
Security Compliance Manager
- Denver, CO
- $130,000-145,000 per year
- Permanent
- Full-time
- Draft, publish, and maintain information-security and privacy policies, standards, and procedures.
- Establish a living compliance calendar covering control tests, access reviews, vendor assessments, and policy refresh cycles.
- Facilitate working sessions so Engineering, IT, PeopleOps, and Legal understand their accountability for controls such as vulnerability management, change management, and incident response, etc...
- Track and report control ownership status; escalate gaps or overdue actions.
- Lead annual ISO 27001 audits end-to-end: scoping, readiness assessments, evidence collection, auditor coordination, and remediation follow-up.
- Maintain audit work-papers and a centralized evidence repository
- Execute and document periodic controls: quarterly user access reviews, privileged-access attestations, vendor risk assessments, business continuity tests, and vulnerability-remediation SLAs.
- Automate evidence capture wherever feasible through tooling integrations (e.g., Vanta, Jira, Slack).
- Conduct security risk assessments for new products and vendors; track mitigation plans to closure.
- Update policies and training content in response to regulatory and industry changes. .
- Generate KPIs and board-level metrics on compliance health, audit findings, and risk trends.
- Develop and deliver role-based security and privacy training; ensure coverage and completion tracking.
- Promote a culture of accountability through regular communications, lunch-and-learns, and compliance office hours.
- 5+ years in information-security compliance, ideally within a SaaS environment.
- Demonstrated ownership of at least one full SOC 2 Type 2 audit cycle.
- Strong project-management skills: ability to run parallel work-streams, influence without authority, and meet tight deadlines.
- Working knowledge of common control frameworks (SOC 2, ISO 27001, NIST CSF, etc..)
- Familiarity with security tooling for evidence collection (e.g., Vanta) and ticketing systems (Jira).
- Excellent written and verbal communication; adept at translating control requirements for technical and non-technical audiences.
- CISSP, CISA, CISM, or similar certification.
- Experience building RACI matrices and running cross-functional governance forums.
- Background in vulnerability management processes or secure SDLC.
- A commitment to fostering flexible hybrid work
- A generous PTO policy with a minimum of three weeks off per year
- Free therapy coverage benefits to ensure our employees have access to the care they need (must be enrolled in our medical plans to participate)
- Competitive Medical, Dental, and Vision coverage with plans to meet every need, including HSA ($1,100 company contribution) and FSA options
- Employer-paid short-term, long-term disability, life & AD&D to cover life's unexpected events. Not only that, we also cover the difference in salary for up to seven (7) weeks of short-term disability leave (after the required waiting period) should you need to use it.
- Eight weeks of paid Parental Leave (if the parent also qualifies for STD, this benefit is in addition, which allows between 8-16 weeks of paid leave)
- 401K retirement plan with 100% matching which immediately vests on up to 4% of base salary
- Travel to Denver 1x a year for annual Shift gathering
- Fourteen (14) company holidays
- Company Shutdown between Christmas and New Years
- Supplemental life insurance, pet insurance coverage, commuter benefits and more!