Remote Security Compliance Leader GRC & Audit

Sardine

Northern (KY)

Hybrid

USD 140,000 - 210,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Generous compensation
Remote-first culture
Health insurance
401(k) match
Home office stipend
MacBook Pro provided
Meal stipend
Learning stipend

Job summary

Sardine is seeking a Security Compliance Lead to own the GRC program end-to-end in a remote US setting. You will partner with engineering, IT, product, security, and legal teams to run audits and control assessments across SOC 2 Type II, PCI DSS, ISO 27001, GDPR/CCPA, and DORA, while driving FedRAMP efforts.

You will manage a Security Compliance Analyst, lead regulatory readiness, and continuously improve the evidence and control framework to support growth and customer trust.

Qualifications

  • 7+ years in security compliance, GRC, or audit.
  • Deep knowledge of PCI DSS, SOC 2, ISO 27001, GDPR/CCPA, DORA.
  • Technical and product fluency with security tech.
  • Excellent written and verbal communication, executive-ready docs.
  • Experience in fast-growing fintech/payments environments.
  • People leadership or readiness to lead a team.

Responsibilities

  • Own compliance planning and the program across SOC 2 Type II, PCI DSS, ISO 27001, GDPR/CCPA, and DORA.
  • Drive FedRAMP efforts, coordinate NIST SP 800-53 controls and assessments.
  • Interface with auditors, regulators, and stakeholders; partner with engineering, IT, product and legal.
  • Present objectives, scope, and results to senior management and board.
  • Own the control framework and security policy library.
  • Own the risk picture, risk register, and reporting cadence.
  • Manage customer assurance work with security questionnaires and attestations.
  • Lead evidence collection, scans, and process improvements from findings.
  • Build product and technical fluency to ground controls in Sardine's tech.
  • Look for automation opportunities and streamlined controls.
  • Produce executive-ready documentation and lead regulator meetings.
  • Develop and scale the team starting with a Security Compliance Analyst.

Job description

Sardine is seeking a Security Compliance Lead to own the GRC program end-to-end in a remote US setting. You will partner with engineering, IT, product, security, and legal teams to run audits and control assessments across SOC 2 Type II, PCI DSS, ISO 27001, GDPR/CCPA, and DORA, while driving FedRAMP efforts.

You will manage a Security Compliance Analyst, lead regulatory readiness, and continuously improve the evidence and control framework to support growth and customer trust.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Remote Security Compliance Lead (SOC 2, PCI)
Remote Security Compliance Lead (SOC 2, PCI)

Mixpeek • Northern (KY)

Hybrid
USD 140,000 - 220,000
Remote-first culture
MacBook Pro delivered to your door
Home office stipend
GRC Analyst - Cloud Security & Compliance
GRC Analyst - Cloud Security & Compliance

United States Digital Space LLC • United States

Remote
USD 134,000 - 202,000
Equity
Healthcare
Mentorship events
+2
Remote Security GRC Analyst: Risk & Compliance Lead
Remote Security GRC Analyst: Risk & Compliance Lead

NEPSE Trading • United States

On-site
USD 70,000 - 77,000
Health insurance
401(k) plan with company match
Pension plan
+1
Security & Compliance Lead — Build Our Foundational GRC
Security & Compliance Lead — Build Our Foundational GRC

Litehouse • Northern (KY)

Hybrid
USD 120,000 - 190,000
Remote-first
Professional development
Flexible PTO
+2
Remote Senior InfoSec GRC Analyst — ISO 27001 & SOC 2 Lead
Remote Senior InfoSec GRC Analyst — ISO 27001 & SOC 2 Lead

United States Digital Space LLC • United States

Remote
USD 127,000 - 205,000
Remote & Flexible
Annual kickoff and team meetups
Remote Security GRC Program Manager
Remote Security GRC Program Manager

United States Digital Space LLC • United States

Remote
USD 130,000 - 190,000
Security GRC Analyst: Remote-Ready, High-Impact Compliance
Security GRC Analyst: Remote-Ready, High-Impact Compliance

Whatnot • Los Angeles (CA)

Hybrid
USD 120,000 - 180,000
Holiday and time off
Health insurance
Work from home
+8
Remote Security & Compliance Leader (SOC 2 / ISO 27001)
Remote Security & Compliance Leader (SOC 2 / ISO 27001)

rater8, Inc. • United States

Remote
USD 145,000 - 185,000
Medical, dental, and vision benefits
Unlimited PTO after 60 days
401(k) with company match
+1
Senior GRC Program Lead - SOC 2, GDPR & Security
Senior GRC Program Lead - SOC 2, GDPR & Security

Tandem Inc. • Draper (UT)

Hybrid
USD 110,000 - 170,000
On-site gym
Flexible PTO
Redo perks: monthly ecommerce credit
+2
Remote GRC Security & Compliance Leader
Remote GRC Security & Compliance Leader

Avantdigitalnow • San Francisco (CA)

Remote
USD 120,000 - 150,000