Compliance Program Lead: SOC 2, HIPAA & ISO 27001

Relay

Raleigh (NC)

On-site

USD 110,000 - 140,000

Full time

8 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

100% Paid Insurance: Health, Dental, V
Paid Time Off
401(k) Matching
Parental Leave
Wellness Perks and onsite fitness

Job summary

Relay, the Intelligent System of Action for the physical economy, is hiring a Compliance Manager to own our end-to-end certification program (SOC 2 Type II, HIPAA, ISO 27001:2022, PCI DSS) and to serve as the Drata expert, central to our governance program. You’ll manage auditors, evidence, controls, and workflows to keep certifications on schedule.

This ownership role requires collaborating with leaders across the company to drive policy lifecycle, control health, and vendor risk while

Qualifications

  • A degree in Computer Science, IT, or a security-related discipline; equivalent compliance certifications (CRISC, CGRC, GRCP, CISM, or CISA) will be considered in place of a formal degree.
  • 5+ years of experience in information security compliance, GRC, or audit roles, with at least 2 years directly managing certification programs.
  • Hands-on experience running SOC 2 Type II audits end-to-end, including auditor management, evidence collection, and remediation.
  • Working knowledge of HIPAA security requirements, ISO 27001:2022 (ISMS operation and surveillance/recertification audits), and PCI DSS.
  • Expert-level proficiency with Drata or a comparable GRC/compliance automation platform (Vanta, Secureframe, Hyperproof), including control mapping, monitoring, and auditor collaboration workflows.
  • Demonstrated experience managing external audit firms through complete audit cycles.
  • Experience building and running internal audit and control testing programs.
  • Experience owning policy management and third-party vendor risk programs.
  • Exceptional interpersonal and communication skills: translate framework requirements into plain language for any department leader, drive accountability without friction.
  • Strong organizational and project management skills—manage multiple concurrent audit timelines without missing deadlines.

Responsibilities

  • Own Relay's compliance certification portfolio — SOC 2 Type II + HIPAA, ISO 27001:2022, and PCI DSS — including the master schedule, audit readiness, and on-time completion of engagements.
  • Serve as Relay's Drata SME: administer the platform, maintain mapping and monitoring, manage evidence workflows, and drive adoption across control owners.
  • Manage external auditors directly from within Drata — coordinate audit windows, fieldwork, evidence requests, findings, and remediation through to report issuance.
  • Run the internal audit program: plan and execute control testing, document results, track findings and remediation, and prepare the organization for external audits.
  • Own control management across all frameworks — maintain the unified library, assign owners, monitor health, and remediate gaps.
  • Own the policy management lifecycle — draft, review, update, route for approval, publish, and track attestations.
  • Own third-party vendor risk management: security and compliance reviews for new vendors, reassessments, documentation, and risk tracking.
  • Partner with department leaders to assign responsibilities, communicate requirements clearly, and hold owners to deadlines with firmness.
  • Support customer trust activities, including security questionnaires and customer audit requests, and maintain trust center documentation.
  • Report posture, audit status, risks, and metrics to security leadership and steering committees.

Skills

Compliance management
Auditing
Project management
Communication
Stakeholder collaboration

Education

Bachelor's degree in Computer Science / IT / security
CRISC CGRC GRCP CISM CISA or equivalent

Tools

Drata
Vanta
Secureframe
Hyperproof

Job description

Relay, the Intelligent System of Action for the physical economy, is hiring a Compliance Manager to own our end-to-end certification program (SOC 2 Type II, HIPAA, ISO 27001:2022, PCI DSS) and to serve as the Drata expert, central to our governance program. You’ll manage auditors, evidence, controls, and workflows to keep certifications on schedule.

This ownership role requires collaborating with leaders across the company to drive policy lifecycle, control health, and vendor risk while

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Compliance Program Lead: SOC 2, HIPAA & ISO 27001
Compliance Program Lead: SOC 2, HIPAA & ISO 27001

Relaypro • Raleigh (NC)

On-site
USD 110,000 - 150,000
Health, dental, and vision insurance
401(k) with company match
Generous PTO
+1
Compliance & Audit Manager
Compliance & Audit Manager

Asprcmsolutions • Dallas (TX), Northern (KY)

Hybrid
USD 110,000 - 160,000
Senior Compliance & Audit Lead — SOC 2, ISO 27001, HIPAA
Senior Compliance & Audit Lead — SOC 2, ISO 27001, HIPAA

Asprcmsolutions • Dallas (TX), Northern (KY)

Hybrid
USD 110,000 - 160,000
Security & Compliance Leader for HIPAA & SOC 2
Security & Compliance Leader for HIPAA & SOC 2

Embedded Shishya • United States

Remote
USD 190,000 - 220,000
Unlimited PTO
Health coverage
Equity options
+3
Compliance Engineering Lead - Automate & Certify Trust
Compliance Engineering Lead - Automate & Certify Trust

Socket • United States

On-site
USD 150,000 - 190,000
Equity program
Health benefits
Remote-first culture
+1
Security & Compliance Leader (HIPAA, SOC 2, HITRUST) — Equity
Security & Compliance Leader (HIPAA, SOC 2, HITRUST) — Equity

Collectly, Inc. • Northern (KY)

Hybrid
USD 190,000 - 220,000
Unlimited PTO
Health coverage
Equity opportunities
+3
Compliance Manager
Compliance Manager

Relaypro • Raleigh (NC)

On-site
USD 110,000 - 150,000
Health, dental, and vision insurance
401(k) with company match
Generous PTO
+1
Security & Compliance Lead: HIPAA & SOC 2 Expert
Security & Compliance Lead: HIPAA & SOC 2 Expert

Prompt • United States

Hybrid
USD 180,000 - 280,000
Competitive salaries
Remote/hybrid environment
Equity potential
+10
Remote Compliance Engineering Lead — Automate SOC 2 & ISO 27001
Remote Compliance Engineering Lead — Automate SOC 2 & ISO 27001

Socket • United States

On-site
USD 180,000 - 270,000
Market competitive salary bands
Meaningful equity program
Comprehensive health benefits for you/
+3
Compliance Manager
Compliance Manager

Relay • Raleigh (NC)

On-site
USD 110,000 - 140,000
100% Paid Insurance: Health, Dental, V
Paid Time Off
401(k) Matching
+2