
Compliance Manager
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
• Take charge of Sourcegraph’s governance, risk, and compliance program, primarily focusing on compliance.
• Collaborate across departments including Security, Engineering, IT, Legal, People, Sales, and others.
• Continuously develop and enhance the compliance program, covering SOC 2 and ISO 27001 certifications.
• Prepare Sourcegraph for additional compliance frameworks as the organization expands.
• Design and customize controls, gather evidence, train internal teams, engage with auditors, manage remediation, and ensure follow-up actions are completed.
• Cultivate relationships with key stakeholders and gain insights into the existing ISMS, risk register, controls, certifications, audit processes, and areas of focus.
• Oversee SOC 2 and ISO 27001 audit activities, which include control testing, evidence collection, stakeholder coordination, auditor requests, findings, and remediation efforts.
• Maintain the risk register, ISMS processes, policies, and compliance documentation.
• Guide internal teams on compliance obligations and offer practical compliance advice.
• Assist with customer-facing compliance tasks, such as security questionnaires and compliance inquiries.
• Lead audits or significant certification milestones.
• Manage the GRC operational rhythm, which includes ISMS meetings, risk management activities, control reviews, documentation updates, and audit preparations.
• Create a forward-thinking compliance roadmap.
• Identify control deficiencies, evaluate risks, propose solutions, and drive remediation efforts.
• Implement automation, AI, or process enhancements to minimize manual compliance efforts.
• Minimum of 5 years of experience in governance, risk, compliance, information security compliance, or a related position.
• Proven track record of end-to-end ownership of SOC 2 and ISO 27001 programs, preferably in a SaaS, tech startup, or similarly dynamic environment.
• Experience in managing external audits and certification processes, including audit preparation, evidence gathering, control testing, stakeholder training, auditor engagement, remediation, and follow-up.
• Strong knowledge of risk management, control design, ISMS governance, and compliance program operations.
• Experience tailoring compliance controls to fit an organization's actual environment.
• Familiarity with cloud technology environments and security and compliance implications for a distributed or remote workforce.
• Excellent project management and organizational capabilities.
• Outstanding written and verbal communication skills.
• Proactive approach and willingness to personally carry out compliance tasks.
• Interest in AI, automation, and new technologies.
• Working hours should overlap with GMT-3 for at least 20 hours each week.
• Nice-to-have: Experience with GDPR, HIPAA, HITRUST, FedRAMP, FISMA, PCI DSS, or related standards.
• Nice-to-have: Background in supporting security questionnaires, customer assurance processes, or sales-related compliance activities.
• Nice-to-have: Familiarity with GRC platforms, compliance automation tools, or internal automation for evidence collection and control monitoring.
• Nice-to-have: Possession of CISA, CISSP, ISO 27001 Lead Implementer or Lead Auditor, CRISC, or similar certifications.
• Significant equity opportunities.
• Generous perks and benefits package.
• Competitive cash compensation.
Radian Generation
Incora
Arclin
Arclin
Get handpicked remote jobs straight to your inbox weekly.