# Security Compliance Manager

**Company:** [Sardine](https://hotfix.jobs/companies/sardine)
**Location:** Remote
**Role:** Security Engineering
**Salary:** $130k – $190k/yr
**Experience:** 7+ years
**Skills:** SOC 2, Pci Dss, ISO 27001, GDPR, CCPA, Dora, FedRAMP, Nist Sp 800-53, Nist Csf, Cis Controls, Vanta, Risk Management, GRC
**Posted:** 2026-08-25

> Own and scale Sardine’s security compliance and GRC function across major security, privacy, and resilience frameworks, including FedRAMP. The role leads audits, risk management, customer assurance, executive reporting, and a growing compliance team while partnering closely with technical and business stakeholders.

## Job Description

## Responsibilities
- Own the security compliance and GRC program across SOC 2 Type II, PCI DSS Level 1 Service Provider, ISO 27001, GDPR, CCPA, and DORA.
- Drive the FedRAMP authorization effort, including NIST SP 800-53 control implementation, 3PAO assessment coordination, and continuous monitoring.
- Serve as the primary contact for auditors, regulators, and industry stakeholders.
- Partner with engineering, IT, product, security, and legal teams to achieve successful reviews and audit outcomes.
- Present objectives, scope, results, and the business impact of control gaps to senior management and the board through the CISO.
- Own the control framework, security policies, standards library, risk register, risk quantification, and reporting cadence.
- Lead the customer assurance and trust program, including security questionnaires, attestations, and trust artifacts.
- Coordinate evidence, scans, and artifacts, and drive improvements based on findings, quality reviews, and maturity assessments.
- Build sufficient product and technical fluency to make informed control and risk decisions and collaborate effectively with engineering and product teams.
- Identify opportunities for consistency, streamlining, and automation.
- Produce executive-ready documentation and presentations and facilitate effective meetings with regulators and internal stakeholders.
- Lead, mentor, and develop the security compliance team, initially including a Security Compliance Analyst.

## Requirements
- 7+ years of experience in security compliance, GRC, or audit.
- End-to-end ownership of audit or certification programs such as SOC 2, PCI DSS, and/or ISO 27001.
- Deep knowledge of PCI DSS, SOC 2, ISO 27001, GDPR, CCPA, and DORA.
- Familiarity with NIST CSF and CIS control frameworks.
- Technical and product fluency, with the ability to collaborate as a peer with engineering and product teams.
- Excellent written and verbal communication skills, executive-ready documentation ability, and credible presence with auditors, regulators, and leadership.
- Experience in a fast-paced, high-growth environment; fintech or payments experience is strongly preferred.
- Ability to operate as a leader, partner, and individual contributor as needed.
- Willingness to travel as needed.
- Experience leading, mentoring, or managing others, or clear readiness to manage a direct report.

## Nice-to-haves
- Direct experience running a PCI DSS Level 1 service provider program.
- Hands-on exposure to DORA operational-resilience requirements.
- Familiarity with GRC and security tooling, including Vanta.
- Familiarity with Rippling and macOS environments.

## Compensation and Benefits
- Compensation in cash and equity.
- Early exercise for all options, including pre-vested options.
- Remote-first culture and work-from-anywhere flexibility.
- Flexible paid time off and year-end break.
- Health, dental, and vision coverage for employees and dependents in the United States and Canada.
- 4% 401(k)/RRSP matching in the United States and Canada.
- MacBook Pro, home-office setup stipend, monthly meal stipend, monthly social-meetup stipend, annual health and wellness stipend, and annual learning stipend.

## Similar jobs

- [Security Engineer, Detection and Response](https://hotfix.jobs/jobs/e00040ab-bd5e-47da-a22b-c36fa3dea16c) - Writer - San Francisco, CA - $132k – $258k/yr
- [Senior Cloud Security Engineer](https://hotfix.jobs/jobs/3babcef3-e76c-4d5c-918e-3b5b417fbadd) - Reltio - Remote - $122k – $180k/yr
- [Senior Security Compliance Engineer, Public Sector](https://hotfix.jobs/jobs/3427156e-b584-45f3-8a5e-23c79be146af) - GitLab - Remote - $139k – $196k/yr
- [Senior Security Assurance Engineer](https://hotfix.jobs/jobs/4db71196-4678-47f9-b8fd-a70dc317bd46) - GitLab - Remote - $139k – $196k/yr
- [Senior Security Engineer](https://hotfix.jobs/jobs/bf99bce1-bf10-4938-81d3-d24f8455171f) - Pindrop - Remote - $140k – $165k/yr

**Apply:** https://hotfix.jobs/jobs/a631d7a7-01a4-496e-8e8c-97bd0b990c08
**Canonical:** https://hotfix.jobs/jobs/a631d7a7-01a4-496e-8e8c-97bd0b990c08