Group Security & Compliance Manager ($60,000/year USD), Sparkrock

Ionic Partners, LLC

United States

Remote

USD 140,000 - 210,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

100% remote and global
Stipend for home office
Flexible work hours
Growth and feedback culture
Access to cutting-edge tools

Job summary

Sparkrock is seeking a Group Security & Compliance Manager to own the customer trust and compliance across its growing portfolio in a 100% remote, global environment.

You will drive SOC 2 Type II, AI compliance, and build a customer-facing trust portal while coordinating audits across multiple portfolio companies and reporting to executive leadership.

Qualifications

  • 6+ years in security GRC, customer trust, or SaaS compliance.
  • Excellent spoken and written English; able to engage enterprise customers.
  • SOC 2 audit experience as a primary point of contact (Type II preferred).
  • Working understanding of cloud security concepts.
  • Awareness of AI compliance landscape and willingness to own it.

Responsibilities

  • Lead customer security reviews, RFPs, RFIs, and questionnaires to keep deals moving.
  • Stand up and maintain a customer-facing trust portal with AI/ML section.
  • Own SOC 2 Type II program management across portfolio companies and audits.
  • Author and maintain security policies, DPAs, and incident templates.
  • Own AI compliance including AI use disclosures and incident communications.
  • Run third-party vendor security reviews and renewals.
  • Develop internal security awareness training and customer onboarding.
  • Coordinate customer-facing incident communications with legal and engineering.

Skills

Security GRC
SOC 2 Type II
Cloud security
AI compliance
Stakeholder communication

Tools

Vanta
Drata
SafeBase

Job description

Are you a security and compliance leader who thrives on customer trust? Do you want to work for a best-in‑class, 100% remote organization with the brightest talent from around the world? If so, then keep reading…

At Sparkrock, we help social benefit organizations, such as nonprofits, school boards, and government agencies, reach their full potential through technology. Every day, over 150,000 people use our ERP and product platforms to work more efficiently, freeing up time and resources to focus on the good they want to achieve.

As our Group Security & Compliance Manager, you will own the entire customer‑trust and compliance function across a growing private‑equity portfolio, not one slice of it at one company. Every enterprise deal that hinges on security passes through you, and you get to build the program from the trust portal up rather than inherit someone else’s mess.

Unlike most GRC managers who sit inside a single company running one SOC 2, this role spans multiple portfolio companies on different clouds, and it owns the AI trust story as a first‑class part of the job. You’ll drive SOC 2 Type II audits, stand up the customer‑facing trust portal, and own AI compliance as the frameworks are still settling, representing the group directly in every customer security review.

If you thrive at the intersection of broad ownership, direct influence on revenue, and building something before the playbook is written, this role is for you.

Responsibilities
  • Lead customer security reviews, RFPs, RFIs, and questionnaires, turning around accurate, complete responses fast enough to keep deals moving
  • Stand up and maintain a customer-facing trust portal (SafeBase / Vanta / Drata or equivalent), including a dedicated AI/ML section
  • Own SOC 2 Type II program management, driving audits across portfolio companies (including Sparkrock’s Type II conversion and CXT scoping), coordinating evidence with the Senior Group Security Engineer, and managing auditor relationships
  • Author and maintain security policies and documentation, including DPAs, sub-processor lists, and incident-communication templates
  • Own AI compliance and trust, including AI questionnaire responses, AI sub-processor management, framework tracking (EU AI Act, ISO 42001, NIST AI RMF), AI use disclosure, AI acceptable-use policy, and AI incident-comms playbooks
  • Run third-party vendor security reviews and renewals
  • Build and deliver internal security awareness training, and onboard customers through the required security setup
  • Draft and coordinate customer-facing incident communications, including breach/incident notifications with legal and engineering
Requirements
  • 6+ years in security GRC, customer trust, or SaaS compliance.
  • Excellent spoken and written English. Articulate, polished, and credible in live calls with enterprise customers and third parties — this person represents the group externally.
  • SOC 2 audit experience as a primary point of contact (Type II strongly preferred).
  • Working understanding of cloud security concepts — able to read and translate technical findings, not produce them.
  • Awareness of the AI compliance landscape and willingness to own it.
Nice to have
  • CISSP / CISA / CIPP/E; Vanta / Drata / SafeBase experience.
  • PE-backed or multi-portfolio background.
  • ISO 42001 / NIST AI RMF familiarity; EU AI Act awareness.
Benefits
  • We are 100% remote and global. Live your best life wherever that may be, and never lose out on career opportunities because of it.
  • Flexible work hours. We work asynchronously and don’t care when you’re online, just that you deliver great results and are there for our customers.
  • We are dedicated to your growth with consistent and meaningful feedback, support in achieving your personal career goals, and access to leading-edge tools, playbooks and technology to amplify your experience.
  • Introductions to thought leaders in the space and webinars on cutting edge tech hot topics.
  • Stipend to help set up your ideal home office
  • Focus on culture: coffee chats, happy hours, cooking classes, book clubs, and more!

We strive to build a team that reflects the diversity of the community we work in and encourage applications from traditionally underrepresented groups such as women, visible minorities, Indigenous peoples, people identifying as LGBTQ2SI, veterans, and people with disabilities.

All open roles are for existing vacancies unless otherwise communicated to the candidate. We are committed to keeping candidates informed throughout the process and will notify all interviewed applicants of our hiring decision within 45 days of their interview. Sparkrock retains all job postings and related recruitment information for a minimum of three years.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Engineer, GRC San Francisco or Remote (US) $185,000 – $230,000
Security Engineer, GRC San Francisco or Remote (US) $185,000 – $230,000

Pazau, Inc. • San Francisco (CA)

Remote
USD 185,000 - 230,000
Equity in Pazau
4 weeks paid time off
16 weeks parental leave
+2
GRC Manager
GRC Manager

G2 Crowd, Inc. • Chicago (IL)

On-site
USD 120,000 - 131,000
Flexible work
Parental leave
Unlimited PTO
Information Security Lead
Information Security Lead

Secfix • United States

On-site
USD 180,000 - 240,000
Remote work: 100% remote
Equity: generous equity package
Mentorship from top VCs
+6
GRC Lead
GRC Lead

Hightouch • United States

Remote
USD 160,000 - 230,000
Equity compensation
GRC Manager
GRC Manager

Valence • United States

On-site
USD 130,000 - 190,000
WFH stipend
Phone stipend
Workspace support
Senior GRC Specialist
Senior GRC Specialist

Fireworks AI • United States

On-site
USD 110,000 - 150,000
Director of Governance, Risk & Compliance
Director of Governance, Risk & Compliance

Jobgether SRL • United States

Remote
USD 140,000 - 210,000
401(k) match
Health insurance (employee)
Paid time off 3 weeks
+3
Senior Manager, GRC Engineering
Senior Manager, GRC Engineering

Workstreet, Inc. • United States

On-site
USD 110,000 - 150,000
Career Development
Technical Training
Competitive Compensation
+2
Manager, GRC Engineering
Manager, GRC Engineering

Workstreet • Northern (KY)

On-site
USD 150,000 - 190,000
Career Development
Role-Related Training
Competitive Compensation
+2
Lead Security Engineer
Lead Security Engineer

8090 Solutions Inc • Redwood City (CA)

On-site
USD 180,000 - 350,000