DescriptionMassed Compute is looking for someone for a Security Program Manager role. This job involves owning the security program day-to-day, pursuing and obtaining ISO 27001 certification and leading FedRAMP readiness efforts.
This is a hands-on GRC seat. You run the queue: controls, evidence, auditors, vendors, questionnaires, and abuse. Engineering still patches systems. You make sure the evidence is real and the auditor has a named owner.
We will train you on the tools (Vanta), vendor reviews, and SOC 2 audits. You need good judgment, follow-through, and clear writing.
What you will do- Own GRC Tool (Vanta): failing controls, evidence, and following up with the people who actually fix things
- Be the primary contact for our SOC 2 auditor and the ISO 27001 certification body
- Maintain SOC 2 Type II compliance through audits (PBC lists, walkthroughs, findings response)
- Run vendor security reviews on a weekly cadence
- Answer customer security questionnaires; stand up and maintain a current Trust Center
- Own abuse / acceptable-use intake and enforcement process
- Own spam reporting and email blocking
- Keep HIPAA, GDPR, and EU AI Act documents accurate
- Finish our ISO 27001 ISMS package: procedures, Statement of Applicability, internal audit, management review
- Build a FedRAMP readiness folder (inventory, authorization boundary, control map from SOC 2/ISO to NIST 800-53). We start a 3PAO only if a named federal deal requires it
- Use AI to draft, research, and speed up routine GRC work; verify accuracy before any output is treated as auditable proof
- Own employee security onboarding and offboarding (accounts and access, Vanta tasks, MDM, background-check evidence, timely leaver cutoff)
What you need- You write clearly. This job is evidence, auditor email, and customer questionnaires
- You can own a queue: pick up work, follow up professionally, close the loop, and see items through to completion
- You work AI-first: you use automation to move faster, and you personally review the output before it becomes audit evidence or customer-facing material
- You are willing to be the named contact for auditors and customers once trained
Background in security, compliance, IT, operations, or similar process work helps. Direct SOC 2 / Vanta / vendor-review experience is not required.
Nice to have- SOC 2, ISO 27001, HIPAA, or GDPR exposure in any role
- Vanta, Drata, Secureframe, Sprinto, or another GRC tool
- Vendor security reviews or customer security questionnaires
- Policies or procedures you wrote that someone else actually used
- NIST 800-53 or FedRAMP as a contributor
- Cloud, IaaS, GPU cloud, or colocation familiarity
- Trust-and-safety, AUP, or abuse handling
Work Authorization
Applicants must be legally authorized to work in the United States and obtain security clearance. We are unable to sponsor work visas for this position.
Benefits- Market competitive compensation
- We are a remote-first company. You'll get a stipend to dial in your setup and additional opportunities to connect with your peers during periodic in person team gatherings
- Flexible PTO policy with the expectation that you take the time you need to recharge
- 100% coverage of medical, dental, and vision insurance for employees, 30% of premiums for dependents, plus a tax-advantaged Flexible Spending Account
- Company-facilitated 401(k) retirement plan
- Parental leave for all new parents