Security Compliance Manager

JobgetherVerified source: this listing comes from the employer's official hiring system or a verified company · United States · Remote
Listed via Lever
Posted Aug 26, 2026 · Apply by Nov 25
Recently checked

Last checked active on Aug 27, 2026.

Position Overview

Location: United States United States flag
Compensation: Not disclosed
Position: Mid
Type: Job
Employment: Full time
Practice Area: Compliance
Remote: Yes
Deadline: Nov 25, 2026

Job Description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security Compliance Manager based in the United States.

This is a senior, hands-on leadership role responsible for owning and strengthening the organization’s security compliance and GRC function end-to-end. You’ll shape the compliance strategy across major security, privacy, regulatory, and industry frameworks while keeping the business continuously audit- and customer-ready. The role combines strategic program ownership with close collaboration across engineering, IT, product, security, and legal teams. You’ll serve as a trusted point of contact for auditors, regulators, customers, and senior leadership, translating complex risks into clear business implications. You’ll also drive a major FedRAMP initiative, improve control efficiency, and build scalable processes that support a rapidly growing technology environment. As the function develops, you’ll lead and mentor team members while expanding the organization’s compliance capabilities. This remote-first opportunity is ideal for an experienced GRC professional who thrives on ownership, technical fluency, and meaningful business impact.

Accountabilities:

    • Own the strategy, planning, design, and ongoing operation of the security compliance and GRC program across SOC 2 Type II, PCI DSS Level 1 Service Provider, ISO 27001, GDPR, CCPA, and DORA.
    • Lead the organization’s FedRAMP authorization efforts, coordinating NIST SP 800-53 control implementation, third-party assessment activities, and continuous monitoring across engineering and IT.
    • Serve as the primary point of contact for auditors, regulators, industry stakeholders, and other external reviewers, ensuring assessments and compliance engagements are well planned and successfully executed.
    • Partner closely with engineering, IT, product, security, and legal teams to implement effective controls and resolve compliance and risk issues.
    • Present compliance objectives, program scope, findings, risks, and outcomes to senior leadership and board-level stakeholders in a clear, concise, and business-focused manner.
    • Own the control framework by rationalizing overlapping requirements across standards and maintaining an efficient, coherent, and evidence-focused control environment.
    • Manage the security policy and standards library, ensuring documentation remains accurate, relevant, and aligned with regulatory and business requirements.
    • Own the organizational risk picture, including the risk register, risk quantification, reporting cadence, remediation tracking, and validation of risk treatment decisions.
    • Lead the customer assurance and trust program, including security questionnaires, attestations, and trust documentation, helping ensure security reviews support rather than delay commercial opportunities.
    • Coordinate evidence collection, security scans, artifacts, and documentation while identifying opportunities to automate and streamline compliance processes.
    • Lead continuous improvement initiatives based on findings from regulators, internal and external reviews, quality assessments, and maturity evaluations.
    • Develop sufficient technical and product fluency to understand platform architecture, evaluate control effectiveness, and collaborate with engineering and product teams as a trusted peer.
    • Identify creative and scalable approaches to compliance that improve consistency, efficiency, and automation.
    • Produce executive-ready documentation, presentations, meeting materials, and reporting for internal and external stakeholders.
    • Lead, mentor, and develop the compliance team, including a Security Compliance Analyst, while establishing priorities and scaling the function as regulatory and business requirements evolve.
    • Requirements

      • 7+ years of experience in security compliance, GRC, audit, or a closely related field, including end-to-end ownership of audit or certification programs.
      • Demonstrated experience managing programs such as SOC 2, PCI DSS, and/or ISO 27001 from planning through assessment and ongoing compliance.
      • Deep knowledge of security and privacy frameworks, including PCI DSS, SOC 2, ISO 27001, GDPR, CCPA, and DORA.
      • Familiarity with broader control frameworks such as NIST Cybersecurity Framework and CIS Controls.
      • Strong technical and product aptitude, with the ability to understand complex technology environments and confidently collaborate with engineering and product teams.
      • Ability to connect technical controls, security risks, and compliance requirements to real-world business outcomes.
      • Exceptional written and verbal communication skills, including the ability to create executive-ready documentation and communicate credibly with auditors, regulators, leadership, and customers.
      • Experience working in a fast-paced, high-growth environment; fintech, payments, or similarly regulated technology environments are strongly preferred.
      • Strong program management, organizational, analytical, and problem-solving capabilities with a focus on continuous improvement.
      • Ability to operate effectively as a strategic leader, cross-functional partner, and hands-on individual contributor depending on the situation.
      • Demonstrated experience leading, mentoring, or managing team members, or clear readiness to take ownership of people leadership responsibilities.
      • Willingness and ability to travel when required.
      • Bonus: Direct experience operating a PCI DSS Level 1 Service Provider compliance program.
      • Bonus: Hands-on experience with DORA and operational resilience requirements.
      • Bonus: Familiarity with GRC and security tooling, including compliance automation platforms such as Vanta, HRIS platforms such as Rippling, and macOS environments.
      • Benefits

        • Competitive Compensation: Generous compensation package combining cash and equity.
        • Equity Flexibility: Early exercise available for all options, including pre-vested options.
        • Remote-First Work: Work from anywhere with a globally distributed, remote-first culture.
        • Time Off: Flexible paid time off plus a year-end company break.
        • Health Coverage: Health, dental, and vision insurance for employees and dependents in the US and Canada.
        • Retirement: 4% 401(k) / RRSP matching for eligible employees in the US and Canada.
        • Technology: MacBook Pro delivered directly to your home.
        • Home Office: One-time stipend to help equip your workspace with items such as a desk, chair, monitor, and other essentials.
        • Meals: Monthly meal stipend.
        • Social Connection: Monthly stipend to support social meet-ups.
        • Wellness: Annual health and wellness stipend.
        • Learning: Annual learning and professional development stipend.
        • Career Growth: Opportunity to help build and scale a critical security compliance function within a high-growth technology environment.
How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best!  Why Apply Through Jobgether?    Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.     #LI-CL1

Practice Area

Position

Mid

Industry

Legal

Applicant Location Requirements

Applicants must be located in: United States

Application Deadline

November 25, 2026

Employment Type

Full time

Work Arrangement

Remote/Telecommute Position

Application to Jobgether

Sign in to apply

See the complete description, requirements, and every detail of this role, then apply. Everything here is included with your account.

Apply to this job and future roles across 90 countries
Human CV / resume reviews from real experts
Application tracker, saved roles, and company watchlist
Return to this job the moment you are signed in
Report this job
Thank you. Our team will review this report.

Tell us if this listing is inaccurate, closed, fake, duplicated, or unsafe. You do not need an account to report it.