Source Job

India

  • Maintain and enhance Anovia's ISO/IEC 27001 ISMS, including policies, controls, risks, and audit coordination.
  • Support SOC 2, HIPAA, and other compliance programs, including vendor assessments, vulnerability management, and incident response.
  • Lead ambiguous technical and operational initiatives from planning through implementation, coordinating stakeholders and driving completion.

Information Security Compliance GRC ISO 27001 Microsoft 365

20 jobs similar to Program Manager-Security Operations & Compliance

Jobs ranked by similarity.

Germany 6w PTO

  • Lead ISO 27001 and SOC 2 audit cycles end-to-end, owning compliance and audit.
  • Own customer trust by responding to security questionnaires and representing InfoSec to enterprise clients.
  • Drive risk management, vendor security, and incident response while building AI-assisted workflows.

We are the first AI-native Employee Experience Platform, helping organizations unlock inspirational communication. Our diverse team of 550+ employees supports over 1,500 customers, and we are a unicorn company valued at over $1 billion.

$100,000–$130,000/yr
Global

  • Take ownership of information security governance, including policies, risk registers, and control documentation.
  • Manage day-to-day security program operations, mentor analysts, and coordinate cross-functional initiatives.
  • Lead incident response, compliance support, and serve as primary counterpart to the vCISO.

Aries is a financial technology company building modern infrastructure and products for active investors and traders. As a growing organization, they are investing in a practical, accountable security program deeply integrated into how the company operates.

$80,208–$83,372/yr
Poland

  • Lead the design, implementation, and maintenance of Hyland's enterprise ISO governance and certification program across multiple certifications, business units, and regions.
  • Drive strategic expansion of ISO scope, including advanced certifications like TISAX and C5, and establish governance models and control ownership across teams.
  • Measure and report ISO program health through metrics, dashboards, and reporting, while providing leadership and mentorship to compliance specialists.

Hyland is the pioneer of the Content Innovation Cloud, delivering enterprise intelligence through solutions that unlock actionable insights and drive automation. Trusted by thousands of organizations worldwide, including many Fortune 100 companies, Hyland has nearly 4,000 employees and fosters an employee-centric, inclusive culture.

$135,000–$145,000/yr
Global

  • Own the IT evidence program across ISO 27001, SOC 1, SOC 2, PCI DSS, and HIPAA for approximately 13 operating sites, managing audits and remediation.
  • Manage vulnerability management end to end, oversee endpoint detection and response, and lead security incident response through to conclusion.
  • Contribute to identity governance across a hybrid cloud and on-premises IdP, overseeing access review and privileged access controls.

Serverfarm is a leading developer and operator of data centers with over 750 locations and key customer relationships in 45 countries. With Manulife Investment Management's acquisition in 2023, the company is positioned for explosive growth and offers a culture of innovation and career development.

Europe 4w PTO

  • Lead and develop the Information Security GRC strategy, roadmap, operating model, and governance cadence.
  • Coordinate SOC 2, DORA/CySEC-related assurance, internal and external audits, and regulatory requests.
  • Build, develop, and manage the GRC team and improve GRC efficiency through automation and reusable evidence.

JustMarkets is an international FinTech company. It is a growing organization with a focus on information security and compliance.

Canada

  • Lead and mature Fullscript's security compliance program across SOC 2, PCI DSS, and HITRUST frameworks.
  • Manage internal and external audits, coordinate remediation efforts, and maintain continuous audit-readiness.
  • Partner cross-functionally with Security, Engineering, Privacy, Legal, and Product to translate compliance requirements into scalable practices.

Fullscript is a health technology company that powers every part of care by providing practitioners with clinical insights, lab interpretations, and high-quality supplements. With over 125,000 practitioners and 10 million patients, they foster a culture of curiosity, collaboration, and putting people first.

$160,000–$180,000/yr
US

  • Lead and mature cybersecurity compliance programs including SOC 2 Type 2 and ISO 27001 readiness.
  • Drive cloud and application security across AWS and Azure, integrating secure SDLC and DevSecOps practices.
  • Manage corporate IT operations, identity and access, and build the cybersecurity team as the organization grows.

Genea is a leader in property technology, providing cloud-based physical security, submeter billing, and on-demand HVAC solutions to over 1 million users across 39 countries. It has been recognized as a Top Workplace from 2021-2025 with a 4.3 Glassdoor rating, fostering a team-oriented and transparent culture.

India Unlimited PTO

  • Own the audit journey for a portfolio of global customers from gap assessment through external audit closure.
  • Identify security and compliance gaps, turning them into practical remediation plans with engineering and leadership teams.
  • Serve as the coordination point between customers and independent auditors, facilitating evidence requests and communication.

Sprinto is an autonomous trust platform that centralizes compliance and security requirements across frameworks, vendors, and customers. Backed by Accel and Elevation, with $31.8M in funding, Sprinto serves over 4,000 organizations and fosters a remote-first culture of ownership and impact.

US

  • Lead and mature the information security program, building on ISO 27001 and SOC 2 foundations.
  • Develop and operationalize security policies, risk management, and incident response.
  • Partner with Engineering and Product to integrate security into software development.

This is a partner company role managed by Jobgether, a platform that uses AI-powered matching to connect candidates with hiring companies. The partner is a rapidly scaling SaaS and cloud technology environment, with a growing security team and established ISO 27001 and SOC 2 programs.

Global

  • Lead and expand the security function across application security, security compliance, infrastructure & cloud security, and business application security.
  • Build and run the AppSec program with AI-assisted code review and integrate security into CI/CD pipelines.
  • Own ISO 27001 and SOC 2 certification, manage audits, and secure cloud and business applications.

Constructor provides an all-in-one platform for education and research using machine intelligence and data science to address educational challenges like access inequality and low engagement. The company is led by a gender-balanced board and fosters an inclusive culture, though employee size is not specified.

Europe 5w PTO

  • Build and maintain compliance frameworks in the Secfix platform, including ISO 27001, TISAX, SOC 2, GDPR, and more.
  • Own internal audits end-to-end for customers, ensuring they are prepared for external audits.
  • Collaborate with product and engineering to translate compliance gaps into structured product work and enhance platform quality.

Secfix automates security compliance for European companies, helping them achieve ISO 27001, GDPR, TISAX, and SOC 2 efficiently. They are a 100% remote team with hubs in Munich, Berlin, and London, recently raised a $12M Series A, and are backed by top VCs.

India

  • Perform cybersecurity and technology risk assessments across systems, vendors, and business processes.
  • Support compliance with SOC 2, HIPAA, HITRUST, and PCI DSS frameworks.
  • Manage third-party risk assessments and track remediation of security findings.

Jobgether is a platform that uses AI-powered matching to connect candidates with job opportunities. They partner with companies to manage applications and hiring processes, offering remote roles and streamlined recruitment.

US

  • Develop and execute enterprise cybersecurity strategy and multi-year security roadmap.
  • Lead cybersecurity risk management, security operations, and incident response programs.
  • Ensure compliance with HIPAA, HITRUST, NIST, and other regulatory frameworks.

Mom's Meals provides home-delivered meal solutions for individuals with health needs. The company values its team members and offers a generous benefits package.

Germany

  • Own and build the group-wide ISMS following BSI standards and ISO 27001 certification.
  • Manage risk, incident response, and security awareness across technical and organizational domains.
  • Work hands-on with IT and engineering teams, ensuring security governance and regulatory compliance.

Vektor Group builds AI platforms for customers in the defence and government sector. It is a startup with flat hierarchies, real ownership, and fast decisions.

US

  • Own end-to-end audit evidence collection and validation across multiple compliance frameworks including FedRAMP, ISO 27001, and SOC 2.
  • Maintain and continuously verify technical controls across GCP, GitHub, and Microsoft 365 environments.
  • Serve as the primary liaison between GRC and technical teams to reduce audit burden and ensure continuous audit readiness.

A-LIGN is a leading provider of cybersecurity compliance programs, offering services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. They are the number one issuer of SOC 2 and HITRUST and a top three FedRAMP assessor, operating in a high-growth, PE-backed environment.

US Unlimited PTO

  • Develop, implement, and manage GRC strategies to support compliance with frameworks like FedRAMP, IRAP, and SOC 2.
  • Lead security assessments, audits, and certification processes, ensuring timely and successful completion.
  • Collaborate with cross-functional teams to integrate GRC requirements into operations and technology.

GitLab is the intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity, improve operational efficiency, and reduce security and compliance risk. More than 50 million registered users and over 50% of the Fortune 100 trust GitLab, driven by a high-performance culture of continuous knowledge exchange.

Global

  • Monitor security systems, logs, and alerts to detect and respond to threats.
  • Run vulnerability scans and coordinate remediation with IT and engineering.
  • Maintain compliance with SOC 2 and support security awareness programs.

Power Digital is an AI-native growth firm combining talent and proprietary technology to help brands drive measurable business outcomes. With a people-first culture, the company values diversity and collaboration, using its AI operating system Omega to amplify capacity for strategy, creativity, and analysis.

Europe

  • Act as Information Security Officer for FinTech, supporting ISO 27001, SOCv2, and DORA implementation.
  • Coordinate security activities across teams, ensuring alignment with cyber security strategy and governance.
  • Track risks, gaps, and remediation, while preparing updates for security leadership.

Coinspaid Dev is the engineering brand behind the technology and infrastructure built within Coinspaid. With over 120 engineers and 11 years of industry experience, the team builds distributed systems and blockchain infrastructure across more than 20 blockchain networks.

$200,000–$245,000/yr
US

  • Own the overall security posture, including policy, standards, and risk framework.
  • Manage ISO 27001, SOC 2, FedRAMP, and CMMC compliance programs.
  • Lead incident response, vulnerability management, and customer security assurance.

RapidFort is a cybersecurity company that helps organizations secure and optimize their software supply chain and containerized environments. As a fast-growing startup, we foster a culture of ownership and direct communication, where every team member contributes to our mission of securing cloud-native applications for regulated industries.

US

  • Own and mature preventative security capabilities across cloud, SaaS, endpoint, identity, network, and data environments.
  • Translate broad security objectives into concrete technical requirements, controls, tooling, and implementation plans.
  • Partner across Engineering, Platforms, Product, and business teams to continuously strengthen security posture as we scale.

Backstory is the leading AI answers platform for sales teams, helping modern sales teams ask questions and get the right answer in real time. Backed by top investors like Andreessen Horowitz and ICONIQ Capital, Backstory is based in San Francisco and has been recognized by Gartner, Forrester, and the Forbes AI 50.