Advise leadership as the primary strategist on security, privacy, and compliance matters, and oversee additional frameworks such as GDPR and CCPA. - Conduct security risk assessments, manage incident response processes, and drive remediation across the business. - Define enterprise data governance standards, including data classification, retention, and lifecycle management. - Administer Vanta and related GRC tooling to automate compliance monitoring, continuous control testing, and audit workflows. - Lead company-wide security awareness initiatives and monitor emerging threats, regulations, and industry best practices.
Requirements - Three to five years of experience in information security, data privacy, governance, compliance, or risk management. - Direct experience maintaining SOC 2 Type II and leading or supporting an ISO 27001 certification in a SaaS or cloud-first environment. - Hands-on experience with Vanta or a comparable GRC platform such as Drata, Secureframe, or Sprinto. - Working knowledge of GDPR, CCPA, and other applicable privacy regulations. - Familiarity with cloud infrastructure, SaaS environments, identity and access management, and core security controls. - Strong communication skills with the ability to explain technical concepts to non-technical audiences and influence cross-functional stakeholders. - Bachelor's degree in Information Security, Computer Science, Information Systems, Business, Legal Studies, or a related field, or equivalent practical experience.
Nice to have - Professional certifications such as CIPP/US, CIPM, CISSP, CISM, or CRISC. - Experience in a high-growth SaaS or technology startup environment. - Knowledge of privacy-by-design principles.
Benefits and work setup - Remote workplace with flexible work schedules. - Competitive compensation with a salary range of $140,000 to $170,000 plus bonus. - Paid time off and paid parental leave. - Health, dental, vision, and long-term disability insurance. - 401(k) plan and professional development opportunities.