Source Job

$140,000–$175,000/yr
US

  • Represent the practice directly with customers through calls, webinars, and conferences to drive deals.
  • Map compliance frameworks like GDPR, NIST, PCI, and HIPAA to Zscaler capabilities control by control.
  • Build reusable playbooks and educate field teams to handle compliance conversations while protecting data.

Compliance Frameworks AI/ML Security Architecture Customer Engagement Sales Enablement

20 jobs similar to Security-Compliance Program Manager

Jobs ranked by similarity.

$160,000–$230,000/yr
Global

  • Own customer security reviews and compliance programs, driving fast and accurate responses.
  • Ensure practical risk decisions and reliable security answers through automation and AI.
  • Scale the function by building processes and self-service resources."

The company is a technology company that builds quickly and focuses on security and compliance. It is a remote-first small team with a culture of autonomy and growth.

Global 4w PTO

  • Act as part vCISO and account manager, guiding clients through security and compliance programs.
  • Assess security posture, provide recommendations, and design programs using NIST, SOC 2, and ISO 27001.
  • Liaise with auditors and internal teams to translate programs into policies, procedures, and configurations.

Oneleet provides a platform for companies to build, manage, and monitor cybersecurity programs and achieve SOC 2 and ISO 27001. It raised a $33M Series A and is a fast-growing, remote-first team with an opinionated culture.

$102,899–$137,718/yr
Global

  • Own and drive Sourcegraph's governance, risk, and compliance program, including SOC 2 and ISO 27001 certifications.
  • Manage audits end-to-end: evidence collection, control testing, stakeholder coordination, and remediation.
  • Support customer-facing compliance activities and tailor controls to fit Sourcegraph's fast-moving environment.

Sourcegraph builds AI-powered code search and batch change tools for engineering teams to manage complex codebases. It is a globally distributed team backed by a16z, Sequoia, and Redpoint, valuing high agency and customer love.

Global

  • Own the compliance function as its sole occupant, reporting to the Head of Engineering and partnering with the Security Lead on policies, audits, and evidence.
  • Manage the Q&A library, customer security reviews, audit calendar, and third-party risk to keep Duvo reviewable for buyers and auditors.
  • Deliver precise, evidenced answers that stand up to hostile reviewers and keep the trust center and subprocessor list current.

Duvo builds an AI operations platform for large enterprises, enabling customers to create AI agents that automate business-critical processes across systems like SAP, spreadsheets, and supplier portals. The company is growing fast and values velocity, direct feedback, autonomy, and heavy use of AI tools.

$175,000–$200,000/yr
US Canada

  • Lead compliance programs including SOC 2, GDPR, CCPA/CPRA, and Shopify partner security requirements.
  • Own security policies, risk management, business continuity, and incident response.
  • Manage IT operations, endpoint security, and cloud security across the company.

Rebuy revolutionizes shopping with intelligent, personalized experiences for DTC brands. They are a fully remote team with a culture rooted in ownership, drive, and empathy.

US 3w PTO

  • Own and mature internal and Managed GRC programs, including federal SSPs, POA&Ms, audits, and risk assessments.
  • Collaborate with CISOs, engineers, and control owners to translate compliance requirements into practical technical controls.
  • Lead and develop a GRC team while introducing automation and AI to improve scalability and consistency.

The company provides managed Governance, Risk & Compliance (GRC) and security assurance services, with a strong focus on federal security programs and frameworks like NIST, SOC 2, and CMMC. It supports a growing GRC team and emphasizes low-ego collaboration, automation, and AI-enabled approaches to scale delivery.

Global

  • Own global certification programs like ISO 27001 and SOC 2, and advise engineering teams on secure development.
  • Collaborate directly with engineers to audit cloud infrastructure, CI/CD pipelines, and AI-driven security controls.
  • Assess risks of emerging technologies and drive continuous compliance improvements across the organization.

Picus Security is an exposure validation company that proves what attackers can exploit and what defenses stop, turning exposures into defensible decisions. As a fast-growing global remote team, it values continuous security validation and has a 95% recommendation rate.

$139,200–$189,000/yr
North America Unlimited PTO

  • Own risk identification, analysis, and prioritization across third-party risk and security risk assessments using established frameworks.
  • Translate technical vulnerabilities and risk findings into clear, quantified risk statements for non-security stakeholders and leadership.
  • Drive remediation of findings and risk exceptions to closure, partnering with Engineering, IT, Product, and Legal.

GitLab is an intelligent orchestration platform for DevSecOps, helping organizations increase developer productivity and improve security. With over 50 million users, GitLab is trusted by more than 50% of the Fortune 100 and fosters a high-performance culture driven by values and continuous knowledge exchange.

$130,000–$150,000/yr
US

  • Own and mature security, privacy, and compliance programs across HIPAA, SOC 2, and HITRUST.
  • Lead HITRUST certification end to end, including scoping, evidence collection, and assessor coordination.
  • Partner with Engineering, Product, SRE, and IT to integrate security into architecture, SDLC, and cloud infrastructure.

IntusCare is an end-to-end ecosystem built specifically to help PACE programs deliver exceptional care, strengthen financial performance, and stay compliant. It is a growing healthcare SaaS organization that empowers teams to improve outcomes for dual-eligible seniors.

US 18w maternity 16w paternity

  • Contribute to secure-by-design practices and maturing SAST, SCA, and DAST programs.
  • Develop Secure AI Development Lifecycle and AI-assisted threat modeling framework.
  • Mentor engineers on secure coding and foster cross-functional collaboration.

Spring Health is a global mental health company using an AI-native platform to deliver personalized mental health support. The company reaches over 170 million people worldwide and fosters a culture of innovation, collaboration, and commitment to eliminating barriers to mental health.

India

  • Establish and enforce security, compliance, risk, privacy, and AI governance policies and standards.
  • Lead AI governance and security architecture, including risk assessments and audits for GenAI/ML tools.
  • Oversee compliance audits, incident response, and security technologies while collaborating with global stakeholders.

This global organization focuses on security, risk, compliance, privacy, and AI governance for distributed teams. Its collaborative, inclusive culture values innovation, continuous improvement, and operational resilience, with no employee count disclosed.

$180,000–$220,000/yr
US

  • Drive SOC 2, ISO 27001, and PCI 4.0 compliance audit cycles: gather evidence, design controls, and coordinate with auditors.
  • Own the compliance automation platform Vanta: monitor control status, chase failing checks, and update risk register.
  • Run vendor and third-party risk reviews, security assessments, and respond to customer security questionnaires.

AssemblyAI builds the best-in-class Voice AI models powering the next generation of voice applications. With under 100 people, it is a capital-efficient AI company generating roughly $500K ARR per employee and operating as a true meritocracy with no bureaucracy.

North America

  • Lead design and implementation of innovative compliance processes, focusing on ABAC and Export Compliance.
  • Collaborate with Ethics & Compliance SMEs to translate requirements into scalable, user-friendly workflows.
  • Drive automation and digitalization of compliance processes using ServiceNow and AI capabilities.

ServiceNow is the AI control tower for business reinvention, bringing together AI, data, and workflows to help 85% of the Fortune 500 work smarter. The company is building an AI-native culture where technology and talent are unstoppable together, with a focus on freeing people from busywork.

$190,000–$250,000/yr
United States

  • Provide architect-level thought leadership in securing enterprise AI programs, including models, applications, and data.
  • Lead complex client engagements as SME across AI security services, from assessment to executive readout.
  • Author reference architectures and enable teams to deliver coherent AI security solutions.

Trace3 is a leading Transformative IT Authority, providing unique technology solutions and consulting services to clients. With over 1,200 employees across the United States, the company embodies a startup spirit with a scalable business culture focused on innovation and growth.

Germany 6w PTO

  • Lead ISO 27001 and SOC 2 audit cycles end-to-end, owning compliance and audit.
  • Own customer trust by responding to security questionnaires and representing InfoSec to enterprise clients.
  • Drive risk management, vendor security, and incident response while building AI-assisted workflows.

We are the first AI-native Employee Experience Platform, helping organizations unlock inspirational communication. Our diverse team of 550+ employees supports over 1,500 customers, and we are a unicorn company valued at over $1 billion.

$114,800–$165,000/yr
US

  • Own Abnormal's governance committees, including AI, Data, and Security Governance.
  • Manage the enterprise policy program end-to-end, from drafting to stakeholder acknowledgment.
  • Oversee risk management operations, including risk assessments, exceptions, and audits.

Abnormal AI protects the humans behind the world's most critical organizations from AI-powered cybercrime. Over 5,000 enterprises trust our behavioral AI platform, and we offer a collaborative, fast-paced security culture.

Global

  • Lead and expand the security function across application security, security compliance, infrastructure & cloud security, and business application security.
  • Build and run the AppSec program with AI-assisted code review and integrate security into CI/CD pipelines.
  • Own ISO 27001 and SOC 2 certification, manage audits, and secure cloud and business applications.

Constructor provides an all-in-one platform for education and research using machine intelligence and data science to address educational challenges like access inequality and low engagement. The company is led by a gender-balanced board and fosters an inclusive culture, though employee size is not specified.

Europe 5w PTO

  • Build and maintain compliance frameworks in the Secfix platform, including ISO 27001, TISAX, SOC 2, GDPR, and more.
  • Own internal audits end-to-end for customers, ensuring they are prepared for external audits.
  • Collaborate with product and engineering to translate compliance gaps into structured product work and enhance platform quality.

Secfix automates security compliance for European companies, helping them achieve ISO 27001, GDPR, TISAX, and SOC 2 efficiently. They are a 100% remote team with hubs in Munich, Berlin, and London, recently raised a $12M Series A, and are backed by top VCs.

$143,500–$205,000/yr
US

  • Manage premium customer support relationships and drive deep product adoption for top-tier customers.
  • Partner with Field Sales, serve as trusted advisor for web and email security implementations, and manage escalations.
  • Deliver high-impact training, monitor customer environments, and translate insights into product requirements.

Zscaler accelerates digital transformation with the Zero Trust Exchange platform, a cloud security solution protecting thousands of customers from cyberattacks. The company is AI-native and values ownership, collaboration, and a challenge culture.

India

  • Maintain and enhance Anovia's ISO/IEC 27001 ISMS, including policies, controls, risks, and audit coordination.
  • Support SOC 2, HIPAA, and other compliance programs, including vendor assessments, vulnerability management, and incident response.
  • Lead ambiguous technical and operational initiatives from planning through implementation, coordinating stakeholders and driving completion.

Anovia is an industry-leading technology outsourcing support provider specializing in workflow and knowledge processes, technical support, helpdesk, and multilingual services. With over 200 experts globally, we serve Fortune 500 companies and value growth, learning, and work-life balance.