Jobgether
Compliance Engineering Lead
legalfull-timeUS
SALARY
Not listed
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
general
✦ AutoApply Sick of applying? We apply to roles like this for you, up to 20 a month.
Learn more
About the role
Accountabilities
- Own the SOC 2 Type II program end to end, including audit scope, observation periods, auditor relationships, evidence collection, controls, findings, and the final customer-facing report.
- Lead the organization through ISO 27001 certification, including defining the scope and ISMS, conducting gap assessments and internal audits, preparing teams, achieving certification, and maintaining an effective management system afterward.
- Build a continuous and automated evidence-collection infrastructure using APIs and systems of record such as cloud platforms, source-control systems, identity providers, MDM, and ticketing tools.
- Develop scheduled control tests and monitoring that identify configuration drift or control failures quickly, replacing recurring manual compliance work with reliable automation.
- Own and mature enterprise risk and third-party vendor risk programs, including risk registers, vendor tiering, assessments, reviews, renewal cadences, and executive reporting.
- Lead the customer-facing security assurance function, including the trust portal and security documentation library, with the goal of proactively addressing enterprise customer requirements and reducing questionnaire volume.
- Evaluate and shape the organization’s AI assurance strategy, assessing frameworks and regulations such as ISO/IEC 42001, AI assurance standards, the EU AI Act, and the NIST AI Risk Management Framework.
- Partner closely with Security, Engineering, Legal, and Go-to-Market teams to identify and resolve compliance gaps across organizational boundaries.
- Own the compliance technology strategy, evaluating existing GRC platforms and determining where purchasing, integrating, or building internal capabilities provides the greatest leverage.
- Hire, develop, and lead an initial customer-trust team member focused on security questionnaires, RFPs, and contract security reviews.
- Establish clear ownership, documentation, service levels, and repeatable processes so compliance becomes an embedded operational capability rather than an audit-time exercise.
- Proven SOC 2 Type II ownership: personally accountable for at least two complete SOC 2 Type II cycles, including auditor management, scoping, evidence, controls, and remediation of findings.
- Strong ISO 27001 expertise: experience taking an organization through certification or managing an ISMS through surveillance audits, with a practical understanding of how to make the system operationally effective.
- Compliance automation experience: comfortable building and maintaining automations against APIs and operational systems; you naturally look for opportunities to replace repetitive manual processes with scheduled, reliable workflows.
- Hands-on experience with GRC and compliance platforms such as Drata, Vanta, or comparable solutions, combined with sound judgment about their strengths and limitations.
- Strong risk prioritization skills, with the ability to distinguish meaningful security and compliance risks from lower-value administrative or audit preferences.
- Excellent written and verbal communication skills, with the ability to produce clear materials for auditors, enterprise security teams, engineers, and executive stakeholders.
- A strong ownership mindset and willingness to solve ambiguous, cross-functional problems at the intersection of Security, Engineering, Legal, and Go-to-Market.
- Experience working effectively in a remote, fast-moving environment where priorities evolve and processes may need to be created from the ground up.
- Ability to balance strategic program ownership with hands-on execution, including automation, control testing, evidence management, and operational improvements.
- Preferred: exposure to AI governance frameworks such as ISO/IEC 42001, NIST AI RMF, or the EU AI Act; experience within a security vendor or highly scrutinized enterprise environment; contract security review experience; or experience building compliance automation internally.
- Market-competitive salary bands.
- Meaningful equity program.
- Comprehensive health benefits for employees and their families, with 99% coverage.
- Flexible time off, paid holidays, and a winter shutdown for rest and recharge.
- Paid parental leave.
- Remote-first working environment.
- Quarterly team off-sites.
- An ownership-driven culture emphasizing excellence, urgency, rigorous thinking, trust, collaboration, and customer focus.
- Significant autonomy and the opportunity to shape a foundational compliance and GRC function.
Requirements:
Benefits:
✦ Sick of applying to 40 jobs a month?
I rewrite your resume for ATS by hand first. Once you sign off on it, AutoApply applies to up to 20 roles like this a month, cover letter in your own voice each time. From $14.99/mo, cancel anytime.
Get AutoApply