
Security Compliance Manager
Posted Aug 26

Posted Aug 26
This is a fully remote position, open to applicants in United States.
• Take ownership of compliance planning and the compliance program for SOC 2 Type II, PCI DSS Level 1 Service Provider, ISO 27001, GDPR, CCPA, and DORA.
• Lead Sardine's FedRAMP initiative, which includes the implementation of NIST SP 800-53 controls, 3PAO assessments, and ongoing monitoring across engineering and IT.
• Act as the main point of contact for auditors, regulators, and industry stakeholders.
• Collaborate with engineering, IT, product, security, and legal teams to ensure thorough reviews yield positive outcomes.
• Communicate objectives, scope, and results to senior management and the board through the CISO.
• Manage the control framework, consolidating overlapping controls into a coherent and evidence-efficient set.
• Oversee the security policy and standards library.
• Handle the risk register, risk quantification, and reporting cadence.
• Ensure that actions taken to mitigate risks are suitable and reported accurately.
• Manage the customer assurance and trust program, which includes security questionnaires, attestations, and trust artifacts.
• Facilitate the collection of evidence, scans, and artifacts.
• Drive process enhancements in response to findings and maturity assessments.
• Develop product and technical expertise to ground control design and risk decisions in the platform architecture.
• Identify alternative solutions that enhance consistency and promote streamlining and automation.
• Create executive-ready documentation and presentations and conduct meetings with regulators and internal stakeholders.
• Lead and mentor the Security Compliance Analyst and expand the function as obligations increase.
• Over 7 years of experience in security compliance, GRC, or audit, with complete ownership of audit or certification programs (SOC 2, PCI DSS, and/or ISO 27001).
• Extensive knowledge of security and privacy frameworks such as PCI DSS, SOC 2, ISO 27001, GDPR/CCPA, and DORA.
• Familiarity with control frameworks including NIST CSF and CIS.
• Capability to develop fluency in a technical product and collaborate effectively with engineering and product teams.
• Excellent written and verbal communication skills, with the ability to produce executive-ready documentation and establish credibility with auditors, regulators, and leadership.
• Experience in dynamic, high-growth environments, preferably in fintech or payments.
• Ability to operate as a leader, partner, and individual contributor as required.
• Willingness to travel as necessary.
• Experience in leading, mentoring, or managing others, or clear readiness to manage a direct report.
• Direct experience managing a PCI DSS Level 1 service provider program is a plus.
• Hands-on exposure to DORA requirements is a plus.
• Familiarity with GRC and security tools, including Vanta, Rippling, and macOS environments, is a plus.
• Competitive compensation package including cash and equity.
• Early exercise option for all stock options, including pre-vested.
• Remote-first culture allowing work from anywhere.
• Flexible paid time off and a year-end break.
• Health, dental, and vision insurance coverage for employees and their dependents, applicable in the US and Canada.
• 4% matching contribution in 401k / RRSP for US and Canada employees.
• MacBook Pro provided to you at home.
• One-time stipend to create a home office setup, covering desk, chair, screen, etc.
• Monthly meal stipend.
• Monthly allowance for social meet-ups.
• Annual health and wellness stipend.
• Annual learning stipend.
Kailera Therapeutics
Kailera Therapeutics
Get handpicked remote jobs straight to your inbox weekly.