
Compliance and Documentation Lead
Posted 23 hours ago

Posted 23 hours ago
This is a fully remote position, open to applicants in United States.
• Take ownership of customer and prospect privacy risk assessments, DPIAs, and transfer impact assessments from start to finish.
• Act as the technical expert during customer privacy evaluations and vendor due diligence discussions.
• Develop and uphold data flow diagrams and records of processing for hosted, dedicated, and self-hosted environments.
• Manage operations related to retention, deletion, DSAR, consent, opt-out, de-identification, and redaction controls.
• Oversee subprocessor and vendor privacy assessments along with DPA documentation.
• Convert GDPR, UK GDPR, CCPA/CPRA, US state privacy regulations, and new AI legislation into practical requirements.
• Collaborate with Legal on DPAs, SCCs, transfer mechanisms, and residency commitments.
• Maintain audit evidence for SOC 2, ISO 27001, and PCI DSS while serving as the primary auditor contact.
• Keep cross-framework control mappings and evidence crosswalks updated.
• Manage security questionnaires and the security components of RFPs.
• Work alongside Security Engineering to automate and repurpose evidence.
• Draft and oversee internal policies and standards throughout their lifecycle.
• Curate content for the Trust Center, including AI Safety statements, Model Cards, Privacy Policy material, and deployment/self-hosted documentation.
• Manage document versioning, review processes, and ensure traceability to internal sources of truth.
• Design operational auditing and remediation workflows.
• Conduct compliance and privacy training and enablement for Sales Engineering.
• Significant experience in privacy operations, GRC, security compliance, or technical compliance documentation.
• Proven track record of conducting privacy assessments or managing an audit cycle from beginning to end and taking ownership of the results.
• Outstanding technical and compliance writing skills.
• Experience overseeing compliance operational systems at scale, such as data maps, DSAR workflows, evidence collection, answer libraries, policy sets, or similar tools.
• Hands-on experience in at least one formal SOC 2, ISO 27001, or PCI DSS audit, responsible for producing and defending evidence.
• Practical experience with GDPR and CCPA/CPRA.
• Up-to-date knowledge of emerging AI regulations.
• Ability to interpret architecture diagrams, navigate cloud-infrastructure data flows, comprehend logs and retention settings, and identify compliance gaps.
• Capacity to engage directly with Fortune 500 privacy teams, security reviewers, and DPOs.
• Startup-friendly judgment and comfort in making defensible decisions in uncertain situations.
• A tendency towards developing systems and templates.
• Certifications such as CIPM, CIPT, CIPP/E, CISA, or ISO 27001 Lead Implementer/Auditor are advantageous.
• Familiarity with compliance automation tools like Vanta, Drata, or similar trust center software is a plus.
• Knowledge of NIST AI RMF, ISO/IEC 42001, and the EU AI Act is desirable.
• Experience with ML/AI data pipelines and governance of training data is beneficial.
• Proficiency in SQL, basic scripting, or AI and agentic tools is a plus.
• Exposure to HIPAA or FedRAMP regulations is an added advantage.
• Equity
• Eligibility for bonuses
• 10% annual bonus
• Remote working opportunities
• Flexible, AI-first work environment
• Collaboration with a global team
• Opportunities for professional development through ongoing learning and experimentation with AI tools
Globalli
Arclin
Stripe
Parexel
Get handpicked remote jobs straight to your inbox weekly.