FloQast

Risk & Controls Manager

FloQast • $115K — $155K *
Finance & Insurance
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree required
  • 6+ years in compliance, risk management, or information security, preferably in SaaS
  • Strong expertise in compliance areas like privacy and security
  • Experience with SOC and ISO compliance frameworks
  • Foundational knowledge of GDPR, CCPA, and international privacy laws
  • Excellent communication and interpersonal skills
  • Highly organized and proactive in risk identification

Responsibilities

  • Collaborate with stakeholders to align documentation and policies with regulatory expectations
  • Conduct compliance impact assessments for risk, privacy, and AI
  • Provide strategic guidance on compliance inquiries from internal teams
  • Ensure adherence to SOC and ISO standards in security and compliance programs
  • Manage FloQast's privacy program and data subject requests
  • Oversee third-party risk management and vendor reviews
  • Identify and implement process improvements, including automation and AI

Benefits

  • Medical, Dental, and Vision insurance
  • Family Forming benefits
  • Life & Disability Insurance
  • Unlimited Vacation policy
  • Participation in Employee Stock Program
Full Job Description
FloQast is looking for a Risk & Controls Manager to join our growing InfoSec & Compliance department. This role serves as a risk and controls advisor, ensuring adherence to key compliance frameworks across the organization, and evaluating business initiatives from a risk and controls perspective to help ensure that FloQast's operations, products, and services remain aligned with regulatory, contractual, and internal requirements. This role will own several core risk domains, including privacy, third-party risk management, and policy management, and will also contribute to broader risk program initiatives, including issue management and process automation. We are looking for a well-rounded GRC professional who can operate across multiple risk and compliance domains, with the scope of this role expected to evolve as the needs of the department grow.

The InfoSec & Compliance department at FloQast reports directly to the General Counsel and is responsible for ensuring FloQast manages risk and maintains compliance with an array of frameworks covering security, privacy, AI, and financial reporting. We are a team of in-house subject matter experts who advise, direct, train, and monitor the organization, resulting in daily interactions with all departments on a variety of unique and interesting business initiatives.

This role has a requirement of working in office 3 days per week, which may be subject to change based on team and business needs, as determined by the department leader. Please note that this requirement is subject to ongoing review and may be adjusted in the future.

*Visa sponsorship is NOT available at this time

What You'll Do

  • Collaborate and drive cross-functional alignment with internal stakeholders to review, maintain, and align documentation, policies, and procedures with audit and regulatory expectations
  • Conduct and document compliance impact assessments covering risk, privacy, and AI considerations to support organizational decision-making
  • Provide strategic, risk-informed guidance in response to compliance-related inquiries from internal teams
  • Support FloQast's security and compliance programs by ensuring adherence to applicable SOC and ISO standards
  • Own execution of FloQast's established privacy program, including maintaining privacy documentation, supporting data subject requests, and ensuring ongoing compliance with applicable privacy laws
  • Manage FloQast's sub-processor program, including maintaining notification workflows, coordinating updates to the sub-processor list, and responding to client inquiries related to sub-processor changes
  • Support privacy-related product and vendor reviews, escalating regulatory considerations as needed
  • Own third-party risk management processes and associated due diligence activities, including coordinating vendor reviews and supporting procurement needs
  • Own policy management processes across the organization, including facilitating annual reviews, coordinating updates with policy owners, maintaining version history, and routing finalized policies for approval
  • Support the identification, tracking, and remediation of compliance and policy-related issues, partnering with relevant stakeholders to drive resolution
  • Identify opportunities for process improvement, including automation and AI, within the risk management and compliance function, and actively develop and implement AI-driven workflows to enhance program efficiency and scalability
  • Any other tasks that may be assigned to help the company meet its goals


What You'll Bring

  • Bachelor's degree
  • 6+ years of experience in compliance, risk management, information security, privacy, or a related field, with SaaS industry experience preferred
  • Strong general compliance expertise, including areas such as privacy, security, and IT general controls
  • Experience applying and maintaining compliance with frameworks such as SOC and ISO standards
  • Foundational knowledge of privacy regulations and frameworks such as GDPR, CCPA, and related international privacy laws
  • Strong communication and interpersonal skills, with the ability to collaborate effectively across teams and functions
  • Highly organized, detail-oriented, and proactive in identifying and addressing compliance risks
  • Ability to operate autonomously and drive risk and compliance initiatives with limited oversight
  • Flexible and adaptable in a high-growth, fast-paced environment


Nice to haves/Others

  • Certifications such as CIA, CISA, CISSP, CISM, CIPP/E, CIPM, or similar
  • Experience with cloud hosting environments such as AWS, Azure, or GCP
  • Experience with emerging technologies, including AI-driven features and associated risk considerations
  • Prior experience supporting international compliance initiatives or privacy regulatory readiness across multiple jurisdictions


The base pay range for this position is $115,000 - $155,000. Compensation is not limited to base salary. FloQast values our Total Rewards, and offers a competitive and elaborate Benefits Package including, but not limited to, Medical, Dental, Vision, Family Forming benefits, Life & Disability Insurance, Unlimited Vacation, and participation in our Employee Stock Program. FloQast reserves the right to amend, change, alter, and revise pay ranges and benefits offerings at any time. All applicants acknowledge that by applying to this position you understand that this specific pay range is contingent upon meeting the qualifications and requirements of the role, and for the successful completion of the interview selection and process. It is at the Company's discretion to determine what pay is provided to a candidate within the range associated with the role.

#LI-Hybrid

#LI-LB1

#BI-Hybrid

If this aligns closely with what you are looking for, hit "Apply" and come join our growing team!

About FloQast

FloQast is a provider of accounting workflow automation software created by accountants for accountants. The company was founded in 2013 by Mike Whitmire and Chris Sluty and is headquartered in Los Angeles, California. FloQast's software helps accounting teams close their books faster and more accurately by automating manual tasks and providing a centralized platform for collaboration and documentation. The company has raised over $93 million in funding and has over 1,000 customers, including Twilio, Zillow, and The Golden State Warriors.
Learn more about FloQast
Size
300 employees
Industry
Founded
2013

Similar Jobs

More Jobs at FloQast

More Finance & Insurance Jobs

Find similar Risk & Controls Manager jobs: