Security Compliance Manager
Own and scale Sardine’s security compliance and GRC function across major security, privacy, and resilience frameworks, including FedRAMP. The role leads audits, risk management, customer assurance, executive reporting, and a growing compliance team while partnering closely with technical and business stakeholders.
About the job
Responsibilities
- Own the security compliance and GRC program across SOC 2 Type II, PCI DSS Level 1 Service Provider, ISO 27001, GDPR, CCPA, and DORA.
- Drive the FedRAMP authorization effort, including NIST SP 800-53 control implementation, 3PAO assessment coordination, and continuous monitoring.
- Serve as the primary contact for auditors, regulators, and industry stakeholders.
- Partner with engineering, IT, product, security, and legal teams to achieve successful reviews and audit outcomes.
- Present objectives, scope, results, and the business impact of control gaps to senior management and the board through the CISO.
- Own the control framework, security policies, standards library, risk register, risk quantification, and reporting cadence.
- Lead the customer assurance and trust program, including security questionnaires, attestations, and trust artifacts.
- Coordinate evidence, scans, and artifacts, and drive improvements based on findings, quality reviews, and maturity assessments.
- Build sufficient product and technical fluency to make informed control and risk decisions and collaborate effectively with engineering and product teams.
- Identify opportunities for consistency, streamlining, and automation.
- Produce executive-ready documentation and presentations and facilitate effective meetings with regulators and internal stakeholders.
- Lead, mentor, and develop the security compliance team, initially including a Security Compliance Analyst.
Requirements
- 7+ years of experience in security compliance, GRC, or audit.
- End-to-end ownership of audit or certification programs such as SOC 2, PCI DSS, and/or ISO 27001.
- Deep knowledge of PCI DSS, SOC 2, ISO 27001, GDPR, CCPA, and DORA.
- Familiarity with NIST CSF and CIS control frameworks.
- Technical and product fluency, with the ability to collaborate as a peer with engineering and product teams.
- Excellent written and verbal communication skills, executive-ready documentation ability, and credible presence with auditors, regulators, and leadership.
- Experience in a fast-paced, high-growth environment; fintech or payments experience is strongly preferred.
- Ability to operate as a leader, partner, and individual contributor as needed.
- Willingness to travel as needed.
- Experience leading, mentoring, or managing others, or clear readiness to manage a direct report.
Nice-to-haves
- Direct experience running a PCI DSS Level 1 service provider program.
- Hands-on exposure to DORA operational-resilience requirements.
- Familiarity with GRC and security tooling, including Vanta.
- Familiarity with Rippling and macOS environments.
Compensation and Benefits
- Compensation in cash and equity.
- Early exercise for all options, including pre-vested options.
- Remote-first culture and work-from-anywhere flexibility.
- Flexible paid time off and year-end break.
- Health, dental, and vision coverage for employees and dependents in the United States and Canada.
- 4% 401(k)/RRSP matching in the United States and Canada.
- MacBook Pro, home-office setup stipend, monthly meal stipend, monthly social-meetup stipend, annual health and wellness stipend, and annual learning stipend.
Skills
SOC 2, Pci Dss, ISO 27001, GDPR, CCPA, Dora, FedRAMP, Nist Sp 800-53, Nist Csf, Cis Controls, Vanta, Risk Management, GRC
Similar jobs
Security Engineering jobsBuild detection, threat-hunting, and automated incident-response capabilities for AI infrastructure, including GPU clusters, training pipelines, and model deployments. The role requires substantial security operations experience, strong programming skills, and expertise in distributed systems or AI/ML environments.
Senior Cloud Security Engineer responsible for designing, implementing, and assessing security controls across a multi-cloud environment. The role requires 5+ years of security solution implementation experience, strong cloud and cybersecurity expertise, and proficiency in risk assessment, infrastructure as code, and security technologies.
Senior Security Compliance Engineer supporting public-sector compliance programs, regulated customers, audits, certifications, and FedRAMP continuous monitoring. Requires 5+ years in GRC or cybersecurity, compliance automation experience, cloud familiarity, and U.S. citizenship and residency.
Owns technology compliance and security assurance controls across corporate and business systems, aligning evidence for SOX, SOC 2, ISO, regulatory, and contractual obligations. The role requires 5+ years in compliance, audit, security, or IT, strong control-testing experience, and a bachelor's degree or equivalent.
Senior Security Engineer on the Red Team performing offensive security, adversarial testing, and red team operations against GenAI/LLM systems, deepfake defenses, cloud infrastructure, and SaaS products. Requires 3+ years of hands-on pen testing/red team experience plus demonstrable GenAI attack experience.