Compliance & Certification Lead – SOC 2 / ISO 27001

Speedrun Talent Network

Northern (KY)

Remote

USD 103,000 - 138,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Equity
Generous perks and benefits

Job summary

Sourcegraph seeks a Compliance Manager to own governance, risk, and compliance with a primary focus on compliance for a fast-moving tech environment. You will drive SOC 2 and ISO 27001 initiatives, manage audits end-to-end, tailor controls to our cloud-based setup, and guide internal teams and customers through compliance requirements.

You will collaborate across Security, Engineering, IT, Legal, People, and Sales while shaping the compliance program, risk management, and ISMS documentation for

Qualifications

  • 5+ years of experience in governance, risk, compliance, information security compliance, or a related role.
  • End-to-end ownership of SOC 2 and ISO 27001 programs, ideally within a SaaS, technology startup, or similarly fast-moving environment.
  • Experience personally managing external audits and certification processes, including audit preparation, evidence collection, control testing, stakeholder training, auditor interaction, remediation, and follow-up.
  • Strong understanding of risk management, ISMS governance, and compliance program operations.
  • Experience adapting compliance controls to an organization’s actual environment rather than applying generic or overly prescriptive requirements.
  • Familiarity with cloud-based technology environments and the security and compliance considerations associated with a distributed or remote workforce.
  • Strong project management and organizational skills with the ability to drive cross-functional initiatives from inception through completion.
  • Excellent written and verbal communication skills and the ability to explain compliance requirements clearly to both technical and non-technical audiences.
  • A hands-on mindset and willingness to personally execute the work required to keep the compliance program operating effectively.
  • Curiosity about AI, automation, and emerging technology, with an interest in using new tools to improve compliance workflows.
  • Nice-to-haves: GDPR, HIPAA, HITRUST, FedRAMP, FISMA, PCI DSS or related standards.
  • Experience supporting security questionnaires, customer assurance processes, or sales-related compliance activities.
  • Experience with GRC platforms, compliance automation tools, or building internal automation for evidence collection and control monitoring.
  • Certifications such as CISA, CISSP, ISO 27001 Lead Implementer or Lead Auditor, CRISC, or similar credentials.

Responsibilities

  • Build strong working relationships across Security, Engineering, IT, Legal, People, Sales, and other key stakeholders.
  • Develop a clear understanding of Sourcegraph’s governance, risk, and compliance program, including ISMS, risk register, controls, certifications, audit processes, and current areas of focus.
  • Understand how SOC 2 and ISO 27001 programs operate today, including key owners, evidence requirements, open risks, and upcoming milestones.
  • Participate in day-to-day compliance activities and identify opportunities to improve or simplify existing processes.
  • Take ownership of Sourcegraph’s ongoing SOC 2 and ISO 27001 compliance programs.
  • Independently manage key audit activities, including control testing, evidence collection, stakeholder coordination, auditor requests, findings, and remediation.
  • Evaluate existing controls and tailor them to Sourcegraph’s environment.
  • Maintain ISMS processes, policies, and compliance documentation.
  • Help internal teams understand their compliance responsibilities and provide practical guidance.
  • Support customer-facing compliance activities, including security questionnaires and questions from customers.

Skills

Governance
Risk management
Compliance program
SOC 2
ISO 27001
Cross-functional collaboration
Project management
Security concepts
Cloud environments

Education

Bachelor's degree in a related field

Tools

GRC platforms
Compliance automation tools

Job description

Sourcegraph seeks a Compliance Manager to own governance, risk, and compliance with a primary focus on compliance for a fast-moving tech environment. You will drive SOC 2 and ISO 27001 initiatives, manage audits end-to-end, tailor controls to our cloud-based setup, and guide internal teams and customers through compliance requirements.

You will collaborate across Security, Engineering, IT, Legal, People, and Sales while shaping the compliance program, risk management, and ISMS documentation for

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Compliance Manager - SOC 2 & ISO 27001 Lead
Compliance Manager - SOC 2 & ISO 27001 Lead

Sourcegraph, Inc. • Northern (KY)

Remote
USD 103,000 - 138,000
Equity
Benefits
Compliance Program Lead: SOC 2 & ISO 27001
Compliance Program Lead: SOC 2 & ISO 27001

Real Work From Anywhere Ltd. • United States

Remote
USD 120,000 - 180,000
Senior Compliance Manager: SOC 2 & ISO 27001
Senior Compliance Manager: SOC 2 & ISO 27001

Inclusively Remote • United States

Remote
USD 103,000 - 138,000
Senior Compliance Lead: SOC 2 & ISO 27001
Senior Compliance Lead: SOC 2 & ISO 27001

Sourcegraph, Inc. • United States

Remote
USD 120,000 - 180,000
Compliance Manager (Fully Remote)
Compliance Manager (Fully Remote)

Sourcegraph, Inc. • United States

Remote
USD 120,000 - 180,000
Compliance Manager: SOC 2, Privacy & Hybrid Role
Compliance Manager: SOC 2, Privacy & Hybrid Role

Procare Solutions • Denver (CO)

Hybrid
USD 139,000 - 151,000
Medical, dental, & vision plans
HSA with employer contributions
Vacation, holidays, sick days, and PTO
+1
Security & Compliance Manager - SOC 2, ISO 27001
Security & Compliance Manager - SOC 2, ISO 27001

Augmodo • San Francisco (CA)

On-site
USD 125,000 - 165,000
Medical, dental, vision
401k with company match
Equity
Compliance Engineering Lead - Automate & Certify Trust
Compliance Engineering Lead - Automate & Certify Trust

Socket • United States

On-site
USD 150,000 - 190,000
Equity program
Health benefits
Remote-first culture
+1
InfoSec Leader - ISO 27001/SOC 2 (SaaS)
InfoSec Leader - ISO 27001/SOC 2 (SaaS)

Staffbase • United States

Remote
USD 140,000 - 210,000
31 vacation days
Flexible working time
LTIP
Remote Technology Compliance Lead (SOC 2, ISO 27001)
Remote Technology Compliance Lead (SOC 2, ISO 27001)

Electric Power Engineers, LLC • Austin (TX), Northern (KY)

Hybrid
USD 120,000 - 180,000
Health benefits
Generous PTO
Employee ownership
+1