
Group Security & Compliance Manager
Posted Jul 25

Posted Jul 25
This is a fully remote position, open to applicants in Argentina, +6 more countries.
β’ Lead customer security evaluations, RFPs, RFIs, and questionnaires, providing accurate and comprehensive responses swiftly to ensure deals progress.
β’ Establish and manage a customer-facing trust portal (such as SafeBase, Vanta, Drata, or similar), featuring a specific section for AI/ML.
β’ Oversee the management of the SOC 2 Type II program, facilitating audits across portfolio companies (including Sparkrock's Type II transition and CXT scoping), coordinating documentation with the Senior Group Security Engineer, and nurturing auditor relationships.
β’ Create and sustain security policies and documentation, which includes Data Processing Agreements (DPAs), sub-processor lists, and incident communication templates.
β’ Take charge of AI compliance and trust, encompassing AI questionnaire responses, management of AI sub-processors, tracking frameworks (EU AI Act, ISO 42001, NIST AI RMF), AI usage disclosures, AI acceptable use policies, and AI incident communication playbooks.
β’ Conduct third-party vendor security assessments and manage renewals.
β’ Develop and deliver internal security awareness training, as well as onboard customers through the necessary security configurations.
β’ Compose and coordinate customer-facing incident communications, including breach and incident notifications alongside legal and engineering teams.
β’ Minimum of 6 years in security GRC, customer trust, or SaaS compliance.
β’ Exceptional verbal and written English skills. Poised, eloquent, and credible during live interactions with enterprise customers and third parties β this individual represents the organization externally.
β’ Experience with SOC 2 audits as a primary contact (Type II strongly preferred).
β’ Fundamental understanding of cloud security concepts β able to interpret and explain technical findings, but not to produce them.
β’ Awareness of the AI compliance landscape with a readiness to take ownership of it.
β’ Relevant certifications such as CISSP, CISA, or CIPP/E; familiarity with Vanta, Drata, or SafeBase.
β’ Background in PE-backed or multi-portfolio environments.
β’ Familiarity with ISO 42001, NIST AI RMF, and awareness of the EU AI Act.
β’ We operate fully remotely and globally. Enjoy your best life wherever you are, without missing career opportunities.
β’ Flexible working hours. We work asynchronously and value results over when you're online, ensuring you're available for our customers.
β’ Committed to your growth with regular and meaningful feedback, support for achieving your personal career objectives, and access to cutting-edge tools, playbooks, and technology to enhance your experience.
β’ Opportunities to connect with thought leaders in the field and participate in webinars on the latest technology trends.
β’ Stipend provided to help create your ideal home office.
β’ Emphasis on culture: engage in coffee chats, happy hours, cooking classes, book clubs, and more!
CVS Health
FreedomCare
Northrop Grumman
Get handpicked remote jobs straight to your inbox weekly.