Sierra13.02.2026
Security and Compliance Manager
Зарплата не указана
Полная занятостьОфис
Обязанности
- 01Own independent audits and regulatory programs including ISO 42001, PCI DSS, NIST 800-53, FedRAMP, HIPAA, and related frameworks
- 02Drive scope definition, readiness assessments, auditor engagement, remediation planning, and executive level reporting
- 03Develop a strong working understanding of Sierra’s Conversational AI Platform, model providers, and cloud architecture
- 04Partner with Platform and Agent Engineering to design and operationalize controls across multi cloud environments, infrastructure, inference and data platforms
- 05Build a centralized and evolving security controls library mapped to compliance, regulatory and customer requirements
- 06Continuously assess control effectiveness, identify gaps, prioritize risk, and drive remediation that strengthens Sierra’s security and compliance posture
- 07Define and enforce security baselines for cloud infrastructure, containerized workloads, Kubernetes, identity, encryption, logging, and network security controls
- 08Partner with engineering teams to integrate security requirements into configuration and change management
- 09Design and operate automated compliance workflows using AI, infrastructure as code, and security tooling to reduce manual effort, improve control assurance, and scale with platform evolution
- 10Act as a strategic partner to Platform, Product, Agent Development, Legal, and GTM, ensuring security and compliance requirements are embedded into architecture decisions, product roadmaps, and go to market execution
Требования
- 018+ years of experience in security compliance or GRC or security adjacent roles within fast growing technology companies
- 02Deep expertise in security compliance frameworks including ISO 42001, PCI DSS, NIST 800-53, FedRAMP, and similar regulatory environments
- 03A systems oriented and engineering focused GRC mindset, with the ability to reason about cloud architecture, data flows, and control effectiveness alongside engineers
- 04Experience owning complex audits and driving risk based remediation across distributed teams
- 05Hands-on experience with multi-cloud infrastructure (AWS, Azure, GCP)
- 06Strong experience implementing and automating security controls across cloud infrastructure, configuration management, container security, Kubernetes, encryption, identity, and authentication systems
- 07Ability to clearly communicate compliance requirements internally to engineering teams and externally to customers in a technically credible way
- 08Relevant certifications such as CISSP, CISA, PCI ISA, ISO 27001 Lead Auditor, or equivalent experience
- 09Experience supporting AI platforms, fintech, healthcare, or other highly regulated environments
- 10Familiarity with global regulatory environments including GDPR, DORA, the EU AI Act, and emerging security and AI governance requirements across APAC regions
- 11Experience supporting public sector or FedRAMP aligned environments
Условия
- 01Operate at the center of AI systems, cloud infrastructure, and global compliance
- 02High ownership and deep technical partnership with engineering
- 03Opportunity to define what strong GRC looks like at Sierra