Security Compliance Manager in New York at Jobgether
Explore Related Opportunities
Job Description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security Compliance Manager based in the United States.
This is a senior, hands-on leadership role responsible for owning and strengthening the organization’s security compliance and GRC function end-to-end. You’ll shape the compliance strategy across major security, privacy, regulatory, and industry frameworks while keeping the business continuously audit- and customer-ready. The role combines strategic program ownership with close collaboration across engineering, IT, product, security, and legal teams. You’ll serve as a trusted point of contact for auditors, regulators, customers, and senior leadership, translating complex risks into clear business implications. You’ll also drive a major FedRAMP initiative, improve control efficiency, and build scalable processes that support a rapidly growing technology environment. As the function develops, you’ll lead and mentor team members while expanding the organization’s compliance capabilities. This remote-first opportunity is ideal for an experienced GRC professional who thrives on ownership, technical fluency, and meaningful business impact.
- Own the strategy, planning, design, and ongoing operation of the security compliance and GRC program across SOC 2 Type II, PCI DSS Level 1 Service Provider, ISO 27001, GDPR, CCPA, and DORA.
- Lead the organization’s FedRAMP authorization efforts, coordinating NIST SP 800-53 control implementation, third-party assessment activities, and continuous monitoring across engineering and IT.
- Serve as the primary point of contact for auditors, regulators, industry stakeholders, and other external reviewers, ensuring assessments and compliance engagements are well planned and successfully executed.
- Partner closely with engineering, IT, product, security, and legal teams to implement effective controls and resolve compliance and risk issues.
- Present compliance objectives, program scope, findings, risks, and outcomes to senior leadership and board-level stakeholders in a clear, concise, and business-focused manner.
- Own the control framework by rationalizing overlapping requirements across standards and maintaining an efficient, coherent, and evidence-focused control environment.
- Manage the security policy and standards library, ensuring documentation remains accurate, relevant, and aligned with regulatory and business requirements.
- Own the organizational risk picture, including the risk register, risk quantification, reporting cadence, remediation tracking, and validation of risk treatment decisions.
- Lead the customer assurance and trust program, including security questionnaires, attestations, and trust documentation, helping ensure security reviews support rather than delay commercial opportunities.
- Coordinate evidence collection, security scans, artifacts, and documentation while identifying opportunities to automate and streamline compliance processes.
- Lead continuous improvement initiatives based on findings from regulators, internal and external reviews, quality assessments, and maturity evaluations.
- Develop sufficient technical and product fluency to understand platform architecture, evaluate control effectiveness, and collaborate with engineering and product teams as a trusted peer.
- Identify creative and scalable approaches to compliance that improve consistency, efficiency, and automation.
- Produce executive-ready documentation, presentations, meeting materials, and reporting for internal and external stakeholders.
- Lead, mentor, and develop the compliance team, including a Security Compliance Analyst, while establishing priorities and scaling the function as regulatory and business requirements evolve.
- 7+ years of experience in security compliance, GRC, audit, or a closely related field, including end-to-end ownership of audit or certification programs.
- Demonstrated experience managing programs such as SOC 2, PCI DSS, and/or ISO 27001 from planning through assessment and ongoing compliance.
- Deep knowledge of security and privacy frameworks, including PCI DSS, SOC 2, ISO 27001, GDPR, CCPA, and DORA.
- Familiarity with broader control frameworks such as NIST Cybersecurity Framework and CIS Controls.
- Strong technical and product aptitude, with the ability to understand complex technology environments and confidently collaborate with engineering and product teams.
- Ability to connect technical controls, security risks, and compliance requirements to real-world business outcomes.
- Exceptional written and verbal communication skills, including the ability to create executive-ready documentation and communicate credibly with auditors, regulators, leadership, and customers.
- Experience working in a fast-paced, high-growth environment; fintech, payments, or similarly regulated technology environments are strongly preferred.
- Strong program management, organizational, analytical, and problem-solving capabilities with a focus on continuous improvement.
- Ability to operate effectively as a strategic leader, cross-functional partner, and hands-on individual contributor depending on the situation.
- Demonstrated experience leading, mentoring, or managing team members, or clear readiness to take ownership of people leadership responsibilities.
- Willingness and ability to travel when required.
- Bonus: Direct experience operating a PCI DSS Level 1 Service Provider compliance program.
- Bonus: Hands-on experience with DORA and operational resilience requirements.
- Bonus: Familiarity with GRC and security tooling, including compliance automation platforms such as Vanta, HRIS platforms such as Rippling, and macOS environments.
- Competitive Compensation: Generous compensation package combining cash and equity.
- Equity Flexibility: Early exercise available for all options, including pre-vested options.
- Remote-First Work: Work from anywhere with a globally distributed, remote-first culture.
- Time Off: Flexible paid time off plus a year-end company break.
- Health Coverage: Health, dental, and vision insurance for employees and dependents in the US and Canada.
- Retirement: 4% 401(k) / RRSP matching for eligible employees in the US and Canada.
- Technology: MacBook Pro delivered directly to your home.
- Home Office: One-time stipend to help equip your workspace with items such as a desk, chair, monitor, and other essentials.
- Meals: Monthly meal stipend.
- Social Connection: Monthly stipend to support social meet-ups.
- Wellness: Annual health and wellness stipend.
- Learning: Annual learning and professional development stipend.
- Career Growth: Opportunity to help build and scale a critical security compliance function within a high-growth technology environment.