Replit07/11/2026

Руководитель направления управления рисками и соответствием требованиям

Salary not specified
MARKET
13,534median for this role
Tech Lead / Team Lead · 166 jobs with disclosed pay
5,250half of the offers: 9,771–18,1061.2 млн
The employer didn't disclose pay — compare with the market yourself.
Полная занятостьУдалёнка

Responsibilities

  • 01Own the end-to-end certification roadmap (SOC 2 Type II, ISO 27001, and future frameworks like ISO 42001) including scoping, gap assessments, remediation, and audit execution
  • 02Manage relationships with external auditors and drive the annual audit calendar so certifications renew without last-minute scrambles
  • 03Own and maintain the company's master security risk register including risk identification, scoring methodology, treatment plans, and residual risk reporting
  • 04Build and maintain continuous compliance monitoring so control status reflects real-time state rather than point-in-time snapshots
  • 05Own the core audit artifacts that back every certification including ISMS documentation, Statements of Applicability, risk assessments, and potentially FedRAMP System Security Plans (SSPs)
  • 06Run regular audits and readiness assessments, and track remediation of findings and control gaps to closure
  • 07Support GDPR and broader privacy compliance alongside the Legal/Privacy team, without owning the legal interpretation of requirements
  • 08Partner with the GRC Engineer to define what evidence collection and control monitoring should be automated versus manually reviewed
  • 09Track and report on compliance posture and audit findings to security leadership

Requirements

  • 018+ years in security compliance, IT audit, or GRC roles, with direct ownership of at least one SOC 2 and/or ISO 27001 certification cycle
  • 02Working knowledge of common frameworks (SOC 2, ISO 27001, NIST CSF) and how to map controls across them
  • 03Hands-on experience authoring or substantially maintaining an ISMS, SSP, or equivalent audit-facing documentation set and not just filling out a template
  • 04Experience owning a formal risk register including risk identification, scoring methodology, treatment plans, and residual risk reporting to leadership
  • 05Experience with GRC/compliance automation platforms (e.g., Anecdotes, Vanta, Drata, etc.) and continuous control monitoring
  • 06Experience working directly with external auditors and managing an audit end to end
  • 07Comfortable reading technical control evidence and having detailed conversations with engineers about how systems actually work
  • 08Working familiarity with GDPR/privacy fundamentals sufficient to partner effectively with a legal team

What we offer

  • 01Full-time role
  • 02Can be held from Foster City, CA office
  • 03In-office requirement of Monday, Wednesday, and Friday
  • 04Competitive Salary & Equity
  • 05401(k) Program with a 4% match (US Only)
  • 06Health, Dental, Vision and Life Insurance
  • 07Short Term and Long Term Disability
  • 08Paid Parental, Medical, Caregiver Leave
  • 09Flexible Time Off (FTO) + Holidays
  • 10Commuter Benefits (In-Office Only)
  • 11Monthly Wellness Stipend
  • 12Autonomous Work Environment
  • 13In Office Set-Up Reimbursement (In-Office Only)
  • 14Quarterly Team Gatherings
  • 15In Office Amenities (In-Office Only)