
Compliance and Security Lead
Posted Aug 6

Posted Aug 6
This is a fully remote position, open to applicants in Canada.
• Take charge of Ada's security compliance program from start to finish, which includes audits, customer trust, vendor risk, vulnerability management, and the control framework.
• Lead security audits such as AIUC, PCI, and SOC 2 through Drata, managing evidence collection, control mapping, and coordination with auditors.
• Streamline evidence collection and control monitoring processes to ensure the team is prepared for audits throughout the year.
• Manage the security and compliance components of customer RFPs and security questionnaires.
• Oversee the SafeBase trust center and assist with customer security assessments.
• Lead vulnerability management efforts, focusing on prioritizing findings, designating ownership, and establishing SLAs for critical issues.
• Conduct vendor security and privacy evaluations as a regular procedure.
• Keep policies, data handling and retention documentation, control frameworks, and operational evidence up to date.
• Act as the primary contact for customer security, privacy, and legal teams, serving as the internal authority on compliance status.
• Monitor developments in agentic AI regulations and frameworks, starting with AIUC, and convert them into platform requirements.
• Assume responsibility for compliance tasks distributed across the team, ensuring sustainability.
• Within the first 90 days, manage the AIUC audit, deliver a current-state gap assessment, and create a repeatable process for RFP security responses.
• Extensive audit experience with SOC 1, SOC 2, PCI DSS, NIST frameworks, AICPA standards, and PII/privacy regulations.
• Proven experience in managing audits from beginning to end, including evidence collection, control mapping, and auditor coordination.
• Familiarity with major audit firms, such as Deloitte or EY, through direct collaboration.
• Experience in automating manual compliance programs using tools, processes, and repeatability, particularly with Drata or similar platforms.
• Track record of managing vulnerability programs at scale and effectively reducing large backlogs through prioritization, ownership, and established processes.
• Comfort in engaging in customer-facing discussions regarding security posture with enterprise clients.
• Understanding of contemporary infrastructure, including Kubernetes, Terraform, and CI/CD, enabling effective collaboration with engineers and auditors.
• Experience in overseeing RFP security sections, customer security questionnaires, and trust centers like SafeBase.
• Strong writing capabilities for drafting policies, control documentation, and data handling standards.
• Proactive approach to program ownership with a focus on processes, documentation, and tools.
• Ability to keep abreast of regulatory and framework changes related to agentic AI governance; a keen interest in AIUC and emerging frameworks is a significant advantage.
• An engineering background is preferred but not mandatory.
• Unlimited Vacation: Recharge when you need to.
• Comprehensive Benefits: Extended health coverage, dental, vision, travel, and life insurance.
• Wellness Account: Empowering you to invest in your overall well-being and lifestyle.
• Employee & Family Assistance Plan: Resources to support you and your loved ones.
• Flexible Work Schedule: Balance your work and personal life.
• Remote-First, In-Person Friendly: Options to work from home or at our local hub.
• Learning & Development Budget: Invest in your long-term growth goals and skills.
• Work from Home Budget: Equipping you with the tools and support for a seamless remote work experience.
• Access to Cutting-Edge AI Tools: Work with the best AI tech stack in the industry.
• Hands-On with LLMs: Enhance your expertise in leveraging large language models.
• A Thriving Industry: Join the forefront of innovation in AI, shaping the future of technology.
OCHIN, Inc.
Dynanet Corporation
Solutions for Information Design, Inc.
Fuze Health
Get handpicked remote jobs straight to your inbox weekly.