A Little About the RoleWe're looking for a Compliance Manager to own and mature our compliance program as we scale. You'll be the primary driver of our SOC 2 Type 2 audit program for 5 products, and will provide critical support across SOX, privacy, PCI, HIPAA, and additional regulatory and professional framework compliance efforts. This is a hands-on role for someone who enjoys building repeatable processes, working cross-functionally with engineering and IT teams, and translating regulatory and contractual requirements into practical, auditable controls for business units.
You'll lead a small team: analysts, contractors, stakeholders - making this a great opportunity for someone ready to take on people leadership while staying close to the technical and operational details of compliance work.
What you'll do:- SOC 2 Type 2: Own the end-to-end audit lifecycle - scoping, control design, evidence collection, auditor liaison, remediation tracking, and continuous monitoring between audit cycles.
- SOX Support: Assist with IT general controls (ITGCs) testing, walkthroughs, and coordination with internal audit and external auditors to support financial reporting compliance.
- Privacy Audits: Support privacy compliance efforts (e.g., GDPR, CCPA/CPRA) including audit prep, control validation, and documentation of data handling practices.
- PCI Compliance: Support PCI DSS assessments, including scoping, control validation, and coordination with payment processing and engineering teams.
- Data Processing Addendums (DPAs): Review, negotiate and track DPAs with customers, vendors, and subprocessors, ensuring alignment with our data protection commitments and privacy obligations.
- Vendor & Third-Party Risk: Assess subprocessors and vendors for compliance posture and contractual data protection requirements.
- Controls Oversight: Partner with Engineering, IT, and Security teams to design, implement, and monitor controls; maintain a strong evidence trail and control library.
- Policy & Process: Maintain and evolve compliance policies, procedures, and control narratives to reflect the current environment and audit requirements, including ensuring NEO and annual training is released and accurate.
- Audit Readiness: Serve as a key point of contact for external auditors, customer security questionnaires, and due diligence requests.
- Continuous Improvement: Identify opportunities to automate evidence collection and streamline control monitoring using GRC tooling.
Our ideal candidate will have:- 4+ years' of experience in compliance, information security, or IT audit, with direct experience running or supporting SOC 2 Type 2 audits.
- Working knowledge of SOX ITGC concepts, privacy frameworks (GDPR/CCPA), and PCI DSS requirements - you don't need to be a deep expert in all four, but you should be comfortable supporting each.
- Experience reviewing contract terms.
- Familiarity with common control frameworks (e.g., HIPAA, AICPA Trust Services Criteria, NIST CSF, ISO 27001).
- Prior experience managing or mentoring junior team members or contractors.
- Strong written and verbal communication skills - you can explain control requirements to engineers and translate technical detail for auditors and leadership.
- Comfortable working in a fast-paced SaaS environment with evolving systems and processes.
- Bachelor's degree in a related field, or equivalent practical experience.
- Experience working with GRC platforms (e.g., Vanta, Drata, OneTrust, ServiceNow GRC) is a strong plus.
- Relevant certifications: CISA, CISM, CIPP/E, CIPP/US, or similar.
- Experience supporting multiple concurrent audit cycles in a SaaS or cloud environment.
- Experience with cloud infrastructure (AWS, GCP, or Azure) and understanding of how technical controls map to compliance requirements.
Physical Requirements:- This position works most of the time in a fixed office location and may involve sitting and/or standing for prolonged periods
- Frequently required to communicate verbally and in writing (mostly email) with customers, prospects, and other employees
- Use of computer, telephone, and other office equipment for the greater part of the workday
- Occasional travel may be required for this position
Salary$139,400 - $150,700/year DOE
LocationThis position can be based in our Denver, CO or Atlanta, GA offices. Procare operates in a hybrid working model based on business needs. Candidates must be willing and able to work in office a minimum of 3 days per week.