Product Operations, Security & Compliance

Clay Labs

• $100K — $120K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Information Security, Business, or related field (or equivalent experience)
  • 2+ years of experience in building and scaling operational programs, preferably in a SaaS or tech environment
  • Strong builder mindset with a passion for creating processes from scratch
  • Understanding of privacy laws and frameworks (GDPR, CCPA/CPRA) and their practical application
  • Experience with vendor risk assessments, security questionnaires, and DPA/subprocessor management
  • Familiarity with DSAR processes and compliance tools like Vanta or Transcend
  • Excellent project management skills for driving complex initiatives
  • Strong communication skills for collaboration with legal, engineering, and business teams

Responsibilities

  • Build and own the end-to-end vendor onboarding compliance process
  • Manage internal and external GRC vendor relationships, including intake and performance metrics
  • Ensure integration of teams and systems into Clay's compliance tools and framework
  • Conduct compliance reviews for new data sets and vendor compliance
  • Create operational processes from scratch to scale compliance work across the company
  • Assist in responding to security and privacy questionnaires from customers

Benefits

  • Opportunity to shape compliance processes from the ground up
  • Work at the intersection of multiple teams, enhancing cross-functional collaboration
  • Engage in a fast-paced, high-growth environment
  • Contribute to building trust with customers through privacy and compliance initiatives
Full Job Description
Product Operations @ Clay

As Clay continues to scale, privacy and compliance have become core to how we operate and build trust with our customers. We're looking for a Product Operations individual contributor to build and own the operational systems that keep us compliant across vendor management, data privacy, and security. You'll be creating scalable processes from scratch to support teams across the company as they onboard vendors and handle customer information. You'll work at the intersection of engineering, security, legal and business teams to build processes that scales with our growth.

What You'll Do:
  • Vendor Onboarding & Risk Management: Build and own the end-to-end vendor onboarding compliance process. When teams want to onboard a new vendor, conduct proper review (DPA, SOC 2/GDPR data compliance), update our subprocessor list, and manage customer notifications
  • GRC Vendor Management: Serve as the internal owner and point of contact for external GRC vendors. Manage intake, ticketing, SLAs, quality review, and performance metrics to ensure security and compliance requests are tracked, resolved, and continuously improved
  • Data Privacy Program Management: Ensure teams and systems are integrated into our Clay's compliance tools and framework, include for data subject access/deletion rights (DSAR). Partner with Security, Legal, Marketing, Data, and other stakeholders to scale privacy-by-design practices
  • Compliance Reviews: Build processes for and complete compliance reviews when teams evaluate purchasing new data sets and vendor compliance.
  • Cross-Functional Program Building: Create operational processes and systems from scratch to scale compliance work across the company. You'll own programs end-to-end, not just coordinate projects
  • Customer Security Support: Assist in responding to security and privacy questionnaires from prospective and existing customers, with a particular focus on privacy, data protection, and compliance-related questions


What You'll Bring
  • Bachelor's degree in Information Security, Business, or a related field (or equivalent experience)
  • 2+ years of experience building and scaling operational programs, ideally in a SaaS or tech environment
  • Strong builder mindset: you're excited to create processes and systems from scratch, not just maintain existing ones
  • Understanding of privacy laws and frameworks (GDPR, CCPA/CPRA, etc.) with the ability to apply them practically across vendor management, data flows, and employee compliance
  • Experience with vendor risk assessments, security questionnaires, and DPA/subprocessor management
  • Familiarity with DSAR processes and compliance tools like Vanta, Transcend, or similar platforms
  • Excellent project management skills with the ability to drive complex, cross-functional initiatives to completion
  • Strong communication skills for partnering with legal, engineering, data teams, and business stakeholders
  • Ability to work independently, prioritize effectively, and adapt in a fast-paced, high-growth environment


Bonus Points
  • Knowledge of additional compliance standards (e.g., ISO 27001, SOC 2)
  • Experience with data mapping, privacy impact assessments (PIAs), or incident response in a privacy context
  • Technical aptitude for understanding SaaS infrastructure and data flows

Similar Jobs

More Jobs at Clay Labs

More Information Technology Jobs

Find similar Product Operations, Security & Compliance jobs: