Compliance Manager
4 дн. назад
180k–230k USD / yearUSASenior
risk managementsecurity auditscompliance management
Role owning compliance functions, audits, risk register, and security diligence for customer contracts in a growing tech company.
Обязанности
- 's security and compliance needs are growing as we work with larger and more demanding customers. Compliance is increasingly a customer-facing, contractual function rather than an internal exercise, and we are looking for someone to own it.
- This role owns that function end to end: our audits, our evidence base, our risk register, and the security diligence that customers put us through before and during a contract. You will work directly with the Head of Security and across engineering, IT, legal, and sales. This is a program-ownership role with the autonomy and accountability that implies. You will not have a senior compliance function above you to defer to; you are that function.
- In your first year, success looks like a complete and defensible evidence base with clean audit outcomes, a repeatable way to answer customer security diligence, and a risk register that leadership actually uses.
- Own our SOC 2 Type II and ISO 27001 programs, and future frameworks as we take them on, including scope, evidence, control operation, and the relationship with our external auditors.
- Own and complete the control evidence base in our compliance automation platform, moving controls from partially substantiated to audit-ready and keeping them there.
- Lead security diligence for enterprise and regulated customers: security questionnaires, audit responses, right-to-audit requests, and the recurring reporting these customers require.
- Own the risk register and mature risk management from a security-team activity into a recorded, enterprise-aligned program.
- Coordinate the compliance obligations that come with customer contracts, including data protection, breach-notification timelines, and vendor and subprocessor assessments, in partnership with legal.
- Assess and stand up new certifications as the customer pipeline requires them.
- Partner with engineering and IT to make evidence collection a byproduct of how systems already run, rather than a manual scramble before each audit.
Будет плюсом
- Experience with regulated-customer contractual security obligations: data protection agreements, breach notification, and right-to-audit provisions.
- Exposure to newer or higher-bar frameworks (for example FedRAMP) and a sense of what standing them up would take.
- Experience building a compliance function or team, since this role can grow into one as the company scales.
- Familiarity with cloud infrastructure or AI or ML platforms.
Другое
- At , we're on a mission to democratize distributed computing and make it accessible to software developers of all skill levels. We’re commercializing Ray , a popular open-source project that's creating an ecosystem of libraries for scalable machine learning. Companies like OpenAI , Uber , Spotify , Instacart , Cruise , and many more, have Ray in their tech stacks to accelerate the progress of AI applications out into the real world.
- With , we’re building the best place to run Ray, so that any developer or data scientist can scale an ML application from their laptop to the cluster without needing to be a distributed systems expert.
- Proud to be backed by Andreessen Horowitz, NEA, and Addition with $250+ million raised to date.
- 7+ years in governance, risk, and compliance, ideally including time at a high-growth startup.
- Demonstrated ownership of SOC 2 and ISO 27001 programs, including running audits end to end with external auditors.
- Experience fronting security diligence for enterprise or regulated customers. You have sat across from a customer's auditors or security reviewers and held your own.
- Working fluency with compliance automation platforms (such as Vanta or equivalent) and with turning tooling into genuinely audit-ready evidence, not just dashboards.
- A strong grasp of security controls and how they operate in a cloud and SaaS environment, enough to work credibly with engineers rather than only collecting their attestations.
- The judgment and communication to run a program independently, coordinate across functions, and be trusted as the single owner of compliance.