Security and Compliance Manager
Hackajob
Job TitleSecurity Compliance ManagerJob DescriptionAt Sierra, we're creating a platform to help businesses build better, more human customer experiences with AI. We are guided by a set of values that are at the core of our actions and define our culture: Trust, Customer Obsession, Craftsmanship, Intensity, and Family. These values are the foundation of our work, and we are committed to upholding them in everything we do.What You'll DoOwn independent audits and regulatory programs including ISO 42001, PCI DSS, NIST 800-53, FedRAMP, HIPAA, and related frameworks.Drive scope definition, readiness assessments, auditor engagement, remediation planning, and executive level reporting.Develop a strong working understanding of Sierra's Conversational AI Platform, model providers, and cloud architecture. Partner with Platform and Agent Engineering to design and operationalize controls across multi cloud environments, infrastructure, inference and data platforms.Build a centralized and evolving security controls library mapped to compliance, regulatory and customer requirements. Continuously assess control effectiveness, identify gaps, prioritize risk, and drive remediation that strengthens Sierra's security and compliance posture.Define and enforce security baselines for cloud infrastructure, containerized workloads, Kubernetes, identity, encryption, logging, and network security controls. Partner with engineering teams to integrate security requirements into configuration and change management.Design and operate automated compliance workflows using AI, infrastructure as code, and security tooling to reduce manual effort, improve control assurance, and scale with platform evolution.Who You'll Work WithYou will act as a strategic partner to Platform, Product, Agent Development, Legal, and GTM, ensuring security and compliance requirements are embedded into architecture decisions, product roadmaps, and go to market execution while supporting product velocity and technical complexity.What You'll Bring8+ years of experience in security compliance or GRC or security adjacent roles within fast growing technology companies.Deep expertise in security compliance frameworks including ISO 42001, PCI DSS, NIST 800-53, FedRAMP, and similar regulatory environments.A systems oriented and engineering focused GRC mindset, with the ability to reason about cloud architecture, data flows, and control effectiveness alongside engineers.Experience owning complex audits and driving risk based remediation across distributed teams.Hands-on experience with multi-cloud infrastructure (AWS, Azure, GCP).Strong experience implementing and automating security controls across cloud infrastructure, configuration management, container security, Kubernetes, encryption, identity, and authentication systems.Ability to clearly communicate compliance requirements internally to engineering teams and externally to customers in a technically credible way.Relevant certifications such as CISSP, CISA, PCI ISA, ISO 27001 Lead Auditor, or equivalent experience.Even Better...Experience supporting AI platforms, fintech, healthcare, or other highly regulated environments.Familiarity with global regulatory environments including GDPR, DORA, the EU AI Act, and emerging security and AI governance requirements across APAC regions.Experience supporting public sector or FedRAMP aligned environments.Why Join Us?You will operate at the center of AI systems, cloud infrastructure, and global compliance, shaping how security controls are designed and scaled for modern AI platforms. This role offers high ownership, deep technical partnership with engineering, and the opportunity to define what strong GRC looks like at Sierra.Our ValuesTrust: We build trust with our customers with our accountability, empathy, quality, and responsiveness. We build trust in AI by making it more accessible, safe, and useful. We build trust with each other by showing up for each other professionally and personally, creating an environment that enables all of us to do our best work.Customer Obsession: We deeply understand our customers' business goals and relentlessly focus on driving outcomes, not just technical milestones. Everyone at the company knows and spends time with our customers. When our customer is having an issue, we drop everything and fix it.Craftsmanship: We get the details right, from the words on the page to the system architecture. We have good taste. When we notice something isn't right, we take the time to fix it. We are proud of the products we produce. We continuously self-reflect to continuously self-improve.Intensity: We know we don't have the luxury of patience. We play to win. We care about our product being the best, and when it isn't, we fix it. When we fail, we talk about it openly and without blame so we succeed the next time.Family: We know that balance and intensity are compatible, and we model it in our actions and processes. We are the best technology company for parents. We support and respect each other and celebrate each other's personal and professional achievements.What We OfferWe want our benefits to reflect our values and offer the following to full-time employees:Flexible (unlimited) paid time offMedical, dental, and vision benefits for you and your familyLife insurance and disability benefitsRetirement plan dependent on country of employmentParental leaveFertility and family building benefits through CarrotLunch, as well as delicious snacks and coffee to keep you energizedDiscretionary benefit stipend giving people the ability to spend where it matters mostFree alphorn lessonsThese benefits are further detailed in Sierra's policies, may vary by region, and are subject to change at any time, consistent with the terms of any applicable compensation or benefits plans. Eligible full-time employees can participate in Sierra's equity plans subject to the terms of the applicable plans and policies.Be You, With UsWe're working to bring the transformative power of AI to every organization in the world. To do so, it is important to us that the diversity of our employees represents the diversity of our customers. We believe that our work and culture are better when we encourage, support, and respect different skills and experiences represented within our team. We encourage you to apply even if your experience doesn't precisely match the job description. We strive to evaluate all applicants consistently without regard to race, color, religion, gender, national origin, age, disability, veteran status, pregnancy, gender expression or identity, sexual orientation, citizenship, or any other legally protected class.
- ...Facebook. Bret was also one of Google's earliest product managers and co-creator of Google Maps. Before founding Sierra... ...and data platforms.Build a centralized and evolving security controls library mapped to compliance, regulatory and customer requirements. Continuously...SuggestedFull timeFlexible hours
$140k - $180k
...Security Compliance ManagerWe are looking for a highly motivated Security Compliance Manager with a deep security and compliance background to lead system development and process improvement. As part of Hive's Security Team, you will collaborate with engineers and auditors...Suggested- PwC in San Francisco seeks an experienced SAP Business Process & IT Controls Manager to lead compliance and security services across SAP applications. You will analyze client needs, implement security measures, mentor junior staff, and drive strategic SAP governance initiatives...Suggested
- ...than headcount and we’re looking to align the two quickly. The Role We're hiring our first dedicated GRC Program Manager to own the security & compliance program that our enterprise business runs on: SOC 2 Type II, ISO 27001, ISO 42001, GDPR, and Microsoft SSPA. The program...Suggested
$135k - $250k
Cohere is the leading security‑first enterprise AI company. We build cutting‑edge foundation... ..., FP&A, Tax, Treasury, Operations, Compliance, Legal, and People teams to embed... ...compliance. Demonstrate expertise in project management, with proven ability to oversee...SuggestedFull timeWork at officeLocal areaRemote workHome office$124k - $280k
...ApplicableSpecialismCybersecurity & PrivacyManagement LevelSenior ManagerJob Description & SummaryThe OpportunityAs a Security Risk & Engineering - Tech and Cyber Risk & Compliance - Senior Manager, you will play a pivotal role in guiding clients through complex regulatory landscapes,...Full timeH1b$99k - $232k
...ApplicableSpecialismCybersecurity & PrivacyManagement LevelManagerJob Description & SummaryThe OpportunityAs a Security Risk & Engineering - Tech and Cyber Risk & Compliance - Manager, you will play a pivotal role in guiding organizations through complex regulatory landscapes,...Full timeH1b$134k - $202k
...builders move from idea to production with speed, security, and exceptional developer experience. Now,... ...for a GRC Analyst to join our Governance, Risk & Compliance (GRC) team. You will have the opportunity to manage and maintain ongoing compliance with security and...Work at officeRemote workWorldwideMonday to Friday$190k - $275k
...— shape how we work and grow as a team. About the Team The Security Engineering team at Decagon protects the platform that powers... .... About the Role Join Decagon as a Governance, Risk, and Compliance Manager and play a critical role in securing customer trust as we scale...Full timeWork at officeLocal area$182k - $280k
Kikoff: The Fintech Powering Financial Security at Scale Kikoff is a profitable, pre-IPO... ...Kikoff is seeking a Head of Consumer Compliance to lead and own our consumer protection... ...continuously enhance Kikoff's consumer compliance management system (CMS), including policies,...Local area$135k - $165k
...is seeking a proactive GRC Analyst to join our team in San Francisco. This role will support compliance and risk management initiatives essential for maintaining high security standards. The ideal candidate will have 3-5 years of experience in GRC and relevant qualifications...Contract work- Fluidstack is seeking a Security Compliance Lead in San Francisco to own end-to-end controls across SOC 2 Type II, ISO 27001, NIST 800-53, and... ...with engineering and operations to gather evidence, manage audit readiness, and close findings with external auditors,...
- Salesforce.com, inc. is seeking a detail-oriented Security GRC Analyst to join their Security and Compliance team. In this role, you will lead the Unified Audit... ...various frameworks like SOC 2 and HIPAA, while managing evidence collection and liaising with external auditors...
- Zip is hiring a GRC Analyst to drive compliance programs across SOC 1, SOC 2, ISO 27001, and expanding into the EU and regulated industries... ...and external auditors to maintain certifications and enable secure product development. In this fast-growing environment, you’ll lead...
- Anthropic is seeking a Senior Third Party Risk Manager to lead the top tier of vendor risk, including mission-critical compute, data center... ...shape risk assessments, escalation, and remediation across security, privacy, and operations. You’ll own intake reviews, tiering,...Work at officeVisa sponsorship
- Ivo is looking for a detail-oriented Governance, Risk & Compliance (GRC) Analyst in San Francisco. The ideal candidate will support compliance programs such as SOC 2 Type II and ISO 27001 while managing audits and risk assessments. This onsite role offers a competitive...
- Vercel in San Francisco is seeking a GRC Analyst to join our Governance, Risk & Compliance team. You will manage and maintain ongoing compliance with security and privacy frameworks, policies, and audits including ISO 27001, SOC 2, HIPAA, and PCI DSS. You will collaborate...Remote jobWork at office
$255k
...together to build beneficial AI systems. About the role We're seeking an experienced Policy Communications Manager to help drive external communications for our security, governance, and responsible scaling programs, and associated work. This role offers the opportunity to...Visa sponsorship$150k - $180k
...products that help builders move from idea to production with speed, security, and exceptional developer experience. Now, software is... ...comes next.About the Role: We are looking for a Strategic Sourcing Manager to join our Procurement team. You will own strategic sourcing...Contract workWork at officeWork from homeWorldwideMonday to FridayFlexible hours- ...settlement, and the industry's leading security infrastructure. Home to Anchorage Digital... ...and on LinkedIn.As the Lead for Regulated Compliance Programs, you will be a key architect in... ...protection. You will act as a qualified manager with a wide range of expertise,...
- ...enterprise and internationally. The RoleWe're hiring a Public Sector Compliance Manager to manage Peregrine's public sector compliance function as... ...to auditable recordkeepingFacility Clearance & Personnel Security Serve as our primary point of contact with DCSA to establish...Contract workFor contractorsFor subcontractorWork at officeLocal area
$172.5k - $222.5k
...What you’ll be responsible for: Circle is looking for a Senior Manager to join the Regulatory Assurance team who will help to create... ...central global function focused on developing a best in class compliance management system, supporting all regional and core compliance...Flexible hours- ...offer fast and flexible funding, spend management, and savings tools to their small business... ...markets, underwriting, servicing, compliance, and customer service for our partners.... ...such as vendor management and information security. You will have a critical and central...Flexible hours
$117.2k - $176.7k
...ExperienceLocation: San Francisco, CAThe Senior Security GRC Analyst role is part of our... ...external auditors alike, you will help ensure compliance programs run smoothly and certifications... ...status and risk areas to leadership.Manage internal evidence collection by...Full timeWork at office$200k - $225k
...0.00 Annual SalaryJob Description Summary:The Director of Security and Compliance leads the design and oversight of cybersecurity, compliance... ....Job Description:POSITION RESPONSIBILITIES AND DUTIESRisk Management: Sets the mission, vision, and strategy for technology...Full timeTemporary workFlexible hours$135k - $165k
...company transforming how organizations review, negotiate, and manage contracts. Security, privacy, and trust are foundational to our platform and... ...we are looking for a highly motivated Governance, Risk & Compliance (GRC) Analyst to support and mature Ivo's security...Contract workFlexible hours$110k - $132.5k
Salesforce SOX Compliance & Release Manager (Hybrid in South San Francisco)SummaryThe Salesforce SOX Compliance & Release Manager will maintain and execute our Sarbanes-Oxley (SOX) and Information Technology General Controls (ITGC) frameworks across our enterprise Salesforce...$187.6k - $281.4k
...Our customers depend on us to deliver a secure, trustworthy, and compliant platform. Earning... ...of Trust and own Harvey's end-to-end compliance programs. You will be accountable for... ...remediation roadmapsSelect, onboard, and manage third-party assessors and compliance advisors...$99k - $252.45k
...with a variety of stakeholders. They evaluate compliance with regulations including assessing governance and risk management processes and related controls. In business... ...you will assess the client’s approach for ERP security, business process and IT General Controls, while...H1b- ...are backed by a $13.5 million seed round led by a16z, Menlo Ventures, and Anthropic. About The Role We’re hiring a hands-on Security & Compliance Lead to build and scale Phylo’s security, privacy, and compliance program. You’ll own our compliance roadmap, lead audits...Work at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security and Compliance Manager. Be the first to apply!
- security engineering manager San Francisco, CA
- cloud security manager San Francisco, CA
- corporate security manager San Francisco, CA
- program manager with security clearance San Francisco, CA
- surveillance manager San Francisco, CA
- security systems manager San Francisco, CA
- director global security San Francisco, CA
- security operations manager San Francisco, CA
- director information security San Francisco, CA
- physical security manager San Francisco, CA

