Security & Compliance Manager

Relocity

$140K — $170K *
US-AnywhereRemote in United States
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3-5 years of experience in information security, data privacy, governance, compliance, or risk management
  • Experience maintaining SOC 2 Type II and leading ISO 27001 certification in a SaaS environment
  • Hands-on experience with Vanta or similar GRC platforms like Drata or Secureframe
  • Strong knowledge of GDPR, CCPA, and related privacy regulations
  • Proven success in designing and implementing security and data governance programs
  • Familiarity with cloud infrastructure and security controls
  • Effective communication skills to convey technical information to diverse audiences

Responsibilities

  • Maintain SOC 2 Type II compliance and manage annual audits
  • Lead the effort to achieve ISO 27001 certification
  • Oversee compliance with GDPR, CCPA, and other relevant regulations
  • Improve security controls and governance standards
  • Conduct risk assessments and manage security incidents
  • Automate compliance monitoring and audit workflows using Vanta
  • Work with multiple teams to integrate security into business processes

Benefits

  • Paid Time Off
  • Paid Parental Leave
  • Remote Workplace
  • Flexible Work Schedules
  • Health, Dental, Vision, and LTD Insurance
  • 401(k)
  • Professional Development Opportunities
Full Job Description
What You Will Do

Relocity is seeking an experienced Security & Compliance Manager to maintain and strengthen our information security, privacy, and data governance programs. Reporting into leadership, you will partner closely with Engineering, Product, Operations, and G&A to keep our systems, processes, and policies aligned with evolving regulatory and security requirements as the company grows.

Our compliance foundation is already established. You will own the ongoing maintenance of our SOC 2 Type II program, lead our ISO 27001 certification effort to completion, and continuously improve our governance and risk management practices. You will use Vanta as our compliance platform to streamline monitoring, evidence collection, and audit readiness.

How You Will Do It

Security & Compliance
  • Maintain SOC 2 Type II compliance, including control operation, evidence collection, and annual audit readiness.
  • Lead the ISO 27001 certification effort, from gap assessment through certification and ongoing surveillance.
  • Own additional security and privacy frameworks, including GDPR, CCPA, and other applicable regulations.
  • Serve as the company's primary advisor on security, privacy, and compliance strategy.

Risk & Governance
  • Establish and continuously improve security controls, governance standards, policies, and risk management practices.
  • Conduct security risk assessments, manage incident response, and drive remediation efforts.
  • Administer Vanta and related tooling to automate compliance monitoring, continuous control testing, and audit workflows.

Cross-Functional Partnership
  • Partner with Engineering, Product, Operations, Legal, and leadership to embed security and privacy into products, systems, and business processes.
  • Translate technical risk into practical business recommendations that inform strategic decisions.

Data Protection & Awareness
  • Define enterprise data governance standards, including data classification, retention, and lifecycle management.
  • Lead company-wide security awareness initiatives that promote responsible data stewardship.

Continuous Improvement
  • Monitor evolving regulations, emerging threats, and industry best practices to strengthen our security program.
  • Evaluate and implement technologies and processes that improve automation, visibility, and operational efficiency.

What Will Enable Your Success
  • Experience: Three to Five years in information security, data privacy, governance, compliance, or risk management.
  • Compliance Leadership: Direct experience maintaining SOC 2 Type II and leading or supporting ISO 27001 certification within a SaaS or cloud-first environment.
  • Compliance Automation: Hands-on experience with Vanta or comparable GRC platforms such as Drata, Secureframe, or Sprinto.
  • Privacy Expertise: Strong working knowledge of GDPR, CCPA, and other applicable privacy regulations.
  • Governance: Demonstrated success designing and implementing data classification, retention, privacy, and security programs.
  • Technical Aptitude: Familiarity with cloud infrastructure, SaaS environments, identity and access management, and security controls.
  • Communication: Ability to explain complex technical concepts to technical and non-technical audiences.
  • Cross-Functional Leadership: Proven ability to influence stakeholders and lead initiatives across multiple functions.
  • Education: Bachelor's degree in Information Security, Computer Science, Information Systems, Business, Legal Studies, or a related field, or equivalent practical experience.

Nice to Have
  • Professional certifications such as CIPP/US, CIPM, CISSP, CISM, or CRISC.
  • Experience in a high-growth SaaS or technology startup environment.
  • Knowledge of privacy-by-design principles.
How We Support You and Work-Life Balance...
  • Competitive Compensation
  • Paid Time Off
  • Paid Parental Leave
  • Remote Workplace
  • Flexible Work Schedules
  • Health, Dental, Vision, and LTD Insurance
  • 401(k)
  • Professional Development Opportunities

Salary Range: $140,000 - $170,000 + bonus

#LI-Remote

#LI-AC2

Similar Jobs

More Jobs at Relocity

More Information Technology Jobs

Find similar Security & Compliance Manager jobs: