
Security & Compliance Manager
Posted Aug 7

Posted Aug 7
This is a fully remote position, open to applicants in United States.
• Ensure SOC 2 Type II compliance by overseeing control operations, collecting evidence, and preparing for annual audits.
• Spearhead the ISO 27001 certification process, from assessing gaps to achieving certification and maintaining ongoing surveillance.
• Take ownership of security and privacy frameworks, including GDPR, CCPA, and other relevant regulations.
• Provide guidance to the organization on security, privacy, and compliance strategies.
• Develop and enhance security controls, governance standards, policies, and risk management practices.
• Perform security risk assessments, manage incident responses, and lead remediation initiatives.
• Manage Vanta and related tools for compliance monitoring, continuous control testing, and audit workflows.
• Collaborate with Engineering, Product, Operations, Legal, and leadership teams to integrate security and privacy into products, systems, and business processes.
• Convert technical risks into actionable business recommendations.
• Establish enterprise data governance standards, encompassing data classification, retention, and lifecycle management.
• Lead organization-wide security awareness programs.
• Keep track of evolving regulations, emerging threats, and industry best practices.
• Assess and implement technologies and processes that enhance automation, visibility, and operational efficiency.
• Three to five years of experience in information security, data privacy, governance, compliance, or risk management.
• Direct experience in maintaining SOC 2 Type II and leading or assisting with ISO 27001 certification in a SaaS or cloud-first setting.
• Practical experience with Vanta or similar GRC platforms like Drata, Secureframe, or Sprinto.
• Strong understanding of GDPR, CCPA, and other applicable privacy regulations.
• Proven success in designing and implementing data classification, retention, privacy, and security programs.
• Familiar with cloud infrastructure, SaaS environments, identity and access management, and security controls.
• Capable of articulating complex technical concepts to both technical and non-technical audiences.
• Demonstrated ability to influence stakeholders and lead initiatives across various functions.
• Bachelor’s degree in Information Security, Computer Science, Information Systems, Business, Legal Studies, or a related field, or equivalent practical experience.
• Professional certifications such as CIPP/US, CIPM, CISSP, CISM, or CRISC are preferred.
• Experience in a fast-paced SaaS or technology startup environment is a plus.
• Understanding of privacy-by-design principles is a plus.
• Must be legally authorized to work.
• Successful completion of a background investigation is necessary for any employment offer.
• Competitive Compensation
• Paid Time Off
• Paid Parental Leave
• Remote Workplace
• Flexible Work Schedules
• Health, Dental, Vision, and LTD Insurance
• 401(k)
• Professional Development Opportunities
• Bonus
RTX
Finalsite
EXALTA Group
Auto Approve
Get handpicked remote jobs straight to your inbox weekly.