Skip to main content
Ada

Compliance and Security Lead

RemoteCanada only
Published
Role
Security
Experience
Lead
Employment
Full-time
Company size
Startup
Salary not disclosed
Check eligibility

Open to CA only. Set where you work from to check your eligibility.

No BS summary

Compliance and security lead in Canada to own audits, customer trust, vendor risk, vulnerability management, and control frameworks end to end. Must have deep SOC 1, SOC 2, PCI DSS, NIST, AICPA, privacy/PII audit experience and be comfortable with Drata/SafeBase-style tooling and enterprise customer security conversations. Needs enough modern infrastructure knowledge, including Kubernetes, Terraform, and CI/CD, to work with engineers and auditors.

Core skills

SOC 2PCI DSSDrata

Required skills

SOC 1NISTAICPAPIIKubernetesTerraformCI/CDSafeBaseAIUC

What you'll do

  • Own Ada's security compliance program end to end, including audits, customer trust, vendor risk, vulnerability management, and the control framework.
  • Automate evidence collection and compliance processes so the team is audit-ready year-round.
  • Serve as the internal source of truth on compliance status.
  • Serve as the external face of Ada's security posture in security conversations with enterprise prospects and customers.
  • Translate agentic AI regulatory and framework changes into concrete requirements for the platform team.
  • Own Ada's security audits end to end, including the upcoming AIUC audit, PCI, and SOC 2.
  • Run evidence collection, control mapping, and auditor coordination through Drata.
  • Automate evidence collection and control monitoring so audit season no longer requires heroics.
  • Own the security and compliance sections of customer RFPs and security questionnaires.
  • Maintain the SafeBase trust center so deals stop stalling on security review.
  • Own vulnerability management as a program, driving the backlog down with clear prioritization, ownership, and SLAs for critical findings.
  • Run vendor security and privacy reviews as a standing process with clear SLAs.
  • Maintain the control framework and its documentation, including policies, data handling, retention, and evidence that controls operate.
  • Be the point of contact for customer security, privacy, and legal teams.
  • Track regulatory and framework movement relevant to agentic AI, starting with AIUC.
  • Take ownership of compliance work currently spread across the team and make it sustainable.
  • In the first 90 days, take full ownership of the AIUC audit.
  • In the first 90 days, produce a current-state gap assessment against target frameworks.
  • In the first 90 days, turn the RFP security response into a repeatable process.

What they require

  • Deep audit experience across SOC 1, SOC 2, PCI DSS, NIST frameworks, AICPA standards, and PII/privacy requirements.
  • Experience running audits end to end, including evidence collection, control mapping, and auditor coordination.
  • Experience working directly with major audit firms such as Deloitte or EY.
  • Experience inheriting manual compliance programs and driving them toward automation tooling, process, and repeatability.
  • Experience with Drata or similar compliance automation platforms.
  • Vulnerability management at scale, including reducing a large vulnerability backlog through prioritization, ownership, and process.
  • Customer-facing confidence in security posture conversations with enterprise prospects.
  • Ability to understand modern infrastructure well enough to work with engineers and auditors.
  • Experience owning RFP security sections, customer security questionnaires, and trust centers.
  • Experience with SafeBase or similar trust center platforms.
  • Strong writing skills for policies, control documentation, and data handling standards.
  • Proactive ownership focused on process, documentation, and tooling over heroics.
  • Preferred: Engineering background.
  • Preferred: Interest in agentic AI governance, AIUC, and emerging frameworks.

Benefits

  • Unlimited vacation.
  • Extended health coverage.
  • Dental coverage.
  • Vision coverage.
  • Travel insurance.
  • Life insurance.
  • Wellness account.
  • Employee and Family Assistance Plan.
  • Flexible work schedule.
  • Remote-first, in-person friendly work options.
  • Options to work from home or at a local hub.
  • Learning and development budget.
  • Work from home budget.
  • Access to cutting-edge AI tools.
  • Hands-on work with LLMs.
  • Opportunity to work in a thriving AI industry.

Ada

village in Hardin County, Ohio, United States

🇨🇦 CanadaAI Customer ServiceStartup

Details

Apply routeGreenhouse
Salary not disclosed