Source Job

Global

  • Own the compliance function as its sole occupant, reporting to the Head of Engineering and partnering with the Security Lead on policies, audits, and evidence.
  • Manage the Q&A library, customer security reviews, audit calendar, and third-party risk to keep Duvo reviewable for buyers and auditors.
  • Deliver precise, evidenced answers that stand up to hostile reviewers and keep the trust center and subprocessor list current.

SOC 2 ISO 27001 AI Tooling

20 jobs similar to Compliance Manager

Jobs ranked by similarity.

Germany 6w PTO

  • Lead ISO 27001 and SOC 2 audit cycles end-to-end, owning compliance and audit.
  • Own customer trust by responding to security questionnaires and representing InfoSec to enterprise clients.
  • Drive risk management, vendor security, and incident response while building AI-assisted workflows.

We are the first AI-native Employee Experience Platform, helping organizations unlock inspirational communication. Our diverse team of 550+ employees supports over 1,500 customers, and we are a unicorn company valued at over $1 billion.

US 3w PTO

  • Own and mature internal and Managed GRC programs, including federal SSPs, POA&Ms, audits, and risk assessments.
  • Collaborate with CISOs, engineers, and control owners to translate compliance requirements into practical technical controls.
  • Lead and develop a GRC team while introducing automation and AI to improve scalability and consistency.

The company provides managed Governance, Risk & Compliance (GRC) and security assurance services, with a strong focus on federal security programs and frameworks like NIST, SOC 2, and CMMC. It supports a growing GRC team and emphasizes low-ego collaboration, automation, and AI-enabled approaches to scale delivery.

Global

  • Own global certification programs like ISO 27001 and SOC 2, and advise engineering teams on secure development.
  • Collaborate directly with engineers to audit cloud infrastructure, CI/CD pipelines, and AI-driven security controls.
  • Assess risks of emerging technologies and drive continuous compliance improvements across the organization.

Picus Security is an exposure validation company that proves what attackers can exploit and what defenses stop, turning exposures into defensible decisions. As a fast-growing global remote team, it values continuous security validation and has a 95% recommendation rate.

Global 4w PTO

  • Act as part vCISO and account manager, guiding clients through security and compliance programs.
  • Assess security posture, provide recommendations, and design programs using NIST, SOC 2, and ISO 27001.
  • Liaise with auditors and internal teams to translate programs into policies, procedures, and configurations.

Oneleet provides a platform for companies to build, manage, and monitor cybersecurity programs and achieve SOC 2 and ISO 27001. It raised a $33M Series A and is a fast-growing, remote-first team with an opinionated culture.

$180,000–$220,000/yr
US

  • Drive SOC 2, ISO 27001, and PCI 4.0 compliance audit cycles: gather evidence, design controls, and coordinate with auditors.
  • Own the compliance automation platform Vanta: monitor control status, chase failing checks, and update risk register.
  • Run vendor and third-party risk reviews, security assessments, and respond to customer security questionnaires.

AssemblyAI builds the best-in-class Voice AI models powering the next generation of voice applications. With under 100 people, it is a capital-efficient AI company generating roughly $500K ARR per employee and operating as a true meritocracy with no bureaucracy.

India

  • Maintain and enhance Anovia's ISO/IEC 27001 ISMS, including policies, controls, risks, and audit coordination.
  • Support SOC 2, HIPAA, and other compliance programs, including vendor assessments, vulnerability management, and incident response.
  • Lead ambiguous technical and operational initiatives from planning through implementation, coordinating stakeholders and driving completion.

Anovia is an industry-leading technology outsourcing support provider specializing in workflow and knowledge processes, technical support, helpdesk, and multilingual services. With over 200 experts globally, we serve Fortune 500 companies and value growth, learning, and work-life balance.

$160,000–$180,000/yr
US

  • Own and operationalize Avandra's compliance roadmap across HIPAA, HITRUST, and SOC 2, driving certifications and risk management.
  • Coordinate audit evidence, vendor security assessments, and customer due diligence while keeping audit-ready documentation.
  • Lead M&A compliance integration, including gap analyses and remediation plans for acquired entities.

Avandra Imaging is building the largest indexed data cloud of medical imaging to unlock clinical data for healthcare research. With over 5,000 customer integrations and roughly 70% market share, it is a growth-stage startup with a values-driven culture.

Global Unlimited PTO

  • Own and mature the compliance framework, including continuous controls monitoring, security awareness, and audit coordination.
  • Automate GRC processes using compliance platforms and AI tooling for evidence collection and risk management.
  • Develop policies, manage third-party risk, and scale customer security assurance end-to-end.

Monarch is an all-in-one personal finance platform that simplifies finances. Since 2021, they have become the top-recommended app, with a fully remote, AI-driven team focused on building a product people love.

Canada

  • Lead and continuously improve Plooto's privacy program, ensuring compliance with Canadian privacy laws like PIPEDA and Quebec Law 25.
  • Provide practical privacy guidance to the business, translating legal requirements into risk-based actions without unnecessary friction.
  • Support enterprise risk management, regulatory change, and broader compliance activities while building understanding across the organization.

Plooto is a payment automation platform that helps accountants, bookkeepers, and their clients manage payables and receivables. The company is a growing fintech with strong product-market fit, backed by experienced leaders, and values customer impact, craft, and urgency.

$135,000–$145,000/yr
Global

  • Own the IT evidence program across ISO 27001, SOC 1, SOC 2, PCI DSS, and HIPAA for approximately 13 operating sites, managing audits and remediation.
  • Manage vulnerability management end to end, oversee endpoint detection and response, and lead security incident response through to conclusion.
  • Contribute to identity governance across a hybrid cloud and on-premises IdP, overseeing access review and privileged access controls.

Serverfarm is a leading developer and operator of data centers with over 750 locations and key customer relationships in 45 countries. With Manulife Investment Management's acquisition in 2023, the company is positioned for explosive growth and offers a culture of innovation and career development.

Europe 5w PTO

  • Build and maintain compliance frameworks in the Secfix platform, including ISO 27001, TISAX, SOC 2, GDPR, and more.
  • Own internal audits end-to-end for customers, ensuring they are prepared for external audits.
  • Collaborate with product and engineering to translate compliance gaps into structured product work and enhance platform quality.

Secfix automates security compliance for European companies, helping them achieve ISO 27001, GDPR, TISAX, and SOC 2 efficiently. They are a 100% remote team with hubs in Munich, Berlin, and London, recently raised a $12M Series A, and are backed by top VCs.

US 3w PTO

  • Lead Atmosera's internal GRC program and managed GRC service delivery.
  • Manage federal System Security Plans, POA&Ms, and audit responses.
  • Serve as a senior GRC advisor bridging executive and technical teams.

Atmosera empowers businesses to redefine what's possible with modern technology and human expertise across Applications, Data & AI, DevOps, Security, and Microsoft Azure. As a Microsoft Partner with seven specializations, the company values humility, hunger, and mindfulness in a collaborative team environment.

India Unlimited PTO

  • Guide customers through setup and go-live, ensuring they reach their first audit milestone.
  • Collaborate with founders, CTOs, and security teams to map goals to actionable milestones.
  • Own next steps when stuck, partnering with internal teams to keep the project moving.

Sprinto is an autonomous trust platform that centralizes compliance, audits, risk management, and more for organizations worldwide. Backed by top investors, it serves over 4,000 companies in 75+ countries and fosters a remote-first, ownership-driven culture.

$80,208–$83,372/yr
Poland

  • Lead the design, implementation, and maintenance of Hyland's enterprise ISO governance and certification program across multiple certifications, business units, and regions.
  • Drive strategic expansion of ISO scope, including advanced certifications like TISAX and C5, and establish governance models and control ownership across teams.
  • Measure and report ISO program health through metrics, dashboards, and reporting, while providing leadership and mentorship to compliance specialists.

Hyland is the pioneer of the Content Innovation Cloud, delivering enterprise intelligence through solutions that unlock actionable insights and drive automation. Trusted by thousands of organizations worldwide, including many Fortune 100 companies, Hyland has nearly 4,000 employees and fosters an employee-centric, inclusive culture.

Europe 4w PTO

  • Lead and develop the Information Security GRC strategy, roadmap, operating model, and governance cadence.
  • Coordinate SOC 2, DORA/CySEC-related assurance, internal and external audits, and regulatory requests.
  • Build, develop, and manage the GRC team and improve GRC efficiency through automation and reusable evidence.

JustMarkets is an international FinTech company. It is a growing organization with a focus on information security and compliance.

$142,000–$225,000/yr
US

  • Own and maintain AML/BSA, Sanctions, and KYC/KYB policies across all markets, ensuring compliance with local regulations and partner requirements.
  • Serve as primary compliance point of contact for issuing bank and card network partners, managing audits, exams, and remediation.
  • Build and run governance structure for the compliance program, including reporting, escalation paths, and risk committees.

Motive empowers the people who run physical operations with tools to make their work safer, more productive, and more profitable. Motive serves nearly 100,000 customers across a wide range of industries, from Fortune 500 enterprises to small businesses.

US

  • Oversee and audit continuous identity and location verification across the remote employee lifecycle.
  • Manage compliance with Sentinel Vision monitoring, Yubikey tokens, and Webex admin console.
  • Lead incident response, exception management, and client notification for identity discrepancies.

Sutherland is a global digital transformation company specializing in AI, automation, cloud engineering, and advanced analytics. They work with iconic brands worldwide and have created over 200 unique inventions.

$128,270–$189,230/yr
UK

  • Lead and coordinate second-line regulatory compliance and privacy oversight activities for the UK entity, serving as the operational lead for UK privacy compliance and Data Protection Officer.
  • Translate legal and regulatory requirements into compliance standards, governance routines, and oversight expectations for first-line stakeholders.
  • Prepare management reporting, governance materials, and issue summaries, and support audits and regulatory enquiries.

Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest. They are a remote-first company with a focus on inclusive culture and competitive benefits.

$139,200–$189,000/yr
North America Unlimited PTO

  • Own risk identification, analysis, and prioritization across third-party risk and security risk assessments using established frameworks.
  • Translate technical vulnerabilities and risk findings into clear, quantified risk statements for non-security stakeholders and leadership.
  • Drive remediation of findings and risk exceptions to closure, partnering with Engineering, IT, Product, and Legal.

GitLab is an intelligent orchestration platform for DevSecOps, helping organizations increase developer productivity and improve security. With over 50 million users, GitLab is trusted by more than 50% of the Fortune 100 and fosters a high-performance culture driven by values and continuous knowledge exchange.

$81,184–$101,480/yr
US

  • Ensure regulatory readiness, strengthen governance structures, and enhance reporting accuracy across the organization.
  • Oversee the policy management lifecycle, including creation, review, and approval, ensuring alignment with enterprise standards.
  • Manage lobbying reporting oversight and lead risk-based compliance reviews and training program lifecycles.

LISC is one of the country's largest community development organizations, helping forge vibrant, resilient communities across America. LISC works with residents and partners to close gaps in health, wealth, and opportunity so that people and places can thrive.