openleverjobgether
Compliance Engineering Lead
Jobgether
LocationUS
EmploymentFull-time
Posted2026-08-26T10:23:55.414000+00:00
Last observed2026-08-26 21:51:40.410433
Job idjobgether-jobgether:lever:68f28869-7c5f-4f6b-b9d2-e8c488f1a4f0
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Compliance Engineering Lead based in United States. This is a foundational opportunity to build and lead a modern compliance function as an engineered system rather than a collection of manual processes. You will own the compliance program end to end, with direct responsibility for SOC 2 Type II and the organization’s path to ISO 27001 certification. The role combines security, engineering, risk management, automation, and customer assurance in a high-growth environment. You’ll build continuous evidence pipelines, automate control monitoring, and strengthen vendor and risk-management programs. You’ll also shape the organization’s approach to AI assurance and emerging regulatory frameworks. Reporting directly to the CISO, you’ll have significant autonomy and the opportunity to hire and lead an initial team member while defining the future of GRC. Own the SOC 2 Type II program end to end , including audit scope, observation periods, auditor relationships, evidence collection, controls, findings, and the final customer-facing report. Lead the organization through ISO 27001 certification , including defining the scope and ISMS, conducting gap assessments and internal audits, preparing teams, achieving certification, and maintaining an effective management system afterward. Build a continuous and automated evidence-collection infrastructure using APIs and systems of record such as cloud platforms, source-control systems, identity providers, MDM, and ticketing tools. Develop scheduled control tests and monitoring that identify configuration drift or control failures quickly, replacing recurring manual compliance work with reliable automation. Own and mature enterprise risk and third-party vendor risk programs , including risk registers, vendor tiering, assessments, reviews, renewal cadences, and executive reporting. Lead the customer-facing security assurance function , including the trust portal and security documentation library, with the goal of proactively addressing enterprise customer requirements and reducing questionnaire volume. Evaluate and shape the organization’s AI assurance strategy , assessing frameworks and regulations such as ISO/IEC 42001, AI assurance standards, the EU AI Act, and the NIST AI Risk Management Framework. Partner closely with Security, Engineering, Legal, and Go-to-Market teams to identify and resolve compliance gaps across organizational boundaries. Own the compliance technology strategy, evaluating existing GRC platforms and determining where purchasing, integrating, or building internal capabilities provides the greatest leverage. Hire, develop, and lead an initial customer-trust team member focused on security questionnaires, RFPs, and contract security reviews. Establish clear ownership, documentation, service levels, and repeatable processes so compliance becomes an embedded operational capability rather than an audit-time exercise. Requirements: Proven SOC 2 Type II ownership: personally accountable for at least two complete SOC 2 Type II cycles, including auditor management, scoping, evidence, controls, and remediation of findings. Strong ISO 27001 expertise: experience taking an organization through certification or managing an ISMS through surveillance audits, with a practical understanding of how to make the system operationally effective. Compliance automation experience: comfortable building and maintaining automations against APIs and operational systems; you naturally look for opportunities to replace repetitive manual processes with scheduled, reliable workflows. Hands-on experience with GRC and compliance platforms such as Drata, Vanta, or comparable solutions, combined with sound judgment about their strengths and limitations. Strong risk prioritization skills , with the ability to distinguish meaningful security and compliance risks from lower-value admi
This page is generated from the committed OpenOpps static snapshot. Use the source posting or apply link for the employer's current canonical posting state.