Compliance Manager

Anyscale

San Francisco (CA)

On-site

USD 180,000 - 240,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Anyscale is seeking a seasoned Governance, Risk, and Compliance leader to own SOC 2 Type II and ISO 27001 programs, manage evidence, and coordinate external audits across engineering, IT, legal, and sales. This program-ownership role requires autonomy and accountability.

You will build a defensible evidence base, mature the risk register, and enable enterprise security diligence for regulated customers with a broad internal partnership.

Qualifications

  • 7+ years in governance, risk, and compliance.
  • Experience owning security programs (SOC 2 Type II, ISO 27001).
  • Experience fronting security diligence for enterprise or regulated customers.

Responsibilities

  • Own SOC 2 Type II and ISO 27001 programs, including scope, evidence, controls, and auditor relationships.
  • Develop and maintain the control evidence base in our compliance automation platform.
  • Lead security diligence for enterprise/regulatory customers: questionnaires, audit responses, and right-to-audit requests.
  • Own the risk register and mature risk management as a enterprise-wide program.
  • Coordinate compliance obligations in customer contracts with legal, including data protection and breach timelines.
  • Assess and stand up new certifications as needed by customers.

Skills

Governance
Risk management
Compliance
Security controls
Cloud/SaaS
Audits coordination

Tools

Vanta

Job description

At Anyscale, we're on a mission to democratize distributed computing and make it accessible to software developers of all skill levels. We're commercializing Ray, a popular open-source project that’s creating an ecosystem of libraries for scalable machine learning. Companies like OpenAI, Uber, Spotify, Instacart, Cruise, and many more, have Ray in their tech stacks to accelerate the progress of AI applications out into the real world. With Anyscale, we're building the best place to run Ray, so that any developer or data scientist can scale an ML application from their laptop to the cluster without needing to be a distributed systems expert. Proud to be backed by Andreessen Horowitz, NEA, and Addition with $250+ million raised to date.

About the Role

Anyscale's security and compliance needs are growing as we work with larger and more demanding customers. Compliance is increasingly a customer-facing, contractual function rather than an internal exercise, and we are looking for someone to own it. This role owns that function end to end: our audits, our evidence base, our risk register, and the security diligence that customers put us through before and during a contract. You will work directly with the Head of Security and across engineering, IT, legal, and sales. This is a program-ownership role with the autonomy and accountability that implies. You will not have a senior compliance function above you to defer to; you are that function. In your first year, success looks like a complete and defensible evidence base with clean audit outcomes, a repeatable way to answer customer security diligence, and a risk register that leadership actually uses.

What You'll Do
  • Own our SOC 2 Type II and ISO 27001 programs, and future frameworks as we take them on, including scope, evidence, control operation, and the relationship with our external auditors.
  • Own and complete the control evidence base in our compliance automation platform, moving controls from partially substantiated to audit-ready and keeping them there.
  • Lead security diligence for enterprise and regulated customers: security questionnaires, audit responses, right-to-audit requests, and the recurring reporting these customers require.
  • Own the risk register and mature risk management from a security-team activity into a recorded, enterprise-aligned program.
  • Coordinate the compliance obligations that come with customer contracts, including data protection, breach-notification timelines, and vendor and subprocessor assessments, in partnership with legal.
  • Assess and stand up new certifications as the customer pipeline requires them.
  • Partner with engineering and IT to make evidence collection a byproduct of how systems already run, rather than a manual scramble before each audit.
What You'll Bring
  • 7+ years in governance, risk, and compliance, ideally including time at a high-growth startup.
  • Demonstrated ownership of SOC 2 and ISO 27001 programs, including running audits end to end with external auditors.
  • Experience fronting security diligence for enterprise or regulated customers. You have sat across from a customer's auditors or security reviewers and held your own.
  • Working fluency with compliance automation platforms (such as Vanta or equivalent) and with turning tooling into genuinely audit-ready evidence, not just dashboards.
  • A strong grasp of security controls and how they operate in a cloud and SaaS environment, enough to work credibly with engineers rather than only collecting their attestations.
  • The judgment and communication to run a program independently, coordinate across functions, and be trusted as the single owner of compliance.
Nice to Have
  • Experience with regulated-customer contractual security obligations: data protection agreements, breach notification, and right-to-audit provisions.
  • Exposure to newer or higher-bar frameworks (for example FedRAMP) and a sense of what standing them up would take.
  • Experience building a compliance function or team, since this role can grow into one as the company scales.
  • Familiarity with cloud infrastructure or AI or ML platforms.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cloud Security Engineer
Senior Cloud Security Engineer

Anyscale • San Francisco (CA)

On-site
USD 180,000 - 250,000
Enterprise Security Compliance & Audit Lead
Enterprise Security Compliance & Audit Lead

Anyscale • San Francisco (CA)

On-site
USD 180,000 - 240,000
Senior Product Security Engineer
Senior Product Security Engineer

Anyscale • San Francisco (CA)

On-site
USD 150,000 - 210,000
GRC Engineer
GRC Engineer

Antithesis • Vienna (VA)

On-site
USD 110,000 - 170,000
Senior Security Assurance Lead - Global Compliance & Audit
Senior Security Assurance Lead - Global Compliance & Audit

United States Digital Space LLC • New York (NY)

On-site
USD 120,000 - 190,000
Medical, dental, and vision insurance
Mental health benefits
401(k) plan with company match
+2
Senior Security Assurance Analyst
Senior Security Assurance Analyst

United States Digital Space LLC • New York (NY)

On-site
USD 120,000 - 190,000
Medical, dental, and vision insurance
Mental health benefits
401(k) plan with company match
+2
Security & Compliance Operations Manager San Francisco
Security & Compliance Operations Manager San Francisco

Mintlify, Inc. • San Francisco (CA)

On-site
USD 160,000 - 220,000
Competitive compensation and equity
20 days paid time off
401k
+5
Principal Security GRC Analyst
Principal Security GRC Analyst

Rescale • United States

Remote
USD 150,000 - 230,000
Compliance Operations Lead
Compliance Operations Lead

GovSignals • New York (NY)

On-site
USD 140,000 - 190,000
100% employer-paid medical, vision, and dental
Unlimited PTO
Equity in a fast-growing startup
IT & Security Operations Manager
IT & Security Operations Manager

Clearstory Technologies, Inc. • Walnut Creek (CA)

On-site
USD 80,000 - 120,000
Competitive salary and equity ownership
Comprehensive health, dental, and vision coverage
401(k) plan
+3