Source Job

US Unlimited PTO

  • Build & own Treeline's internal security and compliance program.
  • Deliver compliance outcomes directly for customers.
  • Help build and grow Treeline's Compliance-as-a-Service (CaaS) offering.

SOC 2 ISO 27001 FedRAMP

18 jobs similar to Head of Compliance

Jobs ranked by similarity.

US

  • Apply compliance frameworks to assess, design, and implement security controls.
  • Conduct compliance gap assessments and develop remediation plans.
  • Create and maintain key documentation tailored to client needs.

AHEAD builds platforms for digital business by weaving together advances in cloud infrastructure, automation and analytics, and software delivery. They prioritize creating a culture of belonging where all perspectives and voices are represented, valued, respected, and heard.

$190,000–$230,000/yr
US Unlimited PTO 14w maternity 14w paternity

  • Own security posture, compliance programs, and audit readiness.
  • Lead all IT functions supporting corporate and program needs.
  • Provide guidance and escalation support for IT hardware/software issues as needed.

Red Cell Partners is an incubation firm building and investing in rapidly scalable technology-led companies. They bring revolutionary advancements to market in healthcare, cyber, and national security and are united by a shared sense of duty.

US Unlimited PTO

  • Ownership of our SOC 2 and Privacy compliance roadmap, from problem framing to tracking adoption.
  • Gap analysis and consulting with clients to assess their InfoSec posture and provide actionable paths to certification.
  • Internal playbook development, creating the checklists, policy templates, and controls that will be automated within our software.

Greenplaces helps companies navigate reporting requirements. They empower businesses to measure their carbon emissions and act as the definitive source of truth for all sustainability and compliance activity. They are headquartered in Raleigh, NC, with a distributed team across the country and backed by world-class investors.

Global

  • Track and drive audit partners through the onboarding and enablement lifecycle; maintain internal trackers and coordinate across teams.
  • Keep the auditor directory accurate and current; verify accreditation status and update partner profiles.
  • Assist the SME in mapping audit evidence requirements to platform capabilities; prepare reference data and document findings.

Sprinto is an AI-native GRC platform that helps organizations manage risks, audits, vendor oversight, and continuous monitoring from a single connected platform. With a team of 350+ employees serving 3,000+ customers across 75+ countries, they combine scale with expertise to deliver trust and compliance.

North America Europe Unlimited PTO

  • Lead Craft’s FedRAMP readiness program — defining the roadmap, owning the ATO timeline, and driving execution across engineering and security stakeholders.
  • Design and implement AWS GovCloud architecture that meets FedRAMP Moderate and High requirements.
  • Translate NIST 800-53 Rev. 5 controls into concrete, auditable, and continuously enforced technical implementations — not just documentation.

Craft is the leader in supplier risk intelligence, enabling enterprises to discover, evaluate, and continuously monitor their suppliers at scale. They are a post-Series B high-growth technology company backed by top-tier investors in Silicon Valley and Europe, headquartered in San Francisco with hubs in Seattle and Warsaw.

US Unlimited PTO

  • Support security and compliance programs aligned with frameworks such as NIST, ISO, PCI DSS, and HIPAA.
  • Assist in maintaining alignment with global privacy regulations (GDPR, CCPA, and similar frameworks).
  • Assist in the development, implementation, and maintenance of security, privacy, and AI governance policies, standards, and procedures.

Hims & Hers is a health and wellness platform with a mission to help the world feel great through the power of better health. They are redefining healthcare by putting the customer first and delivering access to care that is affordable, accessible, and personal.

Global

  • Accelerate Onebrief’s execution of GRC programs supporting NIST RMF, FedRAMP High, CMMC, and SOC2 authorizations
  • Develop and manage integrated project plans for control implementation, remediation, and continuous monitoring
  • Coordinate cross-functional teams (Infrastructure, Engineering, Product) to ensure timely delivery of compliance requirements

Onebrief provides collaboration and AI-powered workflow software designed specifically for military staffs, aiming to make them faster, smarter, and more efficient. Valued at $2.15B, the company has raised $320m+ from top-tier investors and operates as an all-remote company.

$190,000–$230,000/yr
US Unlimited PTO 14w maternity

  • Own CMMC 2.0 and SOC 2 end-to-end, including control design and implementation.
  • Lead all IT functions supporting corporate and program needs, owning IT architecture and tooling decisions.
  • Provide guidance and escalation support for IT hardware/software issues; mentor IT Support Specialist & Cloud Infrastructure Engineer.

DEFCON AI leverages artificial intelligence, mathematical optimization, data analytics, and software engineering for resilient optimization of complex systems. They align outcomes with operational goals, better decision making, and empower customers to anticipate, assess, and mitigate the impacts of disruptions.

Global

  • Lead end-to-end PCI DSS compliance, including CDE scoping and reduction, control implementation/validation, and audit management.
  • Lead and support SOC 2 Type II attestation initiatives, including TSC mapping, evidence collection, control testing, and remediation tracking
  • Own the Third-Party Risk Management (TPRM) program, including vendor tiering, risk assessments, and security reviews

HighLevel is an AI-powered business operating system that gives agencies, entrepreneurs and SMBs the infrastructure to build, automate and scale. With over 2,000 team members across 10+ countries, HighLevel operates as a global, remote-first organization built for speed and ownership.

India

  • Own end-to-end compliance strategy and operations.
  • Conduct risk assessments and identify compliance risks.
  • Build compliance programs from ground up and coordinate compliance audits.

Sprinto is an AI-native GRC platform that helps organizations manage risks, audits, vendor oversight, and continuous monitoring from a single connected platform. With a team of 350+ employees serving 3,000+ customers across 75+ countries, Sprinto combines scale with expertise to deliver trust and compliance.

US

  • Define and evolve security governance and risk management strategy, aligning function-level priorities with enterprise objectives and the security roadmap.
  • Lead security-related audits, assessments, and regulatory inquiries in partnership with Legal, Compliance, Privacy, and Internal Audit.
  • Manage and hold accountable a third-party GRC services vendor, ensuring delivery quality, prioritization, and alignment to Clover’s risk appetite.

Clover Health is reinventing health insurance by combining data with human empathy to keep members healthier. They've created custom software and analytics to empower their clinical staff to intervene and provide personalized care. Those who work at Clover are passionate and mission-driven individuals with diverse areas of expertise, working together to solve the most complicated problem in the world: healthcare.

Global

  • Develop, maintain, and continuously improve GRC policies, standards, procedures, and control frameworks.
  • Lead and support SOC 2 Type II, ISO 27001, PCI DSS and other compliance initiatives, including evidence collection, control validation, and remediation tracking.
  • Partner with Security and Platform teams to ensure controls are technically implemented, not just documented.

HighLevel is an AI powered, all-in-one white-label sales & marketing platform that empowers agencies, entrepreneurs, and businesses to elevate their digital presence and drive growth. With over 1,500 team members across 15+ countries, we operate in a global, remote-first environment.

$105,000–$130,000/yr
US 3w PTO

  • Responsible for LINK’s day-to-day IT operations, cybersecurity program, and regulatory compliance posture.
  • Primary internal owner of IT governance and federal compliance, leading the organization through its Cybersecurity Maturity Model Certification (CMMC) Level 2 third-party assessment.
  • Build repeatable processes and a maturing IT infrastructure that supports LINK’s continued growth as a government contractor.

LINK is a fast-growing Woman Owned Small Business (WOSB) that leverages human-centered design to support strategy, innovation, communication, change, and branding within the federal government and adjacent industry partners. They partner with engineers, futurists, and thought leaders to untangle complexity, discover opportunity, and communicate clearly with visual stories.

Poland

  • Safeguard assets and global reputation, acting as a strategic partner.
  • Lead risk mitigation strategies and ensure compliance with global standards.
  • Develop a world-class GRC program that aligns with strategic goals.

EcoVadis is the leading provider of business sustainability ratings. Our solutions are backed by an international team of experts and powerful technology. They analyze data and build sustainability scorecards that give companies actionable insights into their environmental, social and ethical risks.

  • Support client engagements related to CMMC readiness, implementation, and documentation
  • Develop, update, and maintain System Security Plans (SSPs)
  • Assist with NIST SP 800-171, NIST SP 800-53, and FedRAMP documentation, control mapping, and related deliverables

Hotman Group is a remote boutique cybersecurity and GRC firm supporting clients across a range of industries and compliance needs. They value strong writing, quality work, collaboration, sound judgment, and practical execution.

$83,430–$109,232/yr
US Unlimited PTO

  • Implement and manage the NIST Risk Management Framework (RMF) to achieve and maintain compliance.
  • Drive the data privacy program by conducting Privacy Impact Assessments (PIAs) and Data Protection Impact Assessments (DPIAs).
  • Design and execute a continuous internal audit program to validate the effectiveness of controls.

IonQ delivers solutions to solve the world’s most complex problems with quantum computing. IonQ's newest generation quantum computers, IonQ Tempo and IonQ Forte Enterprise, help customers and partners such as Amazon Web Services, AstraZeneca, and NVIDIA achieve 20x performance results.

Global

  • Implement and maintain enterprise security tooling and approved configuration baselines across endpoints, browsers, SaaS platforms, and identity systems.
  • Partner with Corporate Security Engineering leadership and Vulnerability Management to ensure configuration controls and remediation efforts are aligned, measurable, and enforceable.
  • Continuously improve security configurations by reducing drift, expanding automation, and strengthening documentation and evidence collection to support audit readiness.

Onebrief provides collaboration and AI-powered workflow software specifically for military staffs, enhancing their speed, intelligence, and efficiency. It's a remote-first company with a team of veterans and technologists, valued at $2.15B, backed by top-tier investors.

India Unlimited PTO

  • Build the function, create delivery operating model, and build reusable IP.
  • Deliver and scale service lines, and own commercial outcomes.
  • Create “AI-assisted playbooks” for repeatable services and ensure quality and manage risk.

Sprinto is an AI-native GRC platform that helps organizations manage risks, audits, vendor oversight, and continuous monitoring from a single connected platform. With a team of 350+ employees serving 3,000+ customers across 75+ countries, Sprinto combines scale with expertise to deliver trust and compliance.