Source Job

Canada Unlimited PTO

  • Own the security compliance program end-to-end, including audits, customer trust, vendor risk, and vulnerability management.
  • Automate evidence collection and control monitoring to be audit-ready year-round, not just during the August–November season.
  • Act as the external security face for enterprise prospects and translate AI regulatory changes into requirements.

SOC 2 PCI DSS NIST Vulnerability Management

20 jobs similar to Compliance and Security Lead

Jobs ranked by similarity.

US 5w PTO

  • Take ownership of building and scaling comprehensive security, privacy, and compliance programs that protect customer data.
  • Lead compliance initiatives such as SOC 2 Type 2 audits and evaluate additional frameworks like ISO 27001 and HIPAA.
  • Build scalable automated security processes by replacing manual tasks with scripts, APIs, and AI-powered solutions.

Our partner is a technology company focused on building secure, scalable systems. They operate with a remote, collaborative culture emphasizing ownership, transparency, and continuous improvement, with around 50–300 employees.

$60,000–$60,000/yr
Argentina Mexico Brazil Chile Uruguay Colombia Ecuador

  • Lead customer security reviews, RFPs, RFIs, and questionnaires to keep deals moving.
  • Own SOC 2 Type II program management and the customer-facing trust portal.
  • Author security policies and manage AI compliance frameworks.

Sparkrock helps social benefit organizations like nonprofits, school boards, and government agencies reach their full potential through technology. They are a best-in-class, 100% remote organization with a focus on culture and growth, serving over 150,000 users.

US

  • You will own end-to-end compliance audits (SOC 1, SOC 2, HITRUST) and manage compliance automation platforms.
  • You will run the vulnerability management program and remediate security findings across AWS.
  • You will support security incident response, fraud investigations, and third-party risk assessments.

We are transforming post-acute care as the leading digital ordering platform for medical equipment and supplies. We connect major health systems, health plans, and suppliers to help patients get life-saving products at home, with a network of 300,000+ clinicians and 3,000+ supplier locations across all 50 states.

$105,000–$125,000/yr
US

  • Own and continuously improve the company's compliance program across SOC 2, GDPR, ISO 27001, and other frameworks.
  • Lead external audits, develop security policies, and partner with engineering teams to implement controls.
  • Manage third-party risk, respond to customer security questionnaires, and build compliance metrics for executive reporting.

10a Labs is the safety and threat-intelligence layer trusted by frontier AI labs, AI unicorns, Fortune 10 companies, and leading global technology platforms. They are a high-growth technology company with a collaborative culture, operating in a fast-moving environment.

$190,000–$210,000/yr
Global

  • Own Filevine's FedRAMP 20x strategy and execution, including evidence automation, continuous monitoring, and certification readiness.
  • Drive the security compliance and trust program across FedRAMP, SOC 2, ISO, HIPAA, and PCI-DSS, converting obligations into engineering work.
  • Lead cross-functional alignment and executive reporting to ensure compliance, privacy, and security priorities are shipped on time.

Filevine is a Legal AI company delivering Legal Operating Intelligence for the future of legal work. Fueled by a team of exceptional collaborators and innovators, Filevine’s rapid growth has earned AI awards and recognition from Deloitte and Inc. as one of the most innovative and fastest-growing technology companies in the country.

Global

  • Lead global security and compliance programs across multiple business units.
  • Manage SOC 2 Type II audits and customer trust initiatives.
  • Drive AI governance and security awareness training efforts.

The partner company is a technology organization that prioritizes security and compliance to build customer trust. It operates in a growing, multi-business environment with a remote-first culture and a focus on operational excellence.

Global

  • Manage the Compliance and Security workstream within a telecom transformation program, coordinating SOC 2, ISO/IEC 27001, and GDPR readiness activities.
  • Build and maintain the workstream plan with milestones, deliverables, and RAID logs, while driving evidence collection and control-owner alignment.
  • Facilitate workshops, track remediation across multiple domains, and ensure alignment with adjacent program streams and governance forums.

Miratech helps visionaries change the world as a global IT services and consulting company supporting digital transformation for large enterprises. With nearly 1000 professionals operating across 25+ countries and a 99% project success rate, their culture emphasizes relentless performance and growth.

US

  • Lead the market-facing security and compliance voice as Sprinto's first dedicated Field CISO in the US.
  • Build and deepen the advisory board into a real community of security leaders.
  • Walk into deals as a practitioner peer, shaping prospect vision and closing late-stage objections.

Sprinto is an Autonomous Trust Platform that centralizes trust requirements across security frameworks, vendors, and customers. Backed by top-tier investors, it is trusted by over 4,000 organizations across 75 countries and fosters a remote culture of ownership and collaboration.

Philippines

  • Drive compliance, risk management, and security assurance as a GRC Specialist.
  • Own third-party risk management and maintain security documentation.
  • Support audits, self-assessments, and customer security inquiries.

Avid provides technology and collaboration tools for creators to entertain, inform, educate, and enlighten the world. The company fosters a culture of passion, customer focus, and innovation, with employees who believe in their mission.

Global 5w PTO

  • Own and automate our GRC program, including SOC 2 audits, risk assessments, and vendor security reviews.
  • Drive internal security across identity, device management, access reviews, and incident response.
  • Build customer-facing trust resources and coordinate product security audits with engineering.

Close builds a communication-first, AI-powered CRM designed to simplify sales for small businesses. The bootstrapped and profitable company has a 120-person, 100% remote team focused on helping customers scale.

$150,000–$170,000/yr
US Unlimited PTO

  • Lead the governance, risk, and compliance function across security policies, standards, risk management, audits, and third-party risk.
  • Own audit readiness and ongoing compliance programs across frameworks such as SOC 2, ISO 27001, GovRAMP, PCI DSS, HIPAA, NIST CSF, and more.
  • Manage third-party and supply chain risk management, including vendor security reviews, due diligence, and remediation tracking.

Accela provides government software solutions to improve efficiency, increase citizen engagement, and enable thriving communities. They have been an industry leader for nearly 20 years and are committed to diversity, equity, and inclusion.

India

  • Manage internal audits and support external compliance assessments across business functions.
  • Perform gap analyses and track remediation actions for compliance frameworks.
  • Maintain and improve compliance documentation, policies, and risk registers.

Our partner is a growing SaaS organization serving global industries. It fosters a collaborative and inclusive culture with a focus on employee development and well-being.

$220,000–$245,000/yr
US 4w PTO

  • Own internal IT, security, and compliance strategy across the organization.
  • Lead the migration from MSP to an in-house IT function and manage a SecOps team.
  • Drive enterprise incident response, business continuity, and disaster recovery planning.

Karbon is the global leader in AI-powered practice management software for accounting firms. The company is well-funded, ranked #1 on G2, and has a people-first culture recognized with Great Place To Work certification and on Fortune's Best Small Workplaces list.

US

  • Own IRAP and ISMAP program strategy and execution across Australia and Japan.
  • Coordinate with regional assessors and government agencies to maintain compliance.
  • Design and maintain compliance documentation and manage continuous monitoring.

For over 20 years, Smartsheet has empowered teams to manage work seamlessly and scale solutions smarter. They are now uniting human teams with AI agents to automate tasks and uncover insights.

$145,000–$175,000/yr
United States

  • Strengthen company-wide security posture through hands-on engineering, collaboration, and pragmatic standards, focusing on application security, cloud and infrastructure security, and secure development practices.
  • Define and implement scalable security standards supporting SOC 2 readiness through practical, automated, and auditable solutions, partnering with Engineering, Infrastructure, IT, Product, Legal, and other teams.
  • Build and maintain internal security tools, automation, and services that support secure development, compliance workflows, vulnerability management, and operational visibility.

Later is the world’s most intelligent influencer marketing company, built to give brands the confidence to create unforgettable campaigns by combining real creator relationships, trusted intelligence, and expert guidance. Trusted by leading enterprise brands including Nike, Wayfair, Unilever, and Southwest Airlines, Later bridges creativity and performance so campaigns deliver results.

United States Unlimited PTO

  • Partner with the CISO to define and execute Sardine's security strategy and roadmap.
  • Help identify and prioritize the highest-risk areas across the business, including application security, compliance, and incident response.
  • Support customer-facing security conversations and represent Sardine's security program to auditors and stakeholders.

Sardine is the leading agentic risk platform for fighting financial crime, providing an integrated solution to stop fraud and automate fraud operations. The company is a fast-growing startup with a remote-first culture and hubs in the US, Canada, and Brazil.

India

  • Manage and conduct internal and external compliance audits for frameworks like ISO, SOC, and NIST.
  • Work with global teams to implement and update compliance controls, policies, and training.
  • Stay updated on regulatory changes and perform gap analysis to maintain certifications.

QAD is building a world-class SaaS company that solves real-world problems in manufacturing and supply chain. They are a growing, virtual-first company with a collaborative culture that values idea-sharing and growth.

Canada Unlimited PTO

  • Manage multi-jurisdictional compliance execution including HIPAA, GDPR, PIPEDA, and emerging privacy laws.
  • Lead IT operations and service delivery including user onboarding, device management, and identity & access management.
  • Drive vendor risk management and BAA/DPA lifecycle, ensuring breach notification timelines and data deletion commitments.

Practice Better is an all-in-one platform helping health and wellness practitioners run their businesses and scale their impact. We are a remote-first team headquartered in Toronto, made up of curious, driven, and empathetic people, trusted by thousands of practitioners worldwide.

$115,000–$145,000/yr
Global

  • Serve as a hands-on GRC advisor for customers, guiding them through risk assessments, audit preparation, and control rollouts.
  • Help customers navigate audits like SOC 2, ISO 27001, HIPAA, PCI-DSS, and NIST, translating requirements into practical steps.
  • Spot GRC complexity early and partner with Support and Customer Success to own escalations requiring real GRC expertise.

Compyl is a GRC and automated security compliance platform built by security practitioners. Backed by Venture Guides, Contour Venture Partners, and Armory Square Ventures, it is a high-growth Series A company.

$210,000–$350,000/yr
US

  • Partner with Sales, Customer Success, and Marketing on strategic enterprise opportunities, bringing security and GRC expertise into customer conversations.
  • Lead executive briefings and CISO-to-CISO conversations to build trust and confidence in Drata's platform.
  • Represent Drata at industry conferences, CISO dinners, and roundtables across the Americas, EMEA, and APAC, building relationships and credibility.

Drata helps companies earn and keep trust by providing a proof layer that shows they deserve it. The company has over 600 employees worldwide and fosters a culture built on trust, speed, and continuous growth.