Compliance Manager
Own Anyscale’s compliance function end to end, leading SOC 2 and ISO 27001 programs, audit readiness, customer security diligence, and enterprise risk management. The role requires 7+ years in governance, risk, and compliance plus strong cloud and SaaS security-controls expertise.
About the job
Responsibilities
- Own SOC 2 Type II, ISO 27001, and future compliance framework programs, including scope, evidence, control operation, and external auditor relationships.
- Maintain a complete, audit-ready control evidence base in a compliance automation platform.
- Lead security diligence for enterprise and regulated customers, including questionnaires, audit responses, right-to-audit requests, and recurring reporting.
- Own the security risk register and mature enterprise risk management practices.
- Coordinate customer-contract compliance obligations, including data protection, breach-notification timelines, and vendor and subprocessor assessments, in partnership with legal.
- Assess and establish new certifications based on customer requirements.
- Partner with engineering and IT to integrate evidence collection into normal system operations.
Requirements
- 7+ years of experience in governance, risk, and compliance, ideally in a high-growth startup.
- End-to-end ownership of SOC 2 and ISO 27001 programs and external audits.
- Experience leading security diligence for enterprise or regulated customers.
- Working fluency with compliance automation platforms such as Vanta or equivalent.
- Strong understanding of security controls in cloud and SaaS environments.
- Ability to independently manage programs, coordinate cross-functionally, and serve as the single compliance owner.
Nice to Have
- Experience with contractual security obligations, including data protection agreements, breach notification, and right-to-audit provisions.
- Exposure to higher-bar frameworks such as FedRAMP.
- Experience building a compliance function or team.
- Familiarity with cloud infrastructure, AI, or ML platforms.
Skills
SOC 2, ISO 27001, Governance Risk Compliance, Risk Management, Security Controls, Cloud Security, SaaS, Vanta, Security Questionnaires, FedRAMP, Data Protection, Audit Management
Similar jobs
Security Engineering jobsOwn and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Leads offensive security, threat intelligence, security testing, and incident response across applications, infrastructure, and networks. The role requires at least five years of relevant experience, cloud security expertise, AI and automation experience, and a bachelor's degree.
Own Anyscale’s secure software development lifecycle, partner with engineering on secure architecture and features, and lead vulnerability management and remediation. The role requires 8+ years of product or application security experience and strong hands-on secure-development expertise.
The Senior Application Security Engineer will build secure-by-default software patterns, supply-chain controls, and developer-facing security tooling across a distributed systems platform. The role requires 5+ years of production software experience, strong application security expertise, and depth in Go or Rust.
Build and lead Fireworks AI’s security operations function, owning detection engineering, incident response, threat intelligence, and SecOps workflows. The role requires 7+ years of security experience, hands-on EDR and cloud security expertise, strong Python automation skills, and the ability to grow an IC function into a team.