Own day-to-day management of our compliance tooling (Drata), ensuring controls, evidence, and monitoring stay audit-ready.
Prepare, organize, and maintain evidence for SOC 2 and ISO 27001 audits in partnership with Engineering, Product, IT, and People Ops.
Coordinate with internal teams to collect, validate, and refresh compliance evidence and artifacts.
Lead responses to security, privacy, and vendor due-diligence questionnaires with accuracy and efficiency.
Own end-to-end responses to security, privacy, and vendor due-diligence questionnaires, ensuring responses are accurate, product-specific, and aligned with actual systems and practices.
Translate internal security, privacy, and data-handling policies into clear, customer-facing responses and documentation.
Maintain and organize our security and privacy documentation, including policies, procedures, and standard responses.
Track compliance tasks, follow-ups, and deadlines to ensure nothing slips through the cracks.
Support external auditors and assessors by preparing materials, answering questions, and managing requests.
Continuously improve compliance and trust processes, identifying repeat gaps in customer questionnaires and driving documentation or process improvements to reduce reactive effort over time.
Who you are
You have 35 years of experience in security, compliance, or risk operations, with hands-on exposure to SOC 2 and/or ISO 27001
You're detail-oriented and comfortable validating whether documented controls match real-world systems and workflows
You can confidently coordinate with Engineering, IT, Security, and Product teams to clarify technical details and close gaps
You've worked with compliance platforms (Drata preferred) and understand how evidence, controls, and audits actually work in practice
You're highly organized and thrive in bringing order to complex, cross-functional workflows
You're comfortable coordinating with Engineering and Product teams and translating compliance requirements into clear action items
You write clearly and confidently in English especially when responding to security questionnaires and auditor requests
You're a self-starter who can run with ambiguity, follow through, and close loops without constant oversight
You care about doing things right, but you're practical and know how to balance rigor with speed