Skip to main content
10a Labs

Compliance Manager

RemoteUnited States only
Published
Role
Operations
Experience
Senior
$105k–$125k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Compliance manager with 5+ years in compliance, information security, governance, risk, or audit. Must own SOC 2 programs/audits, understand GDPR, work with security frameworks, cloud environments, and GRC platforms. Fully remote but U.S.-based.

Core skills

SOC 2GDPRGRC platforms

Required skills

ISO 27001/NIST CSF/CIS Controls/HIPAAAWS/GCPVanta/Drata/Secureframe

Optional skills

AI governanceAI securityPrivacy impact assessmentsData governanceCompliance workflow automationSecurity toolingIdentity and access managementCloud security

What you'll do

  • Own the company's compliance program across SOC 2, GDPR, ISO 27001, Cyber Essentials Plus, and additional security, privacy, and governance frameworks.
  • Lead all phases of external audits, certifications, and annual compliance assessments.
  • Develop, maintain, and continuously improve security policies, standards, procedures, and internal controls.
  • Partner with engineering and security teams to implement, document, and validate technical, administrative, and operational controls.
  • Manage evidence collection, audit readiness, and ongoing compliance activities using GRC platforms and internal tooling.
  • Coordinate enterprise risk assessments and track remediation efforts through successful completion.
  • Own third-party risk management, including vendor security reviews and due diligence.
  • Respond to customer security questionnaires, support enterprise procurement processes, and maintain customer trust documentation.
  • Build and maintain customer-facing compliance resources, including trust portals, security documentation, and compliance artifacts.
  • Monitor changes to global privacy and security regulations, recommending updates to policies and controls as requirements evolve.
  • Help develop and operationalize AI governance practices aligned with emerging regulations and industry frameworks, including the EU AI Act and NIST AI Risk Management Framework.
  • Develop compliance metrics, dashboards, and executive reporting to communicate organizational risk and program maturity.
  • Deliver security awareness and compliance training across the organization.
  • Collaborate with engineers, analysts, and leadership to embed compliance throughout product development, infrastructure, and business operations.
  • Serve as the primary internal subject matter expert for compliance and governance initiatives.

What they require

  • Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Technology, Business, Risk Management, Law, or a related field.
  • 5+ years of experience in compliance, information security, governance, risk management, or audit.
  • Experience owning or managing SOC 2 compliance programs and external audits.
  • Strong understanding of GDPR and modern data privacy requirements.
  • Experience implementing and maintaining security controls aligned with frameworks such as ISO 27001, NIST CSF, CIS Controls, HIPAA, or similar.
  • Experience working with cloud environments such as Amazon Web Services (AWS) or Google Cloud Platform (GCP).
  • Experience using Governance, Risk, and Compliance (GRC) platforms such as Vanta, Drata, Secureframe, or similar.
  • Experience supporting customer security reviews and enterprise procurement processes.
  • Strong project management skills with the ability to manage multiple initiatives simultaneously.
  • Excellent written and verbal communication skills with both technical and non-technical audiences.
  • Exceptional organizational skills and attention to detail.
  • Highly organized with exceptional attention to detail.
  • Comfortable owning complex programs with minimal oversight.
  • Proactive and able to identify risks before they become problems.
  • Practical and solutions-oriented when balancing security, compliance, and business objectives.
  • Able to influence cross-functional teams and build strong working relationships.
  • Curious about evolving regulatory requirements and emerging AI governance standards.
  • Comfortable working in a fast-moving environment with evolving priorities.
  • Preferred: Experience leading multiple successful SOC 2 Type II audits.
  • Preferred: Familiarity with AI systems, AI governance, or AI security concepts.
  • Preferred: Experience supporting compliance programs within high-growth technology or SaaS companies.
  • Preferred: Experience with privacy impact assessments, data governance, or international privacy regulations.
  • Preferred: Experience automating compliance workflows or integrating compliance into engineering processes.
  • Preferred: Familiarity with security tooling, identity and access management, or cloud security best practices.
  • Preferred: Professional certifications such as CISA, CISM, CRISC, CISSP, ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, or Certified Information Privacy Professional (CIPP).

Benefits

  • Performance-based annual bonus.
  • Support for conferences, continuing education, and professional certifications.
  • Fully remote, U.S.-based work environment.
  • Comprehensive health, dental, and vision coverage.
  • Generous PTO and paid holiday schedule.
  • 401(k) plan.

10a Labs is the safety and threat-intelligence layer trusted by frontier AI labs, AI unicorns, Fortune 10 companies, and leading global technology platforms. Its adversarial red teaming, model evaluations, and intelligence collection enable engineering, safety, and security teams to stay ahead of evolving threats and deploy AI systems safely.

AI Safety

Details

Apply routeGreenhouse
$105k–$125k/yr