Назад
Company hidden
11 часов Π½Π°Π·Π°Π΄

Head of Compliance

Π€ΠΎΡ€ΠΌΠ°Ρ‚ Ρ€Π°Π±ΠΎΡ‚Ρ‹
remote (Ρ‚ΠΎΠ»ΡŒΠΊΠΎ USA)
Π’ΠΈΠΏ Ρ€Π°Π±ΠΎΡ‚Ρ‹
fulltime
Π“Ρ€Π΅ΠΉΠ΄
head
Английский
b2
Π‘Ρ‚Ρ€Π°Π½Π°
US
Вакансия ΠΈΠ· списка Hirify.GlobalВакансия ΠΈΠ· Hirify Global, списка ΠΌΠ΅ΠΆΠ΄ΡƒΠ½Π°Ρ€ΠΎΠ΄Π½Ρ‹Ρ… tech-ΠΊΠΎΠΌΠΏΠ°Π½ΠΈΠΉ
Для мэтча ΠΈ ΠΎΡ‚ΠΊΠ»ΠΈΠΊΠ° Π½ΡƒΠΆΠ΅Π½ Plus

ΠœΡΡ‚Ρ‡ & Π‘ΠΎΠΏΡ€ΠΎΠ²ΠΎΠ΄

Для мэтча с этой вакансиСй Π½ΡƒΠΆΠ΅Π½ Plus

ОписаниС вакансии

ВСкст:
/
TL;DR
Head of Compliance (SOC 2/ISO 27001): Building and owning Treeline's internal security and compliance program while delivering SOC 2 and ISO 27001 readiness engagements for customers with an accent on audit preparation, control implementation, and scalable compliance frameworks. Focus on managing concurrent customer engagements, coordinating auditors and penetration testing, and turning field experience into a repeatable Compliance-as-a-Service product.

Location: United States β€” remote; US-based candidates required. Occasional travel to customer sites may be required. San Francisco, Los Angeles, Austin, or remote.

Company

hirify.global is building an automation- and AI-powered software stack for managed service providers serving small and mid-market businesses.

What you will do

  • Own hirify.global's internal compliance program, including controls, evidence collection, Vanta or Drata hygiene, auditor coordination, policies, risk registers, vendor assessments, and ISMS documentation.
  • Drive SOC 2 Type II and ISO 27001 certification efforts from gap assessment through audit preparation.
  • Lead customer SOC 2 and ISO 27001 readiness engagements, including scoping, control implementation, audit preparation, and coordination of penetration testing.
  • Manage multiple concurrent customer engagements and communicate with security engineers, founders, CISOs, and other stakeholders.
  • Build repeatable frameworks, scoping standards, and customer-facing artifacts for the Compliance-as-a-Service offering.
  • Feed customer insights into hirify.global's platform and product decisions.

Requirements

  • 5–8+ years of experience in compliance, security, or risk.
  • Meaningful experience at or alongside an audit or advisory firm, such as a SOC 2 audit practice, Big Four risk practice, or compliance consultancy.
  • End-to-end experience running SOC 2 and ISO 27001 readiness projects.
  • Hands-on experience building compliance frameworks from scratch.
  • Deep familiarity with SOC 2 and ISO 27001; Vanta or Drata experience is strongly preferred.
  • Must be US-based and able to travel occasionally to customer sites.

Nice to have

  • FedRAMP familiarity.

Culture & Benefits

  • Founding equity and competitive base salary.
  • Comprehensive health, dental, and vision coverage.
  • Flexible paid time off.
  • Remote-first work environment with direct partnership with engineering and leadership.
  • Small, collaborative team with an emphasis on execution, autonomy, and minimal bureaucracy.

Π‘ΡƒΠ΄ΡŒΡ‚Π΅ остороТны: Ссли Ρ€Π°Π±ΠΎΡ‚ΠΎΠ΄Π°Ρ‚Π΅Π»ΡŒ просит Π²ΠΎΠΉΡ‚ΠΈ Π² ΠΈΡ… систСму, ΠΈΡΠΏΠΎΠ»ΡŒΠ·ΡƒΡ iCloud/Google, ΠΏΡ€ΠΈΡΠ»Π°Ρ‚ΡŒ ΠΊΠΎΠ΄/ΠΏΠ°Ρ€ΠΎΠ»ΡŒ, Π·Π°ΠΏΡƒΡΡ‚ΠΈΡ‚ΡŒ ΠΊΠΎΠ΄/ПО, Π½Π΅ Π΄Π΅Π»Π°ΠΉΡ‚Π΅ этого - это мошСнники. ΠžΠ±ΡΠ·Π°Ρ‚Π΅Π»ΡŒΠ½ΠΎ ΠΆΠΌΠΈΡ‚Π΅ "ΠŸΠΎΠΆΠ°Π»ΠΎΠ²Π°Ρ‚ΡŒΡΡ" ΠΈΠ»ΠΈ ΠΏΠΈΡˆΠΈΡ‚Π΅ Π² ΠΏΠΎΠ΄Π΄Π΅Ρ€ΠΆΠΊΡƒ. ΠŸΠΎΠ΄Ρ€ΠΎΠ±Π½Π΅Π΅ Π² Π³Π°ΠΉΠ΄Π΅ β†’