Information Security Compliance Lead (ISO/SOC/CMMC/FedRAMP)

Matcha

Northern (KY)

Hybrid

USD 150,000 - 180,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Synack is seeking an Information Security Compliance Manager to lead ISO, SOC, CMMC, and FedRAMP compliance efforts in a US citizen-only role. You’ll automate SSP artifacts, manage POAMs, and advance AI-enabled security operations across Synack’s platform.

Collaboration with product, engineering, and operations is essential as we harden DevSecOps practices. You will own risk assessments of AI-based systems, align to NIST/CIS standards, and drive evidence collection and control-drift management.

Qualifications

  • 8+ years of IT security experience in strategy, risk, audit and compliance
  • Experience with Python, Terraform, and CI/CD pipelines, plus AI integration

Responsibilities

  • Automate generation of SSPs, including risk matrices and security control traceability
  • Develop and maintain automated POAMs
  • Contribute to automation and AI adoption within security ops
  • Own inventory and risk assessments of AI/agentic systems per NIST AI RMF and ISO 42001
  • Build and own automated evidence collection and control drift around security controls
  • Communicate security compliance issues to stakeholders and track remediation tasks
  • Codify controls into IaC guardrails, CNAPP policies, and CI/CD checks
  • Collaborate with PMs and engineers to ensure security policies are applied across Synack services and infrastructure
  • Coordinate with field teams for vendor security assessments and 3rd party risk assessments

Skills

Python
Terraform
CI/CD
AI integration
GRC tools
Datadog
Stackdriver
Azure Sentinel
SOAR
SIEM
CNAPP
DevSecOps
Governance & Compliance

Tools

Datadog
Stackdriver
Azure Sentinel
CI/CD tools
SOAR platforms

Job description

Synack is seeking an Information Security Compliance Manager to lead ISO, SOC, CMMC, and FedRAMP compliance efforts in a US citizen-only role. You’ll automate SSP artifacts, manage POAMs, and advance AI-enabled security operations across Synack’s platform.

Collaboration with product, engineering, and operations is essential as we harden DevSecOps practices. You will own risk assessments of AI-based systems, align to NIST/CIS standards, and drive evidence collection and control-drift management.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

InfoSec Compliance Lead: ISO/SOC/CMMC, FedRAMP & AI
InfoSec Compliance Lead: ISO/SOC/CMMC, FedRAMP & AI

Synack • San Mateo (CA)

On-site
USD 150,000 - 180,000
Manager, Information Security at Synack
Manager, Information Security at Synack

Matcha • Northern (KY)

Hybrid
USD 150,000 - 180,000
Manager, Information Security
Manager, Information Security

Synack • San Mateo (CA)

On-site
USD 150,000 - 180,000
Security & Systems Engineer — Compliance & Infra Lead
Security & Systems Engineer — Compliance & Infra Lead

SilencerCo, LLC • West Valley City (UT)

On-site
USD 120,000 - 180,000
Senior ISSO & Cybersecurity Compliance Leader
Senior ISSO & Cybersecurity Compliance Leader

AIS (Applied Information Sciences) • Washington

On-site
USD 120,000 - 181,000
Cybersecurity Compliance Specialist | NIST/ISO & Audits
Cybersecurity Compliance Specialist | NIST/ISO & Audits

ICEYE • Irvine (CA)

On-site
USD 65,000 - 85,000
Health coverage
Flexible PTO
Friendly environment
+1
Information Security Program Lead
Information Security Program Lead

MSA - The Safety Company • Cranberry Township

On-site
USD 120,000 - 180,000
Information Security Program Lead
Information Security Program Lead

MSA, The Safety Company • Cranberry Township

On-site
USD 120,000 - 180,000
Cybersecurity Program Lead — Incident Response & Risk
Cybersecurity Program Lead — Incident Response & Risk

Synopsys, Inc. • Exton (PA)

On-site
USD 160,000 - 210,000
Hybrid work
Competitive benefits
Compliance Engineering Lead - Automate & Certify Trust
Compliance Engineering Lead - Automate & Certify Trust

Socket • United States

On-site
USD 150,000 - 190,000
Equity program
Health benefits
Remote-first culture
+1