Перейти к основному содержимому
Sardine
Sardine

Security Compliance Manager

УдалённоUnited States только
Опубликовано
Роль
Безопасность
Опыт
Синьор
Занятость
Полная занятость
$130k–$190k/yr
Проверьте доступность

Доступно для: US only. Укажите, откуда вы работаете, чтобы проверить доступность.

Коротко по делу

Senior, hands-on Security Compliance / GRC lead with 7+ years owning audit and certification programs (SOC 2, PCI DSS, ISO 27001). Must be US-based (Remote - US) and have deep practical knowledge of PCI DSS, SOC 2, ISO 27001, GDPR/CCPA and DORA; FedRAMP/NIST SP 800-53 experience expected for the FedRAMP effort.

Ключевые навыки

PCI DSSSOC 2ISO 27001

Обязательные навыки

GDPRCCPADORANIST SP 800-53NIST CSFCIS

Желательные навыки

VantaRipplingmacOS

Чем предстоит заниматься

  • Own compliance planning and the compliance program across SOC 2 Type II, PCI DSS (Level 1 Service Provider), ISO 27001, GDPR, CCPA, and DORA — responsible for the program’s design and direction, not only its execution.
  • Drive Sardine's FedRAMP effort by working toward authorization, coordinating NIST SP 800-53 control implementation, 3PAO assessment, and continuous monitoring across engineering and IT.
  • Serve as the primary interface to auditors, regulators, and industry stakeholders, and partner with internal engineering, IT, product, security, and legal teams to drive reviews to clean outcomes.
  • Own the control framework — including rationalizing overlapping controls across standards into a coherent, evidence-efficient set — and the security policy and standards library.
  • Own the customer assurance and trust program — security questionnaires, attestations, and trust artifacts — and manage evidence, scans, and artifacts to keep Sardine audit- and customer-ready.

Что требуется

  • 7+ years in security compliance, GRC, or audit, including end-to-end ownership of audit or certification programs (SOC 2, PCI DSS, and/or ISO 27001).
  • Deep knowledge of security and privacy frameworks — PCI DSS, SOC 2, ISO 27001, GDPR/CCPA, and DORA; familiarity with control frameworks such as NIST CSF and CIS.
  • Technical and product comfort — able to build fluency in a technical product and engage engineering and product teams as a peer.
  • Fast-paced, high-growth experience — fintech or payments strongly preferred given Sardine’s PCI Level 1 service provider obligations.
  • People leadership — experience leading, mentoring, or managing others, or clear readiness to step into managing a direct report.

Преимущества

  • Generous compensation in cash and equity
  • Early exercise for all options, including pre-vested
  • Health insurance, dental, and vision coverage for employees and dependents - US and Canada specific
  • 4% matching in 401k / RRSP - US and Canada specific
  • MacBook Pro delivered to your door

Sardine is an agentic risk platform for fighting financial crime. Its platform unifies data across risk teams to stop fraud in real time, prevent AI-driven attacks, and automate fraud and AML operations, supported by a fraud consortium spanning billions of devices, consumers, and businesses worldwide.

FintechСтартапsardine.ai

Что говорят о компании

5.0/ 5

$130k–$190k/yr