Security Compliance Manager
Last checked active on Aug 27, 2026.
Position Overview
Job Description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security Compliance Manager based in the United States.
This is a senior, hands-on leadership role responsible for owning and strengthening the organization’s security compliance and GRC function end-to-end. You’ll shape the compliance strategy across major security, privacy, regulatory, and industry frameworks while keeping the business continuously audit- and customer-ready. The role combines strategic program ownership with close collaboration across engineering, IT, product, security, and legal teams. You’ll serve as a trusted point of contact for auditors, regulators, customers, and senior leadership, translating complex risks into clear business implications. You’ll also drive a major FedRAMP initiative, improve control efficiency, and build scalable processes that support a rapidly growing technology environment. As the function develops, you’ll lead and mentor team members while expanding the organization’s compliance capabilities. This remote-first opportunity is ideal for an experienced GRC professional who thrives on ownership, technical fluency, and meaningful business impact.
Accountabilities:
- Own the strategy, planning, design, and ongoing operation of the security compliance and GRC program across SOC 2 Type II, PCI DSS Level 1 Service Provider, ISO 27001, GDPR, CCPA, and DORA.
- Lead the organization’s FedRAMP authorization efforts, coordinating NIST SP 800-53 control implementation, third-party assessment activities, and continuous monitoring across engineering and IT.
- Serve as the primary point of contact for auditors, regulators, industry stakeholders, and other external reviewers, ensuring assessments and compliance engagements are well planned and successfully executed.
- Partner closely with engineering, IT, product, security, and legal teams to implement effective controls and resolve compliance and risk issues.
- Present compliance objectives, program scope, findings, risks, and outcomes to senior leadership and board-level stakeholders in a clear, concise, and business-focused manner.
- Own the control framework by rationalizing overlapping requirements across standards and maintaining an efficient, coherent, and evidence-focused control environment.
- Manage the security policy and standards library, ensuring documentation remains accurate, relevant, and aligned with regulatory and business requirements.
- Own the organizational risk picture, including the risk register, risk quantification, reporting cadence, remediation tracking, and validation of risk treatment decisions.
- Lead the customer assurance and trust program, including security questionnaires, attestations, and trust documentation, helping ensure security reviews support rather than delay commercial opportunities.
- Coordinate evidence collection, security scans, artifacts, and documentation while identifying opportunities to automate and streamline compliance processes.
- Lead continuous improvement initiatives based on findings from regulators, internal and external reviews, quality assessments, and maturity evaluations.
- Develop sufficient technical and product fluency to understand platform architecture, evaluate control effectiveness, and collaborate with engineering and product teams as a trusted peer.
- Identify creative and scalable approaches to compliance that improve consistency, efficiency, and automation.
- Produce executive-ready documentation, presentations, meeting materials, and reporting for internal and external stakeholders.
- Lead, mentor, and develop the compliance team, including a Security Compliance Analyst, while establishing priorities and scaling the function as regulatory and business requirements evolve.
- 7+ years of experience in security compliance, GRC, audit, or a closely related field, including end-to-end ownership of audit or certification programs.
- Demonstrated experience managing programs such as SOC 2, PCI DSS, and/or ISO 27001 from planning through assessment and ongoing compliance.
- Deep knowledge of security and privacy frameworks, including PCI DSS, SOC 2, ISO 27001, GDPR, CCPA, and DORA.
- Familiarity with broader control frameworks such as NIST Cybersecurity Framework and CIS Controls.
- Strong technical and product aptitude, with the ability to understand complex technology environments and confidently collaborate with engineering and product teams.
- Ability to connect technical controls, security risks, and compliance requirements to real-world business outcomes.
- Exceptional written and verbal communication skills, including the ability to create executive-ready documentation and communicate credibly with auditors, regulators, leadership, and customers.
- Experience working in a fast-paced, high-growth environment; fintech, payments, or similarly regulated technology environments are strongly preferred.
- Strong program management, organizational, analytical, and problem-solving capabilities with a focus on continuous improvement.
- Ability to operate effectively as a strategic leader, cross-functional partner, and hands-on individual contributor depending on the situation.
- Demonstrated experience leading, mentoring, or managing team members, or clear readiness to take ownership of people leadership responsibilities.
- Willingness and ability to travel when required.
- Bonus: Direct experience operating a PCI DSS Level 1 Service Provider compliance program.
- Bonus: Hands-on experience with DORA and operational resilience requirements.
- Bonus: Familiarity with GRC and security tooling, including compliance automation platforms such as Vanta, HRIS platforms such as Rippling, and macOS environments.
- Competitive Compensation: Generous compensation package combining cash and equity.
- Equity Flexibility: Early exercise available for all options, including pre-vested options.
- Remote-First Work: Work from anywhere with a globally distributed, remote-first culture.
- Time Off: Flexible paid time off plus a year-end company break.
- Health Coverage: Health, dental, and vision insurance for employees and dependents in the US and Canada.
- Retirement: 4% 401(k) / RRSP matching for eligible employees in the US and Canada.
- Technology: MacBook Pro delivered directly to your home.
- Home Office: One-time stipend to help equip your workspace with items such as a desk, chair, monitor, and other essentials.
- Meals: Monthly meal stipend.
- Social Connection: Monthly stipend to support social meet-ups.
- Wellness: Annual health and wellness stipend.
- Learning: Annual learning and professional development stipend.
- Career Growth: Opportunity to help build and scale a critical security compliance function within a high-growth technology environment.
Requirements
Benefits
Practice Area
Position
Mid
Industry
Legal
Applicant Location Requirements
Applicants must be located in: United States
Application Deadline
November 25, 2026
Employment Type
Full time
Work Arrangement
Remote/Telecommute Position
Application to Jobgether
Sign in to apply
See the complete description, requirements, and every detail of this role, then apply. Everything here is included with your account.
Already registered? Sign in to continue