
Head of Compliance
Posted Jul 27

Posted Jul 27
This is a fully remote position, open to applicants in California, +1 more state.
β’ Take full ownership of Treeline's compliance program from start to finish β including controls, evidence gathering, Vanta/Drata upkeep, and auditor coordination β guiding the process from gap assessment to certification.
β’ Develop and sustain security policies, risk registers, vendor evaluations, and ISMS documentation from the ground up.
β’ Collaborate with engineering, GTM, operations, and our portfolio companies to integrate security and compliance into Treeline's development and delivery processes.
β’ Act as the primary internal contact for all compliance-related inquiries, customer security questionnaires, and audit requests.
β’ Lead SOC 2 and ISO 27001 readiness initiatives from beginning to end β including scoping, gap analysis, control implementation, and audit preparation.
β’ Manage the relationship with audit partners and organize penetration testing as part of a comprehensive compliance service package.
β’ Work at every level: conduct technical deep-dives with security engineers and present roadmaps to founders and key stakeholders.
β’ Independently manage multiple simultaneous customer engagements β ensuring nothing falls through the cracks and everything stays on schedule.
β’ Contribute to the development and expansion of Treeline's Compliance-as-a-Service offering into a repeatable, revenue-generating product line.
β’ Establish the frameworks, scoping standards, and customer-facing documents that enhance compliance delivery scalability β ensuring that every engagement improves, not just increases in size.
β’ Relay insights gained in the field directly back into the platform β your customer interactions influence product decisions, rather than simply following them.
β’ 5β8+ years of experience in compliance, security, or risk management β with significant tenure at or alongside an audit or advisory firm (SOC 2 audit shop, Big 4 risk practice, compliance consultancy).
β’ Personally manage SOC 2 and ISO readiness projects from inception to completion, not merely providing support β you anticipate auditor inquiries ahead of time.
β’ Practical experience in creating compliance frameworks from scratch, rather than just maintaining existing programs.
β’ Strong familiarity with SOC 2 and ISO 27001; knowledge of FedRAMP is a plus.
β’ Preferred experience with Vanta or Drata β you are familiar with the platform, not just the concept.
β’ Exceptional project management skills β capable of juggling multiple engagements simultaneously without losing focus.
β’ Strong customer-facing communication abilities that are effective at all levels β comfortable interacting with a CISO as well as a small founding team.
β’ Motivated by building programs from the ground up β you find blank-page challenges inspiring rather than daunting.
β’ You view compliance as a business driver, not merely a checkbox β and you understand how to advocate for that perspective.
β’ Based in the US and willing to travel occasionally to customer locations as the program expands.
β’ Founding equity in an a16z-backed company that is transforming a $200B+ market β youβre joining at a pivotal moment, not after the fact.
β’ Your contributions directly influence what Treeline's engineering team incorporates into the platform β you are upstream of product decisions, not downstream.
β’ Work closely with Engineering and leadership; no bureaucratic layers or waiting for tickets to pursue your ideas.
β’ A team that prioritizes execution over hierarchy β small, collaborative, and genuinely innovating in a market that has lacked real progress for decades.
β’ Competitive base salary and equity.
β’ Comprehensive health, dental, and vision insurance coverage.
β’ Flexible PTO and a remote-first working environment.
CVS Health
FreedomCare
Northrop Grumman
Get handpicked remote jobs straight to your inbox weekly.