Skip to main content
Sardine
Sardine

Security Compliance Manager

RemoteUnited States only
Published
Role
Security
Experience
Senior
Employment
Full-time
$130k–$190k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Senior, hands-on Security Compliance / GRC lead with 7+ years owning audit and certification programs (SOC 2, PCI DSS, ISO 27001). Must be US-based (Remote - US) and have deep practical knowledge of PCI DSS, SOC 2, ISO 27001, GDPR/CCPA and DORA; FedRAMP/NIST SP 800-53 experience expected for the FedRAMP effort.

Core skills

PCI DSSSOC 2ISO 27001

Required skills

GDPRCCPADORANIST SP 800-53NIST CSFCIS

Optional skills

VantaRipplingmacOS

What you'll do

  • Own compliance planning and the compliance program across SOC 2 Type II, PCI DSS (Level 1 Service Provider), ISO 27001, GDPR, CCPA, and DORA — responsible for the program’s design and direction, not only its execution.
  • Drive Sardine's FedRAMP effort by working toward authorization, coordinating NIST SP 800-53 control implementation, 3PAO assessment, and continuous monitoring across engineering and IT.
  • Serve as the primary interface to auditors, regulators, and industry stakeholders, and partner with internal engineering, IT, product, security, and legal teams to drive reviews to clean outcomes.
  • Own the control framework — including rationalizing overlapping controls across standards into a coherent, evidence-efficient set — and the security policy and standards library.
  • Own the customer assurance and trust program — security questionnaires, attestations, and trust artifacts — and manage evidence, scans, and artifacts to keep Sardine audit- and customer-ready.

What they require

  • 7+ years in security compliance, GRC, or audit, including end-to-end ownership of audit or certification programs (SOC 2, PCI DSS, and/or ISO 27001).
  • Deep knowledge of security and privacy frameworks — PCI DSS, SOC 2, ISO 27001, GDPR/CCPA, and DORA; familiarity with control frameworks such as NIST CSF and CIS.
  • Technical and product comfort — able to build fluency in a technical product and engage engineering and product teams as a peer.
  • Fast-paced, high-growth experience — fintech or payments strongly preferred given Sardine’s PCI Level 1 service provider obligations.
  • People leadership — experience leading, mentoring, or managing others, or clear readiness to step into managing a direct report.

Benefits

  • Generous compensation in cash and equity
  • Early exercise for all options, including pre-vested
  • Health insurance, dental, and vision coverage for employees and dependents - US and Canada specific
  • 4% matching in 401k / RRSP - US and Canada specific
  • MacBook Pro delivered to your door

Sardine is an agentic risk platform for fighting financial crime. Its platform unifies data across risk teams to stop fraud in real time, prevent AI-driven attacks, and automate fraud and AML operations, supported by a fraud consortium spanning billions of devices, consumers, and businesses worldwide.

FintechStartupsardine.ai
$130k–$190k/yr