
Senior Technical Security Compliance Manager
- Seattle, WA San Francisco, CA
- Permanent
- Full-time
- Manage and optimize security compliance audits and assessments including customer audits independently end-to-end while adhering to strict deadlines and maintaining executive level metrics and reporting
- Implement and drive strategies to streamline audit processes, improve control and audit effectiveness, and technical solutions and automations
- Implement the use of technical controls and/or AI across security audit, certification, and compliance activities
- Identify automation opportunities and implement scalable solutions including technical and monitoring controls that integrate seamlessly with systems such as GRC platforms, cloud services, and various ticketing tools
- Partner with engineering and product teams to design and architect technical solutions to reduce audit fatigue and streamline operations
- Work with product and engineering, business, and technology teams to define and maintain an effective suite of controls adapting to changes in products, business processes and technology solutions
- Manage audit deliverables, identify, and analyze process gaps, provide guidance and expertise to control owners, develop remediation recommendations, and track to completion
- Develop and maintain strong relationships based on trust and transparency with control owners, auditors, and customers
- Be the subject matter expert to lead compliance discussions, awareness, internal and external audit interviews
- Establish governance across projects with structure on tracking and reporting. Develop metrics to measure and track compliance, risk and the effectiveness of the security compliance program
- Develop technical resource documentation and train the control owners and stakeholders regarding the technical design and implemented solutions to drive adoption
- 8+ years of relevant work experience in Security, Compliance, Auditing, Assessments or other GRC related experience
- 5+ years of managing security compliance audits and/or customer audits
- Experience with cloud infrastructure (Azure, AWS, GCP) and strong technology SaaS experience
- Experience in supporting compliance automation
- Industry certification such as CISSP, CISA, CISM, CRISC, ISO27001 Lead Auditor, CompTIA Security+, AWS/Azure Security, and/or equivalent GRC certification
- Comfortable working in a fast-paced, dynamic environment, and managing multiple projects concurrently
- University degree in Computer Science, Information Systems, or a related field or equivalent work experience
- Experienced in working with cross functional departments and stakeholders to provide security compliance issues, risks, and recommendations
- Ability to review compliance evidences required for audit
- Ability to coach and prepare technical teams and SMEs for audit interviews
- Ability to engage with internal, external, and customer auditors
- Strong understanding of the audit lifecycle, has experience testing controls and writing test scripts in various environments and functions.
- Self-starter with excellent communication, collaborative, and presentation skills
- Strong sense of accountability, business acumen and leadership skills, and goal achievement mind
- Excellent technical and analytical problem-solving skills and quantitative approach to solving problems
- Strong understanding of common compliance and governance frameworks relevant for a fast-paced SaaS organization
- Comfortable interacting at all levels (from C-suite to technical teams)
- Familiarity with privacy principles and the intent of privacy regulations including GDPR, CCPA, HIPAA, HITRUST etc.
- Bonus: Sales personnel are eligible for variable incentive pay dependent on their achievement of pre-established sales goals. Non-Sales roles are eligible for a company bonus plan, which is calculated as a percentage of eligible wages and dependent on company performance.
- Stock: This role is eligible to receive Restricted Stock Units (RSUs).
- Paid Time Off: earned time off, as well as paid company holidays based on region
- Paid Parental Leave: take up to six months off with your child after birth, adoption or foster care placement
- Full Health Benefits Plans: options for 100% employer paid and minimum employee contribution health plans from day one of employment
- Retirement Plans: select retirement and pension programs with potential for employer contributions
- Learning and Development: options for coaching, online courses and education reimbursements
- Compassionate Care Leave: paid time off following the loss of a loved one and other life-changing events