Jobgether
Jobgether

Compliance Engineering Lead

legalfull-timeUS
SALARY
Not listed
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
general
Apply for this position
✦ AutoApply Sick of applying? We apply to roles like this for you, up to 20 a month.
Learn more

About the role

Accountabilities

    • Own the SOC 2 Type II program end to end, including audit scope, observation periods, auditor relationships, evidence collection, controls, findings, and the final customer-facing report.
    • Lead the organization through ISO 27001 certification, including defining the scope and ISMS, conducting gap assessments and internal audits, preparing teams, achieving certification, and maintaining an effective management system afterward.
    • Build a continuous and automated evidence-collection infrastructure using APIs and systems of record such as cloud platforms, source-control systems, identity providers, MDM, and ticketing tools.
    • Develop scheduled control tests and monitoring that identify configuration drift or control failures quickly, replacing recurring manual compliance work with reliable automation.
    • Own and mature enterprise risk and third-party vendor risk programs, including risk registers, vendor tiering, assessments, reviews, renewal cadences, and executive reporting.
    • Lead the customer-facing security assurance function, including the trust portal and security documentation library, with the goal of proactively addressing enterprise customer requirements and reducing questionnaire volume.
    • Evaluate and shape the organization’s AI assurance strategy, assessing frameworks and regulations such as ISO/IEC 42001, AI assurance standards, the EU AI Act, and the NIST AI Risk Management Framework.
    • Partner closely with Security, Engineering, Legal, and Go-to-Market teams to identify and resolve compliance gaps across organizational boundaries.
    • Own the compliance technology strategy, evaluating existing GRC platforms and determining where purchasing, integrating, or building internal capabilities provides the greatest leverage.
    • Hire, develop, and lead an initial customer-trust team member focused on security questionnaires, RFPs, and contract security reviews.
    • Establish clear ownership, documentation, service levels, and repeatable processes so compliance becomes an embedded operational capability rather than an audit-time exercise.
    • Requirements:

      • Proven SOC 2 Type II ownership: personally accountable for at least two complete SOC 2 Type II cycles, including auditor management, scoping, evidence, controls, and remediation of findings.
      • Strong ISO 27001 expertise: experience taking an organization through certification or managing an ISMS through surveillance audits, with a practical understanding of how to make the system operationally effective.
      • Compliance automation experience: comfortable building and maintaining automations against APIs and operational systems; you naturally look for opportunities to replace repetitive manual processes with scheduled, reliable workflows.
      • Hands-on experience with GRC and compliance platforms such as Drata, Vanta, or comparable solutions, combined with sound judgment about their strengths and limitations.
      • Strong risk prioritization skills, with the ability to distinguish meaningful security and compliance risks from lower-value administrative or audit preferences.
      • Excellent written and verbal communication skills, with the ability to produce clear materials for auditors, enterprise security teams, engineers, and executive stakeholders.
      • A strong ownership mindset and willingness to solve ambiguous, cross-functional problems at the intersection of Security, Engineering, Legal, and Go-to-Market.
      • Experience working effectively in a remote, fast-moving environment where priorities evolve and processes may need to be created from the ground up.
      • Ability to balance strategic program ownership with hands-on execution, including automation, control testing, evidence management, and operational improvements.
      • Preferred: exposure to AI governance frameworks such as ISO/IEC 42001, NIST AI RMF, or the EU AI Act; experience within a security vendor or highly scrutinized enterprise environment; contract security review experience; or experience building compliance automation internally.
      • Benefits:

        • Market-competitive salary bands.
        • Meaningful equity program.
        • Comprehensive health benefits for employees and their families, with 99% coverage.
        • Flexible time off, paid holidays, and a winter shutdown for rest and recharge.
        • Paid parental leave.
        • Remote-first working environment.
        • Quarterly team off-sites.
        • An ownership-driven culture emphasizing excellence, urgency, rigorous thinking, trust, collaboration, and customer focus.
        • Significant autonomy and the opportunity to shape a foundational compliance and GRC function.
✦ Sick of applying to 40 jobs a month?
I rewrite your resume for ATS by hand first. Once you sign off on it, AutoApply applies to up to 20 roles like this a month, cover letter in your own voice each time. From $14.99/mo, cancel anytime.
Get AutoApply
Apply now
Compliance Engineering Lead at Jobgether — Remote