About the RoleAnyscale's security and compliance needs are growing as we work with larger and more demanding customers. Compliance is increasingly a customer-facing, contractual function rather than an internal exercise, and we are looking for someone to own it.
This role owns that function end to end: our audits, our evidence base, our risk register, and the security diligence that customers put us through before and during a contract. You will work directly with the Head of Security and across engineering, IT, legal, and sales. This is a program-ownership role with the autonomy and accountability that implies. You will not have a senior compliance function above you to defer to; you are that function.
In your first year, success looks like a complete and defensible evidence base with clean audit outcomes, a repeatable way to answer customer security diligence, and a risk register that leadership actually uses.
What You'll Do- Own our SOC 2 Type II and ISO 27001 programs, and future frameworks as we take them on, including scope, evidence, control operation, and the relationship with our external auditors.
- Own and complete the control evidence base in our compliance automation platform, moving controls from partially substantiated to audit-ready and keeping them there.
- Lead security diligence for enterprise and regulated customers: security questionnaires, audit responses, right-to-audit requests, and the recurring reporting these customers require.
- Own the risk register and mature risk management from a security-team activity into a recorded, enterprise-aligned program.
- Coordinate the compliance obligations that come with customer contracts, including data protection, breach-notification timelines, and vendor and subprocessor assessments, in partnership with legal.
- Assess and stand up new certifications as the customer pipeline requires them.
- Partner with engineering and IT to make evidence collection a byproduct of how systems already run, rather than a manual scramble before each audit.
What You'll Bring- 7+ years in governance, risk, and compliance, ideally including time at a high-growth startup.
- Demonstrated ownership of SOC 2 and ISO 27001 programs, including running audits end to end with external auditors.
- Experience fronting security diligence for enterprise or regulated customers. You have sat across from a customer's auditors or security reviewers and held your own.
- Working fluency with compliance automation platforms (such as Vanta or equivalent) and with turning tooling into genuinely audit-ready evidence, not just dashboards.
- A strong grasp of security controls and how they operate in a cloud and SaaS environment, enough to work credibly with engineers rather than only collecting their attestations.
- The judgment and communication to run a program independently, coordinate across functions, and be trusted as the single owner of compliance.
Nice to Have- Experience with regulated-customer contractual security obligations: data protection agreements, breach notification, and right-to-audit provisions.
- Exposure to newer or higher-bar frameworks (for example FedRAMP) and a sense of what standing them up would take.
- Experience building a compliance function or team, since this role can grow into one as the company scales.
- Familiarity with cloud infrastructure or AI or ML platforms.