Compliance Engineering Lead

JobgetherVerified source: this listing comes from the employer's official hiring system or a verified company · United States · Remote
Listed via Lever
Posted Aug 26, 2026 · Apply by Nov 25
Recently checked

Last checked active on Aug 27, 2026.

Position Overview

Location: United States United States flag
Compensation: Not disclosed
Position: Mid
Type: Job
Employment: Full time
Practice Area: Compliance
Remote: Yes
Deadline: Nov 25, 2026

Job Description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Compliance Engineering Lead based in United States.

This is a foundational opportunity to build and lead a modern compliance function as an engineered system rather than a collection of manual processes. You will own the compliance program end to end, with direct responsibility for SOC 2 Type II and the organization’s path to ISO 27001 certification. The role combines security, engineering, risk management, automation, and customer assurance in a high-growth environment. You’ll build continuous evidence pipelines, automate control monitoring, and strengthen vendor and risk-management programs. You’ll also shape the organization’s approach to AI assurance and emerging regulatory frameworks. Reporting directly to the CISO, you’ll have significant autonomy and the opportunity to hire and lead an initial team member while defining the future of GRC.

Accountabilities

    • Own the SOC 2 Type II program end to end, including audit scope, observation periods, auditor relationships, evidence collection, controls, findings, and the final customer-facing report.
    • Lead the organization through ISO 27001 certification, including defining the scope and ISMS, conducting gap assessments and internal audits, preparing teams, achieving certification, and maintaining an effective management system afterward.
    • Build a continuous and automated evidence-collection infrastructure using APIs and systems of record such as cloud platforms, source-control systems, identity providers, MDM, and ticketing tools.
    • Develop scheduled control tests and monitoring that identify configuration drift or control failures quickly, replacing recurring manual compliance work with reliable automation.
    • Own and mature enterprise risk and third-party vendor risk programs, including risk registers, vendor tiering, assessments, reviews, renewal cadences, and executive reporting.
    • Lead the customer-facing security assurance function, including the trust portal and security documentation library, with the goal of proactively addressing enterprise customer requirements and reducing questionnaire volume.
    • Evaluate and shape the organization’s AI assurance strategy, assessing frameworks and regulations such as ISO/IEC 42001, AI assurance standards, the EU AI Act, and the NIST AI Risk Management Framework.
    • Partner closely with Security, Engineering, Legal, and Go-to-Market teams to identify and resolve compliance gaps across organizational boundaries.
    • Own the compliance technology strategy, evaluating existing GRC platforms and determining where purchasing, integrating, or building internal capabilities provides the greatest leverage.
    • Hire, develop, and lead an initial customer-trust team member focused on security questionnaires, RFPs, and contract security reviews.
    • Establish clear ownership, documentation, service levels, and repeatable processes so compliance becomes an embedded operational capability rather than an audit-time exercise.
    • Requirements:

      • Proven SOC 2 Type II ownership: personally accountable for at least two complete SOC 2 Type II cycles, including auditor management, scoping, evidence, controls, and remediation of findings.
      • Strong ISO 27001 expertise: experience taking an organization through certification or managing an ISMS through surveillance audits, with a practical understanding of how to make the system operationally effective.
      • Compliance automation experience: comfortable building and maintaining automations against APIs and operational systems; you naturally look for opportunities to replace repetitive manual processes with scheduled, reliable workflows.
      • Hands-on experience with GRC and compliance platforms such as Drata, Vanta, or comparable solutions, combined with sound judgment about their strengths and limitations.
      • Strong risk prioritization skills, with the ability to distinguish meaningful security and compliance risks from lower-value administrative or audit preferences.
      • Excellent written and verbal communication skills, with the ability to produce clear materials for auditors, enterprise security teams, engineers, and executive stakeholders.
      • A strong ownership mindset and willingness to solve ambiguous, cross-functional problems at the intersection of Security, Engineering, Legal, and Go-to-Market.
      • Experience working effectively in a remote, fast-moving environment where priorities evolve and processes may need to be created from the ground up.
      • Ability to balance strategic program ownership with hands-on execution, including automation, control testing, evidence management, and operational improvements.
      • Preferred: exposure to AI governance frameworks such as ISO/IEC 42001, NIST AI RMF, or the EU AI Act; experience within a security vendor or highly scrutinized enterprise environment; contract security review experience; or experience building compliance automation internally.
      • Benefits:

        • Market-competitive salary bands.
        • Meaningful equity program.
        • Comprehensive health benefits for employees and their families, with 99% coverage.
        • Flexible time off, paid holidays, and a winter shutdown for rest and recharge.
        • Paid parental leave.
        • Remote-first working environment.
        • Quarterly team off-sites.
        • An ownership-driven culture emphasizing excellence, urgency, rigorous thinking, trust, collaboration, and customer focus.
        • Significant autonomy and the opportunity to shape a foundational compliance and GRC function.
How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best!  Why Apply Through Jobgether?    Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.     #LI-CL1

Practice Area

Position

Mid

Industry

Legal

Applicant Location Requirements

Applicants must be located in: United States

Application Deadline

November 25, 2026

Employment Type

Full time

Work Arrangement

Remote/Telecommute Position

Application to Jobgether

Sign in to apply

See the complete description, requirements, and every detail of this role, then apply. Everything here is included with your account.

Apply to this job and future roles across 90 countries
Human CV / resume reviews from real experts
Application tracker, saved roles, and company watchlist
Return to this job the moment you are signed in
Report this job
Thank you. Our team will review this report.

Tell us if this listing is inaccurate, closed, fake, duplicated, or unsafe. You do not need an account to report it.