Responsibilities
- Establish and manage the full compliance lifecycle, including control frameworks, evidence gathering, platform hygiene, and coordination with auditors to achieve certification readiness
- Develop and maintain core compliance documentation, including security policies, risk inventories, third-party assessments, and information security management systems
- Collaborate with engineering, go-to-market, operations, and external partners to integrate compliance practices into development and service delivery
- Act as the primary internal resource for compliance matters, handling customer security reviews, audit requests, and due diligence inquiries
- Lead end-to-end readiness for SOC 2 and ISO 27001 audits, including planning, control implementation, and preparation for external validation
- Oversee relationships with audit firms and manage penetration testing as part of a holistic compliance delivery strategy
- Communicate effectively across technical and executive levels, from detailed security reviews to strategic roadmap discussions with leadership
- Independently manage multiple customer-facing projects simultaneously, ensuring timely and accurate delivery without dependencies
- Contribute to the development of a Compliance-as-a-Service product, shaping it into a scalable, revenue-generating offering
- Create standardized frameworks, scoping methodologies, and client-facing materials to improve consistency and quality across compliance engagements
- Incorporate field insights into product development, ensuring compliance experience directly informs platform evolution
Work Arrangement
remote-first
Other
- Occasional travel to customer locations may be required as the program expands
- Flexible paid time off policy and remote-first culture