Conduct internal audits and compliance reviews against ISO 27001, ISO 42001, HIPAA, and GDPR frameworks.
Analyze control evidence and documentation within GRC platforms like Vanta to identify gaps and deficiencies.
Develop remediation plans and coordinate multiple audit initiatives in a fast-paced global environment.
Jobgether uses AI-powered matching to connect candidates with hiring companies. They are a growing platform focused on fair and objective candidate review.
Manage the Compliance and Security workstream, coordinating SOC 2, ISO 27001, GDPR, and related audit-readiness activities.
Build and maintain execution plans with clear owners, milestones, dependencies, risks, and decision points.
Facilitate workshops, track evidence, and escalate risks to keep audits on schedule.
Miratech is a global IT services and consulting company that helps visionaries change the world through digital transformation. With nearly 1000 full-time professionals across 25+ countries, the company maintains a culture of Relentless Performance and has achieved over 99% project success since 1989.
Lead and mature Fullscript's security compliance program across SOC 2, PCI DSS, and HITRUST frameworks.
Manage internal and external audits, coordinate remediation efforts, and maintain continuous audit-readiness.
Partner cross-functionally with Security, Engineering, Privacy, Legal, and Product to translate compliance requirements into scalable practices.
Fullscript is a health technology company that powers every part of care by providing practitioners with clinical insights, lab interpretations, and high-quality supplements. With over 125,000 practitioners and 10 million patients, they foster a culture of curiosity, collaboration, and putting people first.
Lead SOC 1 and SOC 2 examinations and support end-to-end SOX planning.
Partner with Security, Engineering, Data, and Finance to implement scalable IT controls.
Conduct controls assessments, drive remediation, and produce auditor-ready documentation.
Kraken is one of the world's longest-standing crypto platforms, trusted by over 10 million individuals and institutions globally, offering spot trading, margin, futures, staking, and OTC services. Part of Payward, it is powered by people from around the world and celebrates diverse talents, backgrounds, and unique perspectives.
Own and continuously improve Camunda's Information Security Management System (ISMS), driving measurable improvements.
Drive security audit cycles for ISO 27001, SOC 2, and future frameworks with minimal supervision.
Review information security requirements in customer contracts and lead responses to complex security questionnaires.
We are the enterprise platform for agentic orchestration, enabling organizations to coordinate AI agents, people, and systems across complex business processes. We are a fully remote, global team trusted by over 700 organizations, named a GP Bullhound Next Unicorn and Great Place to Work certified.
Own the compliance programs and audits end to end, including SOC 2, PCI DSS, GDPR, and ISO 27001.
Manage identity and access, device fleet, and vendor security with ownership over control state.
Drive compliance as a sales enabler and own the customer-facing security package.
Footprint is the agentic platform that learns compliance programs and runs them end to end for banks and fintechs. The team is small, senior, and ships fast.
Lead control implementation and audit readiness across multiple compliance frameworks including FedRAMP, SOC 2, ISO 27001, and TISAX.
Partner with engineering, product, and security teams to translate compliance requirements into practical controls.
Represent the compliance program in customer-facing discussions and security due diligence reviews.
Rescale is pioneering the future of engineering and scientific discovery through intelligent automation, applied AI, and data management. We are a diverse, collaborative, and mission-driven team that unlocks innovation across aerospace, energy, life sciences, and manufacturing industries.
Maintain and mature the ISMS, including the Statement of Applicability, risk treatment plans, and Management Review Meetings.
Support ISO 27001 and SOC 2 Type 2 audits from readiness through certification, including evidence preparation.
Lead the security policy program and collaborate across teams to translate compliance requirements into practical practices.
Mozilla Corporation is a non-profit-backed tech company behind Firefox, focused on making the internet better. With 225+ million monthly users, it is a wholly owned subsidiary of the Mozilla Foundation, promoting privacy, AI, and open-source.
Own the security compliance program end-to-end, including audits, customer trust, vendor risk, and vulnerability management.
Automate evidence collection and control monitoring to be audit-ready year-round, not just during the August–November season.
Act as the external security face for enterprise prospects and translate AI regulatory changes into requirements.
Ada is an AI customer service company that helps enterprises automate customer conversations with AI agents. Founded in 2016, we've powered over 5.5 billion interactions and raised over $250M from top investors.
Own and drive the compliance roadmap across multiple frameworks like ISO 27001, TISAX, and SOC 2.
Implement ISO 27001 end-to-end for customers and mentor junior compliance specialists.
Act as the senior compliance voice for customers, auditors, and product, partnering with CS and founders.
Secfix automates security compliance in Europe, helping companies achieve ISO 27001, GDPR, TISAX, and SOC 2 quickly and easily. We are a 100% remote team with hubs in Munich, Berlin, and London, backed by top VCs with a high-performing, ownership-driven culture.
Manage a focused portfolio of delivery partners across security assurance, advisory, and legal verticals.
Execute and improve Delivery Partnerships playbooks covering onboarding, engagement, co-sell motions, and partner enablement.
Coordinate between delivery partners and Sprinto's product, customer experience, and sales teams to translate partner needs into feedback.
Sprinto is an Autonomous Trust Platform that centralizes trust requirements across security frameworks, vendors, and customers. Backed by top-tier investors such as Accel, Elevation, and Blume Ventures, it has raised $31.8M and is trusted by over 4,000 organizations across 75 countries.
Drive compliance, risk management, and security assurance as a GRC Specialist.
Own third-party risk management and maintain security documentation.
Support audits, self-assessments, and customer security inquiries.
Avid provides technology and collaboration tools for creators to entertain, inform, educate, and enlighten the world. The company fosters a culture of passion, customer focus, and innovation, with employees who believe in their mission.
Automate governance, risk, and compliance frameworks including ISO 27001, PCI-DSS, DORA, and UK Cyber Essentials.
Engineer GRC workflows with internal systems to support compliance by design.
Translate compliance requirements into technical specifications for engineering teams and non-technical stakeholders.
Pleo builds spend solutions that make managing money seamless for finance teams and employees. They are a driven, progressive team of 850+ people from over 100 nationalities, committed to delivering the future of business spending.
Build and maintain technical controls across security and compliance frameworks such as SOC 2, ISO 27001, HIPAA, and other enterprise requirements.
Automate compliance workflows, evidence collection, access reviews, and security checks.
Partner with Engineering and Security to implement controls around access management, infrastructure, data protection, logging, and vulnerability management.
Retell AI is reimagining the call center with cutting-edge voice AI. Backed by Y Combinator, the company has scaled to $60M ARR with a team of 40 people, and is looking for ambitious builders to tackle hard technical problems.
Perform ITGC and application control testing across SOC 2, SOC 1, and HIPAA engagements.
Assist in evaluating the design and effectiveness of IT controls.
Communicate with clients to request evidence, conduct walkthroughs, and clarify audit questions.
Insight Assurance is a global audit firm transforming cybersecurity and compliance. Founded by former Big 4 professionals, it is one of the fastest-growing firms with 170+ professionals serving nearly 2,000 clients.
Own the security program day-to-day, pursuing ISO 27001 certification and FedRAMP readiness.
Manage GRC tool (Vanta), maintain SOC 2 Type II, and run vendor security reviews.
Answer customer security questionnaires and ensure compliance documents are accurate.
Massed Compute is building a modern GPU cloud platform for AI and high-performance compute workloads. We are a lean, ambitious team operating in one of the most important technology markets in the world.
Partner with Engineering to design, implement, and improve security controls across software, application architecture, and AWS infrastructure.
Strengthen security monitoring, detection, incident response, and integrate security into CI/CD pipelines.
Support compliance efforts including SOC 2 and ISO audits, and lead customer security reviews.
AlertMedia helps organizations protect their people, operations, and brand with a modern Risk Intelligence and Response platform. It is a high-growth, PE-backed SaaS company with more than 4,000 clients and a 10-year award-winning culture.
Lead security compliance initiatives across ISO 27001, SOC 2, GDPR, and more.
Conduct internal audits and mentor junior specialists.
Collaborate with product teams to integrate compliance requirements.
Our partner is a fast-growing technology company specializing in security compliance and automation for European businesses. They have a startup culture with a focus on innovation and collaboration.
Lead and mature the GRC program across SOC 2, ISO 27001, PCI DSS, and other compliance frameworks, including audit preparation and evidence collection.
Own the annual security risk assessment process using NIST SP 800-30 methodology, including stakeholder interviews and risk scoring.
Drive security awareness training, AI governance, and Data Loss Prevention program development while collaborating with cross-functional teams.
RainFocus is a rapidly growing software company that provides an industry-disrupting event management platform for Fortune 500 companies like Adobe, Cisco, and IBM. The company is well-funded, growing fast, and building a culture that is challenging, fun, and exciting.
Ensure day-to-day compliance activities across PCI DSS, SOC 2, NIST, GDPR, and ISO frameworks.
Lead preparation and execution of internal and external audits, including evidence collection and remediation tracking.
Perform technical security and compliance reviews of third-party vendors and service providers.
iSeatz drives enduring brand loyalty through digital commerce and technology solutions for travel and lifestyle bookings. The company processes over $9B per year in transactions and has been honored as an Inc. Magazine Best Workplace for three consecutive years, emphasizing transparency, trust, and open communication.