Назад
17 часов назад

Security Compliance Lead (Fintech)

130 000 - 190 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
lead
Английский
c1
Страна
US/Canada/Brazil
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Compliance Lead (Fintech): Owning Sardine’s end-to-end security compliance and GRC program across SOC 2, PCI DSS, ISO 27001, privacy regulations, DORA, and FedRAMP with an accent on audit readiness, control rationalization, risk management, and customer assurance. Focus on coordinating NIST SP 800-53 implementation and 3PAO assessment, presenting control risks to senior leadership and the board, and leading a growing compliance team.

Location: Remote - US

Salary: $130K–$190K plus equity; compensation depends on location, qualifications, work history, and interview performance.

Company

Sardine provides an agentic risk platform that unifies data to fight financial crime, stop fraud and AI-driven attacks, and automate fraud and AML operations.

What you will do

  • Own the security compliance and GRC program across SOC 2 Type II, PCI DSS Level 1, ISO 27001, GDPR, CCPA, and DORA.
  • Drive the FedRAMP authorization effort, including NIST SP 800-53 controls, 3PAO assessment coordination, and continuous monitoring.
  • Act as the primary interface for auditors, regulators, and industry stakeholders while partnering with engineering, IT, product, security, and legal.
  • Own the control framework, security policies, risk register, risk quantification, and executive reporting.
  • Lead customer assurance activities, security questionnaires, attestations, evidence management, and compliance process improvements.
  • Lead, mentor, and develop the Security Compliance Analyst while scaling the compliance function.

Requirements

  • 7+ years of experience in security compliance, GRC, or audit, including end-to-end ownership of audit or certification programs.
  • Deep knowledge of PCI DSS, SOC 2, ISO 27001, GDPR, CCPA, DORA, NIST CSF, and CIS controls.
  • Technical and product fluency sufficient to collaborate effectively with engineering and product teams.
  • Strong written and verbal communication skills, including executive-ready documentation and presentations.
  • Experience in a fast-paced, high-growth environment; fintech or payments experience is strongly preferred.
  • Experience leading or mentoring others, or readiness to manage a direct report; willingness to travel as needed.

Nice to have

  • Direct experience running a PCI DSS Level 1 service provider program.
  • Hands-on exposure to DORA requirements.
  • Familiarity with GRC and security tooling such as Vanta, HRIS platforms such as Rippling, and macOS environments.

Culture & Benefits

  • Remote-first culture with a globally distributed team and flexibility to work from home or other suitable locations within the US.
  • Flexible paid time off and a year-end break.
  • Health, dental, and vision coverage for employees and dependents.
  • Cash and equity compensation, including early exercise for all options.
  • Home-office, meal, social meet-up, health and wellness, and learning stipends.
  • US and Canada benefits include 4% 401(k) or RRSP matching and a MacBook Pro.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →