Own and strengthen the controls environment, ensuring compliance requirements are effectively implemented and maintained.
Support and mature the GRC program, including SOC 2 operations and alignment with frameworks such as NIST.
Manage vendor risk assessments, regulatory licensing, and security issue lifecycle across jurisdictions.
Mesh enables consumers to pay and be paid with any asset, bridging crypto payments into everyday commerce. Backed by investors like PayPal Ventures and Paradigm, the company is building infrastructure for the global economy with a small, fast-moving team.
Lead control implementation and audit readiness across multiple compliance frameworks including FedRAMP, SOC 2, ISO 27001, and TISAX.
Partner with engineering, product, and security teams to translate compliance requirements into practical controls.
Represent the compliance program in customer-facing discussions and security due diligence reviews.
Rescale is pioneering the future of engineering and scientific discovery through intelligent automation, applied AI, and data management. We are a diverse, collaborative, and mission-driven team that unlocks innovation across aerospace, energy, life sciences, and manufacturing industries.
Lead and mature the GRC program across SOC 2, ISO 27001, PCI DSS, and other compliance frameworks, including audit preparation and evidence collection.
Own the annual security risk assessment process using NIST SP 800-30 methodology, including stakeholder interviews and risk scoring.
Drive security awareness training, AI governance, and Data Loss Prevention program development while collaborating with cross-functional teams.
RainFocus is a rapidly growing software company that provides an industry-disrupting event management platform for Fortune 500 companies like Adobe, Cisco, and IBM. The company is well-funded, growing fast, and building a culture that is challenging, fun, and exciting.
Own the security compliance program end-to-end, including audits, customer trust, vendor risk, and vulnerability management.
Automate evidence collection and control monitoring to be audit-ready year-round, not just during the August–November season.
Act as the external security face for enterprise prospects and translate AI regulatory changes into requirements.
Ada is an AI customer service company that helps enterprises automate customer conversations with AI agents. Founded in 2016, we've powered over 5.5 billion interactions and raised over $250M from top investors.
Drive end-to-end execution of GRC programs, leading audit strategy and cross-functional compliance projects.
Manage internal risk workflows, evidence collection, and remediation efforts for audits like SOC 2 and PCI DSS.
Translate regulatory requirements into actionable business processes and enable engineering teams to embed security controls.
They are a global leader in event ticketing technology, transforming ticketing for major events like the Grammys and Golden Globes. With over 160 employees and six offices worldwide, they have received over $65 million in funding and are known for their fast-growing, merit-driven culture.
Own GRC workstreams from initial request through evidence collection, testing, and remediation.
Test security controls and conduct risk assessments to identify gaps and drive realistic remediation.
Support audits, vendor reviews, customer questionnaires, and policy maintenance across teams.
YipitData is a leading market research and analytics firm for the disruptive economy, providing actionable insights from alternative data. The company has a global presence with offices in the US, APAC, and India, and is recognized as an Inc. Best Workplace for three consecutive years, emphasizing transparency, ownership, and continuous mastery.
Own the compliance programs and audits end to end, including SOC 2, PCI DSS, GDPR, and ISO 27001.
Manage identity and access, device fleet, and vendor security with ownership over control state.
Drive compliance as a sales enabler and own the customer-facing security package.
Footprint is the agentic platform that learns compliance programs and runs them end to end for banks and fintechs. The team is small, senior, and ships fast.
Automate governance, risk, and compliance frameworks including ISO 27001, PCI-DSS, DORA, and UK Cyber Essentials.
Engineer GRC workflows with internal systems to support compliance by design.
Translate compliance requirements into technical specifications for engineering teams and non-technical stakeholders.
Pleo builds spend solutions that make managing money seamless for finance teams and employees. They are a driven, progressive team of 850+ people from over 100 nationalities, committed to delivering the future of business spending.
Own the security program day-to-day, pursuing ISO 27001 certification and FedRAMP readiness.
Manage GRC tool (Vanta), maintain SOC 2 Type II, and run vendor security reviews.
Answer customer security questionnaires and ensure compliance documents are accurate.
Massed Compute is building a modern GPU cloud platform for AI and high-performance compute workloads. We are a lean, ambitious team operating in one of the most important technology markets in the world.
Drive compliance, risk management, and security assurance as a GRC Specialist.
Own third-party risk management and maintain security documentation.
Support audits, self-assessments, and customer security inquiries.
Avid provides technology and collaboration tools for creators to entertain, inform, educate, and enlighten the world. The company fosters a culture of passion, customer focus, and innovation, with employees who believe in their mission.
Own and continuously improve Camunda's Information Security Management System (ISMS), driving measurable improvements.
Drive security audit cycles for ISO 27001, SOC 2, and future frameworks with minimal supervision.
Review information security requirements in customer contracts and lead responses to complex security questionnaires.
We are the enterprise platform for agentic orchestration, enabling organizations to coordinate AI agents, people, and systems across complex business processes. We are a fully remote, global team trusted by over 700 organizations, named a GP Bullhound Next Unicorn and Great Place to Work certified.
Ensure day-to-day compliance activities across PCI DSS, SOC 2, NIST, GDPR, and ISO frameworks.
Lead preparation and execution of internal and external audits, including evidence collection and remediation tracking.
Perform technical security and compliance reviews of third-party vendors and service providers.
iSeatz drives enduring brand loyalty through digital commerce and technology solutions for travel and lifestyle bookings. The company processes over $9B per year in transactions and has been honored as an Inc. Magazine Best Workplace for three consecutive years, emphasizing transparency, trust, and open communication.
Own the audit journey for a portfolio of global customers from gap assessment through external audit closure.
Identify security and compliance gaps, turning them into practical remediation plans with engineering and leadership teams.
Serve as the coordination point between customers and independent auditors, facilitating evidence requests and communication.
Sprinto is an autonomous trust platform that centralizes compliance and security requirements across frameworks, vendors, and customers. Backed by Accel and Elevation, with $31.8M in funding, Sprinto serves over 4,000 organizations and fosters a remote-first culture of ownership and impact.
Build and own federal compliance frameworks for FedRAMP, NIST, and CMMC.
Interpret controls at the mechanics level and author precise technical guidance.
Lead Vanta's machine-readable future with OSCAL and FedRAMP 20x.
Vanta helps businesses earn and prove trust by automating security monitoring and compliance. Founded in 2018, the company has a kind and talented team and is used by thousands of companies.
Manage the Compliance and Security workstream, coordinating SOC 2, ISO 27001, GDPR, and related audit-readiness activities.
Build and maintain execution plans with clear owners, milestones, dependencies, risks, and decision points.
Facilitate workshops, track evidence, and escalate risks to keep audits on schedule.
Miratech is a global IT services and consulting company that helps visionaries change the world through digital transformation. With nearly 1000 full-time professionals across 25+ countries, the company maintains a culture of Relentless Performance and has achieved over 99% project success since 1989.
Lead and advance governance, risk management, compliance, and information security programs to support organizational objectives and regulatory requirements.
Manage vulnerability management, third-party risk, security governance, policy development, and AI governance initiatives.
Partner with leaders to foster a culture of accountability, risk awareness, and continuous improvement.
Ultimate Medical Academy is a non-profit healthcare educational institution with a national presence, headquartered in Tampa, Florida and founded in 1994. The organization offers online and on-campus programs and fosters a culture of integrity, student success, and team member development.
Build and maintain technical controls across security and compliance frameworks such as SOC 2, ISO 27001, HIPAA, and other enterprise requirements.
Automate compliance workflows, evidence collection, access reviews, and security checks.
Partner with Engineering and Security to implement controls around access management, infrastructure, data protection, logging, and vulnerability management.
Retell AI is reimagining the call center with cutting-edge voice AI. Backed by Y Combinator, the company has scaled to $60M ARR with a team of 40 people, and is looking for ambitious builders to tackle hard technical problems.
Maintain and mature the ISMS, including the Statement of Applicability, risk treatment plans, and Management Review Meetings.
Support ISO 27001 and SOC 2 Type 2 audits from readiness through certification, including evidence preparation.
Lead the security policy program and collaborate across teams to translate compliance requirements into practical practices.
Mozilla Corporation is a non-profit-backed tech company behind Firefox, focused on making the internet better. With 225+ million monthly users, it is a wholly owned subsidiary of the Mozilla Foundation, promoting privacy, AI, and open-source.
Manage a focused portfolio of delivery partners across security assurance, advisory, and legal verticals.
Execute and improve Delivery Partnerships playbooks covering onboarding, engagement, co-sell motions, and partner enablement.
Coordinate between delivery partners and Sprinto's product, customer experience, and sales teams to translate partner needs into feedback.
Sprinto is an Autonomous Trust Platform that centralizes trust requirements across security frameworks, vendors, and customers. Backed by top-tier investors such as Accel, Elevation, and Blume Ventures, it has raised $31.8M and is trusted by over 4,000 organizations across 75 countries.
Act as a regional anchor for security compliance, managing controls and audits.
Develop and maintain security documentation, including policies and metrics.
Implement AI and automation to streamline compliance and security work.
Airwallex provides a unified payments and financial platform for global businesses, empowering over 250,000 companies with integrated solutions. With over 2,300 employees across 27 global offices, the company values innovation and ambitious work.