Security & Compliance Manager

Posted 1hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Security and compliance manager maintaining SOC 2 and leading ISO 27001 for Relocity’s AI-driven mobility platform. Strengthening privacy, governance, risk management, and data protection across the remote United States team.

Responsibilities:

  • Maintain SOC 2 Type II compliance, including control operation, evidence collection, and annual audit readiness.
  • Lead the ISO 27001 certification effort from gap assessment through certification and ongoing surveillance.
  • Own security and privacy frameworks, including GDPR, CCPA, and other applicable regulations.
  • Advise the company on security, privacy, and compliance strategy.
  • Establish and improve security controls, governance standards, policies, and risk management practices.
  • Conduct security risk assessments, manage incident response, and drive remediation efforts.
  • Administer Vanta and related tooling for compliance monitoring, continuous control testing, and audit workflows.
  • Partner with Engineering, Product, Operations, Legal, and leadership to embed security and privacy into products, systems, and business processes.
  • Translate technical risk into practical business recommendations.
  • Define enterprise data governance standards, including data classification, retention, and lifecycle management.
  • Lead company-wide security awareness initiatives.
  • Monitor evolving regulations, emerging threats, and industry best practices.
  • Evaluate and implement technologies and processes that improve automation, visibility, and operational efficiency.

Requirements:

  • Three to five years of experience in information security, data privacy, governance, compliance, or risk management.
  • Direct experience maintaining SOC 2 Type II and leading or supporting ISO 27001 certification in a SaaS or cloud-first environment.
  • Hands-on experience with Vanta or comparable GRC platforms such as Drata, Secureframe, or Sprinto.
  • Strong working knowledge of GDPR, CCPA, and other applicable privacy regulations.
  • Demonstrated success designing and implementing data classification, retention, privacy, and security programs.
  • Familiarity with cloud infrastructure, SaaS environments, identity and access management, and security controls.
  • Ability to explain complex technical concepts to technical and non-technical audiences.
  • Proven ability to influence stakeholders and lead initiatives across multiple functions.
  • Bachelor's degree in Information Security, Computer Science, Information Systems, Business, Legal Studies, or a related field, or equivalent practical experience.
  • Professional certifications such as CIPP/US, CIPM, CISSP, CISM, or CRISC are nice to have.
  • Experience in a high-growth SaaS or technology startup environment is nice to have.
  • Knowledge of privacy-by-design principles is nice to have.
  • Must be legally authorized to work.
  • Successful completion of a background investigation is required for any employment offer.

Benefits:

  • Competitive Compensation
  • Paid Time Off
  • Paid Parental Leave
  • Remote Workplace
  • Flexible Work Schedules
  • Health, Dental, Vision, and LTD Insurance
  • 401(k)
  • Professional Development Opportunities
  • Bonus