Skip to content
LangChainLangChain

Security Compliance Analyst, Privacy

Build and scale LangChain's privacy compliance program across SOC 2, ISO 27001, GDPR, CCPA, and HIPAA. Partner with engineering and legal to embed controls, manage audits, and support enterprise sales.

About the job

What you'll do

  • Build and automate our compliance operations layer, including evidence pipelines, control monitoring, and agentic systems for always-on visibility into our compliance posture.
  • Work directly with Engineering to embed security and privacy controls into our products, including deletion pipelines, PII detection, access audit logging, and fine-grained data access controls.
  • Maintain and scale our certification and audit programs across SOC 2, ISO 27001, ISO 27701, ISO 42001, HIPAA, GDPR, CCPA, EU-US Data Privacy Framework, and others. Drive audit readiness, identify overlapping requirements, and reuse evidence across frameworks to continuously strengthen our security story.
  • Partner with Legal on security and privacy contract execution, covering DPAs, BAAs, security addenda, and vendor terms. Build the templates, playbooks, and review processes that enable fast, reliable execution in regulated verticals and unblock enterprise sales.
  • Monitor adherence to security and privacy contractual obligations across all signed agreements, building the operational workflows and tracking mechanisms to stay on top of commitments as our customer base grows.
  • Contribute to LangChain's customer trust program — security questionnaire responses, due-diligence reviews, and the trust documentation and whitepapers that give regulated-industry customers confidence in our security posture.
  • Support vendor privacy risk assessments during onboarding and renewals.

What you'll bring

  • 5+ years in privacy, GRC, or security compliance, ideally with time at a Big 4 or advisory firm, or in-house at a high-growth tech company.
  • Hands-on operational experience with privacy regulations and compliance frameworks (GDPR, HIPAA, CCPA, ISO 27001, ISO 27701, SOC 2), including controls mapping, audit support, and day-to-day program operations.
  • Experience with DPAs and BAAs: reviewing, negotiating, or operationalizing them in a commercial context.
  • Technical fluency: comfortable reading code, understanding data flows, validating that controls work as described, and collaborating directly with engineering teams.
  • Exceptional writer. You'll draft policies, respond to security questionnaires, and translate complex requirements into clear guidance for audiences ranging from engineers to executives.

Nice to have

  • Background in a regulated industry (healthcare, finance, government) or working directly with regulated-industry customers.
  • Experience working across multi-cloud deployment environments.
  • Ability to write scripts or code (Python is a strong plus) to automate compliance checks, privacy workflows, or build integrations between security and compliance tooling.
  • Relevant certifications such as CIPM, CIPP/E, CIPP/US, CISA, CISSP, ISO 27001 Lead Implementer, or ISO 27701 Lead Implementer.

Compensation

  • Annual salary range: $175,000 - $220,000 USD
  • Compensation includes base salary, variable compensation for relevant roles, meaningful equity, benefits, and perks.
  • Benefits include medical, dental, and vision coverage, flexible vacation, a 401(k) plan, meals on in-office days in the US and more.

Skills

GDPR, HIPAA, CCPA, ISO 27001, Iso 27701, SOC 2, Dpas, Baas, Python, Cipp/E, Cipp/Us, Cisa, Cissp

Vanta

Vanta

Remote

Manager, Security Operations
$178k+/yrRemote5+ YOESecurity Engineering

Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.

Zoox

Zoox

Foster City, CA

Sensing and Perception System Safety Engineer
$170k+/yrHybrid3+ YOESecurity Engineering

Develops safety requirements, analyses, and fail-operational architectures for autonomous-vehicle sensing and perception systems. The role requires 3+ years analyzing safety-critical systems and familiarity with functional-safety standards, sensing hardware, perception, and cross-functional systems engineering.

Onebrief

Onebrief

United States

Corporate Security Systems Engineer
$180k+/yrRemote4+ YOESecurity Engineering

Own and strengthen Onebrief’s corporate security stack across endpoints, identity, SaaS, Zero Trust, and monitoring. The role emphasizes security automation, configuration-baseline enforcement, telemetry integration, and continuously validated compliance controls.

Greptile

Greptile

San Francisco, CA

Security Engineer
$170k+/yrOn-site3+ YOESecurity Engineering

Own the security posture of a fast-growing developer product across application, infrastructure, cloud, and internal systems. The role requires at least three years of relevant engineering or security experience, strong vulnerability judgment, and hands-on JavaScript or TypeScript expertise.

Exa

Exa

San Francisco, CA

Security Engineer
$180k+/yrOn-siteSecurity Engineering

The Security Engineer will secure cloud infrastructure, engineering systems, APIs, model-training environments, and GPU clusters while supporting rapid delivery. The role requires hands-on cloud security, IAM, secrets and certificate management, compliance ownership, vulnerability monitoring, and incident response experience.