Relay Robotics

Compliance Manager

Relay Robotics$95K — $115K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Degree in Computer Science, IT, or related field or equivalent compliance certifications.
  • 5+ years in information security compliance, GRC, or audit roles; 2 years managing certification programs.
  • Hands-on experience with end-to-end SOC 2 Type II audits including auditor management.
  • Understanding of HIPAA, ISO 27001:2022, and PCI DSS requirements.
  • Expertise with Drata or similar GRC platforms for compliance management.
  • Experience managing external auditors and internal audit programs.
  • Outstanding interpersonal skills for effective communication across departments.

Responsibilities

  • Own and manage Relay's compliance certification portfolio and audit readiness.
  • Serve as the Drata subject matter expert, maintaining workflows and control mapping.
  • Manage relationships with external auditors, coordinating audit processes effectively.
  • Run the internal audit program, including planning, executing, and tracking findings.
  • Maintain control management across all compliance frameworks and support control owners.
  • Oversee policy management lifecycle, ensuring compliance policies are current and tracked well.
  • Conduct third-party vendor risk management, including security reviews and documentation.

Benefits

  • Collaborative work culture that emphasizes compliance as a shared goal.
  • Opportunity for significant impact on compliance timelines and company operations.
  • Engagement with senior leadership, offering visibility and influence across the organization.
  • Continuous professional development through managing diverse compliance frameworks.
Full Job Description
About the Role

Relay is hiring a Compliance Manager to own our compliance program end-to-end. Reporting to the Sr. Manager of IT & Security and working closely with the SVP of IT & Security, you will run our active certification portfolio - SOC 2 Type II + HIPAA, ISO 27001:2022, and PCI DSS - and serve as our Drata expert, the GRC platform at the center of everything we do. You'll manage our external auditors directly from within Drata, keeping evidence, controls, and audit workflows moving so certifications land on schedule, every time.

This is an ownership role, not a coordination role. The certification calendar, internal audit program, control library, policy lifecycle, and third-party vendor risk program will all be yours. And because compliance at Relay is a company-wide effort, your success depends on how well you work with department leaders across the entire organization - earning their trust, making their obligations clear and achievable, and holding the line on deadlines and requirements with professionalism and tact. If you can make compliance feel like a shared win rather than a burden, this role is built for you.
About the Team

You'll join a small, high-leverage IT & Security team responsible for protecting a fast-growing, cloud-first company. We manage a broad technology stack - from identity and device management to SaaS administration and enterprise automation - and we operate as true partners to the business, not just a support function. We move fast, build thoughtfully, and take pride in running a tight, well-integrated environment. We deliberately run a lean internal team amplified by strategic partners and AI-driven tooling, so every member owns real scope, works directly with senior leadership, and sees the impact of their work across the entire organization.
Responsibilities
  • Own Relay's compliance certification portfolio - SOC 2 Type II + HIPAA, ISO 27001:2022, and PCI DSS - including the master certification schedule, audit readiness, and on-time completion of every engagement.
  • Serve as Relay's Drata subject matter expert: administer the platform, maintain control mapping and continuous monitoring, manage evidence collection workflows, and drive adoption across control owners.
  • Manage the relationship with our external auditors directly from within Drata - coordinate audit windows, fieldwork, evidence requests, findings, and remediation through to report issuance.
  • Run the internal audit program: plan and execute control testing, document results, track findings to remediation, and prepare the organization ahead of every external audit.
  • Own control management across all frameworks - maintain the unified control library, assign and support control owners, monitor control health, and remediate gaps and drift.
  • Own the policy management lifecycle - draft, review, update, route for approval, publish, and track attestation of security and compliance policies on their required cadence.
  • Own third-party vendor risk management: security and compliance reviews for new vendors, periodic reassessments, vendor documentation, and risk tracking through to acceptance or remediation.
  • Partner with department leaders across the company to assign compliance responsibilities, communicate requirements in plain language, and hold owners accountable to deadlines with firmness and tact.
  • Support customer trust activities, including security questionnaires, customer audit requests, and maintenance of compliance documentation and the trust center.
  • Report compliance posture, audit status, risks, and program metrics to security leadership and the Security Steering Committee on a regular cadence.
Required Qualifications
  • A degree in Computer Science, IT, or a security-related discipline; equivalent compliance certifications (CRISC, CGRC, GRCP, CISM, or CISA) will be considered in place of a formal degree.
  • 5+ years of experience in information security compliance, GRC, or audit roles, with at least 2 years directly managing certification programs.
  • Hands-on experience running SOC 2 Type II audits end-to-end, including auditor management, evidence collection, and remediation.
  • Working knowledge of HIPAA security requirements, ISO 27001:2022 (including ISMS operation and surveillance/recertification audits), and PCI DSS.
  • Expert-level proficiency with Drata or a comparable GRC/compliance automation platform (Vanta, Secureframe, Hyperproof), including control mapping, monitoring, and auditor collaboration workflows.
  • Demonstrated experience managing external audit firms through complete audit cycles.
  • Experience building and running internal audit and control testing programs.
  • Experience owning policy management and third-party vendor risk programs.
  • Exceptional interpersonal and communication skills: you can translate framework requirements into plain language for any department leader, drive accountability without creating friction, and set a tone that makes compliance a partnership.
  • Strong organizational and project management skills - you can run multiple concurrent audit timelines without letting anything slip.
Preferred Qualifications
  • Relevant certifications such as CISA, CISM, CRISC, ISO 27001 Lead Implementer/Lead Auditor, or CIPP.
  • Experience adding new frameworks to an existing program (e.g., HIPAA, NIST, or FedRamp onto an ISO 27001 foundation).
  • Experience in a fast-paced, cloud-first SaaS environment serving enterprise customers.
  • Familiarity with security tooling that feeds compliance evidence (endpoint protection, identity management, awareness training platforms).
  • Experience presenting to management, leadership and steering committees.
What success and impact looks like in this role:
  • Every certification in the portfolio - SOC 2 Type II + HIPAA, ISO 27001:2022, and PCI DSS - is completed on schedule with no lapses and minimal findings.
  • Drata is fully operationalized: controls mapped across frameworks, continuous monitoring healthy, evidence automated wherever possible, and Auditors working seamlessly within the platform.
  • The internal audit program surfaces and closes gaps before external auditors find them.
  • Policies are current, approved, and attested on schedule; the vendor risk program has full coverage of Relay's third parties with no aging reviews.
  • Department leaders view compliance as a well-run partnership - requirements are clear, deadlines are met, and escalations are rare because the relationships are strong.

About Relay Robotics

Relay Robotics is a robotics company that develops autonomous delivery robots for the food and beverage industry. The company's robots are designed to deliver food and drinks to customers in restaurants and cafes. Relay Robotics was founded in 2015 and is headquartered in San Francisco, California.
Learn more about Relay Robotics
Industry
Founded
2013

Similar Jobs

More Jobs at Relay Robotics

  • Relay Robotics
    Compliance Manager
    $95K — $115K *
    Raleigh, NC 27610 (Wake County)
    Information Technology
    In-Person

More Information Technology Jobs

Find similar Compliance Manager jobs: