Compliance and Security Lead
- Role
- Security
- Experience
- Lead
- Employment
- Full-time
- Company size
- Startup
Open to CA only. Set where you work from to check your eligibility.
No BS summary
Compliance and security lead in Canada to own audits, customer trust, vendor risk, vulnerability management, and control frameworks end to end. Must have deep SOC 1, SOC 2, PCI DSS, NIST, AICPA, privacy/PII audit experience and be comfortable with Drata/SafeBase-style tooling and enterprise customer security conversations. Needs enough modern infrastructure knowledge, including Kubernetes, Terraform, and CI/CD, to work with engineers and auditors.
Core skills
Required skills
About Us Ada is an AI customer service company whose mission is to make customer service extraordinary for everyone. We're driven to raise a new standard of quality customer service at scale, enabling enterprise companies to deliver experiences that people love–instant, proactive, personalized, and effortless. Ada is an AI transformation platform and partner—combining strategic expertise with powerful AI agent management technology to accelerate businesses’ AI maturity to keep them ahead of the curve. With Ada, 83% of customer conversations—and counting—are effortlessly resolved through automation, giving teams more time back, companies more resources to focus on growth, and customers more life to focus on what matters most to them. Established in 2016, Ada is a Canadian company that has powered over 5.5 billion interactions for leading brands like Square, YETI, IPSY, and Monday.com , saving millions of hours of human effort. Backed with over $250M in funding from tier-one investors including Accel, Bessemer, FirstMark, Spark, and Version One Ventures, Ada is a pioneer in the management and application of AI in customer service. At Ada, we see growth as a reflection of each individual owner’s personal growth. That’s why our values are rooted in driving progress and continuous improvement. If you’re ambitious and eager to grow, Ada could be the place for you. Security at Ada Ada's AI Agent resolves customer service conversations for enterprises — which means our customers trust us with their customers' data and their brand. Security and compliance are how we earn and keep that trust. The Security team partners across engineering, legal, and go-to-market to make sure Ada's controls are real, evidenced, and easy for customers to verify. Our Role As Compliance & Security Lead, you own Ada's security compliance program end to end: audits, customer trust, vendor risk, vulnerability management, and the control framework that ties it all together. Our audit season runs August through November — your mandate is to automate evidence collection and process to the point where the team is audit-ready year-round, not scrambling seasonally. You are the internal source of truth on compliance status and the external face of Ada's security posture: you will own security conversations with enterprise prospects and customers. As agentic AI regulation takes shape (starting with AIUC), you translate framework movement into concrete requirements for the platform team. About You Deep audit experience across SOC 1, SOC 2, PCI DSS, NIST frameworks, AICPA standards, and PII/privacy requirements. You have run audits end to end: evidence collection, control mapping, and auditor coordination. Experience working directly with major audit firms such as Deloitte or EY; you know what a gold-standard audit engagement looks like from the inside. You have inherited manual compliance programs and driven them toward automation tooling, process, and repeatability (Drata or similar compliance automation platforms). Vulnerability management at scale: you have taken a large vulnerability backlog (thousands of findings) and driven it down through prioritization, ownership, and process. Customer-facing confidence: you own the room in security posture conversations with enterprise prospects, and you are equally comfortable saying "let me get back to you" and then actually getting back to them. An engineering background is preferred but not required; you must understand modern infrastructure, Kubernetes, Terraform, CI/CD! well enough to hold your own with engineers and auditors alike. Experienced owner of RFP security sections, customer security questionnaires, and trust centers (SafeBase or similar). Strong writer: policies, control documentation, and data handling standards that people actually follow. Proactive owner who builds programs that outlast you: process, documentation, and tooling over heroics. You track regulatory and framework movement interest in agentic AI governance (AIUC and emerging frameworks) is a strong plus. Outcomes Own Ada's security audits end to end: the upcoming AIUC audit, PCI, and SOC 2. Evidence collection, control mapping, and auditor coordination, run through Drata. Automate evidence collection and control monitoring so that audit season (August–November) no longer requires heroics the team is audit-ready year-round. Own the security and compliance sections of customer RFPs and security questionnaires. Maintain the SafeBase trust center so deals stop stalling on security review. Own vulnerability management as a program: drive the backlog down with clear prioritization, ownership, and SLAs for critical findings. Run vendor security and privacy reviews as a standing process with clear SLAs, not one-off scrambles. Maintain the control framework and its documentation: policies, data handling, retention, and the evidence that controls actually operate. Be the point of contact for customer security, privacy, and legal teams, and the internal source of truth on compliance status. Track regulatory and framework movement relevant to agentic AI, starting with AIUC, and translate it into concrete internal requirements for the platform team. Take ownership of the compliance work currently spread across the team, and make it sustainable. First 90 days: take full ownership of the AIUC audit, produce a current-state gap assessment against our target frameworks, and turn the RFP security response into a repeatable process. #LI-NS1 Benefits & Perks At Ada, you’ll not only build extraordinary products but also thrive in an environment designed for your success. We prioritize your well-being, growth, and work-life balance. Here’s what we offer: Benefits Unlimited Vacation: Recharge when you need to. Comprehensive Benefits: Extended health coverage, dental, vision, travel, and life insurance. Wellness Account: Empowering you to invest in your overall well-being and lifestyle. Employee & Family Assistance Plan: Resources to support you and your loved ones. Perks Flexible Work Schedule: Balance your work and personal life. Remote-First, In-Person Friendly: Options to work from home or at our local hub. Learning & Development Budget: Invest in your long-term growth goals and skills. Work from Home Budget: Equipping you with the tools and support for a seamless remote work experience. Access to Cutting-Edge AI Tools: Work with the best AI tech stack in the industry. Hands-On with LLMs: Enhance your expertise in leveraging large language models. A Thriving Industry: Join the forefront of innovation in AI, shaping the future of technology. The above Benefits and Perks only apply to full-time, permanent employees. As part of our recruitment process, we may use AI enabled tools to support certain aspects of hiring, such as interview note-taking. All hiring decisions are made by our team. Thank you for your interest in joining us at Ada. Due to the high volume of applications, we will only contact candidates whose qualifications match closely to the requirements of the position. We appreciate the time you have invested in learning more about us.
What you'll do
- Own Ada's security compliance program end to end, including audits, customer trust, vendor risk, vulnerability management, and the control framework.
- Automate evidence collection and compliance processes so the team is audit-ready year-round.
- Serve as the internal source of truth on compliance status.
- Serve as the external face of Ada's security posture in security conversations with enterprise prospects and customers.
- Translate agentic AI regulatory and framework changes into concrete requirements for the platform team.
- Own Ada's security audits end to end, including the upcoming AIUC audit, PCI, and SOC 2.
- Run evidence collection, control mapping, and auditor coordination through Drata.
- Automate evidence collection and control monitoring so audit season no longer requires heroics.
- Own the security and compliance sections of customer RFPs and security questionnaires.
- Maintain the SafeBase trust center so deals stop stalling on security review.
- Own vulnerability management as a program, driving the backlog down with clear prioritization, ownership, and SLAs for critical findings.
- Run vendor security and privacy reviews as a standing process with clear SLAs.
- Maintain the control framework and its documentation, including policies, data handling, retention, and evidence that controls operate.
- Be the point of contact for customer security, privacy, and legal teams.
- Track regulatory and framework movement relevant to agentic AI, starting with AIUC.
- Take ownership of compliance work currently spread across the team and make it sustainable.
- In the first 90 days, take full ownership of the AIUC audit.
- In the first 90 days, produce a current-state gap assessment against target frameworks.
- In the first 90 days, turn the RFP security response into a repeatable process.
What they require
- Deep audit experience across SOC 1, SOC 2, PCI DSS, NIST frameworks, AICPA standards, and PII/privacy requirements.
- Experience running audits end to end, including evidence collection, control mapping, and auditor coordination.
- Experience working directly with major audit firms such as Deloitte or EY.
- Experience inheriting manual compliance programs and driving them toward automation tooling, process, and repeatability.
- Experience with Drata or similar compliance automation platforms.
- Vulnerability management at scale, including reducing a large vulnerability backlog through prioritization, ownership, and process.
- Customer-facing confidence in security posture conversations with enterprise prospects.
- Ability to understand modern infrastructure well enough to work with engineers and auditors.
- Experience owning RFP security sections, customer security questionnaires, and trust centers.
- Experience with SafeBase or similar trust center platforms.
- Strong writing skills for policies, control documentation, and data handling standards.
- Proactive ownership focused on process, documentation, and tooling over heroics.
- Preferred: Engineering background.
- Preferred: Interest in agentic AI governance, AIUC, and emerging frameworks.
Benefits
- Unlimited vacation.
- Extended health coverage.
- Dental coverage.
- Vision coverage.
- Travel insurance.
- Life insurance.
- Wellness account.
- Employee and Family Assistance Plan.
- Flexible work schedule.
- Remote-first, in-person friendly work options.
- Options to work from home or at a local hub.
- Learning and development budget.
- Work from home budget.
- Access to cutting-edge AI tools.
- Hands-on work with LLMs.
- Opportunity to work in a thriving AI industry.
village in Hardin County, Ohio, United States