Security Compliance Analyst

LangChain

San Francisco (CA)

On-site

USD 153,000 - 215,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Medical, dental, vision coverage
Flexible vacation
401(k) plan
Meals on in-office days (US)

Job summary

LangChain is seeking a Privacy & Security Compliance Lead to build and scale our privacy program. You’ll own SOC 2, ISO 27001, ISO 27701, and privacy frameworks across cloud environments, deployments, and geographies. This in-person role is based in San Francisco or New York.

Work with Engineering, Legal, and product teams to embed controls, drive audits, and secure customer trust. 5+ years in privacy or security compliance, DPAs/BAAs, and strong writing are essential.

Qualifications

  • 5+ years in privacy, GRC, or security compliance.
  • Experience with GDPR, HIPAA, CCPA, ISO 27001/27701, SOC 2.
  • Experience with DPAs and BAAs in commercial contexts.
  • Technical ability to read code and validate data flows.
  • Strong writing to produce policies and questionnaires.

Responsibilities

  • Build and automate our compliance operations layer with evidence pipelines.
  • Collaborate with Engineering to embed privacy controls into products.
  • Maintain and scale SOC 2, ISO 27001, ISO 27701, HIPAA, GDPR, CCPA programs.
  • Partner with Legal on DPAs/BAAs and vendor terms.
  • Monitor contractual obligations across signed agreements.
  • Contribute to customer trust materials and security questionnaires.
  • Support vendor privacy risk assessments during onboarding and renewals.

Skills

Privacy & GRC
Security compliance
DPAs & BAAs management
Technical fluency
Strong writing

Tools

Python

Job description

About Us

At LangChain, our mission is to make intelligent agents ubiquitous. We build the foundation for agent engineering in the real world, helping developers move from prototypes to production‑ready AI agents that teams can rely on. We began as widely adopted open‑source tools and have grown to also offer a platform for building, evaluating, deploying, and operating agents at scale.

With $125M raised at Series B from IVP, Sequoia, Benchmark, CapitalG, and Sapphire Ventures, we’re at a stage where we’re continuing to develop new products, growth is accelerating, and all team members have meaningful impact on what we build and how we work together. LangChain is a place where your contributions can shape how this technology shows up in the real world.

Today, our platform includes LangSmith (Observability, Evaluation, Deployment, Fleet, and Sandboxes), our open source frameworks (LangChain, LangGraph, and Deep Agents), and the newly launched LangSmith Engine for autonomous agent improvement. We have 100M+ monthly open source downloads, 6,000+ active LangSmith customers, and 5 of the Fortune 10 use LangSmith in production (+ 35% of the Fortune 500 overall), including teams at Klarna, Clay, Coinbase, Workday, Lyft, Cloudflare, Harvey, Rippling, Vanta, LinkedIn, Monday.com, Nvidia, and Bridgewater.

About The Team

The Security team at LangChain treats compliance as a business enabler, not a checkbox. We move fast, build customer trust across regulated industries, and are actively rethinking what modern security compliance looks like at an AI‑native company. We are a small team that operates nothing like a traditional compliance function, still deep in the work of building controls, implementing frameworks, and pushing the business forward on security.

About The Role

You’ll play a central role in building and scaling LangChain’s privacy compliance program, developing the processes, technical controls, and automation that back our commitments to customers, partners, and regulators. You’ll maintain and grow our SOC 2, ISO 27001, and privacy programs while taking primary ownership of our privacy framework across multiple cloud environments, deployment models, and geographies. We are looking to hire in‑person in SF or NY.

What you’ll do
  • Build and automate our compliance operations layer, including evidence pipelines, control monitoring, and agentic systems for always‑on visibility into our compliance posture.
  • Work directly with Engineering to embed security and privacy controls into our products, including deletion pipelines, PII detection, access audit logging, and fine‑grained data access controls.
  • Maintain and scale our certification and audit programs across SOC 2, ISO 27001, ISO 27701, ISO 42001, HIPAA, GDPR, CCPA, EU‑US Data Privacy Framework, and others. Drive audit readiness, identify overlapping requirements, and reuse evidence across frameworks to continuously strengthen our security story.
  • Partner with Legal on security and privacy contract execution, covering DPAs, BAAs, security addenda, and vendor terms. Build the templates, playbooks, and review processes that enable fast, reliable execution in regulated verticals and unblock enterprise sales.
  • Monitor adherence to security and privacy contractual obligations across all signed agreements, building the operational workflows and tracking mechanisms to stay on top of commitments as our customer base grows.
  • Contribute to LangChain’s customer trust program — security questionnaire responses, due‑diligence reviews, and the trust documentation and whitepapers that give regulated‑industry customers confidence in our security posture.
  • Support vendor privacy risk assessments during onboarding and renewals.
What you’ll bring
  • 5+ years in privacy, GRC, or security compliance, ideally with time at a Big 4 or advisory firm, or in‑house at a high‑growth tech company.
  • Hands‑on operational experience with privacy regulations and compliance frameworks (GDPR, HIPAA, CCPA, ISO 27001, ISO 27701, SOC 2), including controls mapping, audit support, and day‑to‑day program operations.
  • Experience with DPAs and BAAs: reviewing, negotiating, or operationalizing them in a commercial context.
  • Technical fluency: comfortable reading code, understanding data flows, validating that controls work as described, and collaborating directly with engineering teams.
  • Exceptional writer. You’ll draft policies, respond to security questionnaires, and translate complex requirements into clear guidance for audiences ranging from engineers to executives.
Nice to have
  • Background in a regulated industry (healthcare, finance, government) or working directly with regulated‑industry customers.
  • Experience working across multi‑cloud deployment environments.
  • Ability to write scripts or code (Python is a strong plus) to automate compliance checks, privacy workflows, or build integrations between security and compliance tooling.
  • Relevant certifications such as CIPM, CIPP/E, CIPP/US, CISA, CISSP, ISO 27001 Lead Implementer, or ISO 27701 Lead Implementer.
  • Annual salary range: $153,000- $215,000 USD
Compensation Philosophy

We offer competitive compensation that includes base salary, variable compensation for relevant roles, meaningful equity, benefits, and perks. Actual compensation and offerings will vary based on role, level, and location. Team members in the EU, UK, and APAC receive locally competitive benefits aligned with regional norms and regulations.

Benefits

Benefits include medical, dental, and vision coverage, flexible vacation, a 401(k) plan, meals on in‑office days in the US and more.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer - Detection & Response
Security Engineer - Detection & Response

LangChain • San Francisco (CA)

On-site
USD 180,000 - 240,000
Security Engineer - Detection & Response
Security Engineer - Detection & Response

LangChain, Inc. • San Francisco (CA), Northern (KY)

Hybrid
USD 180,000 - 240,000
Medical, dental, and vision coverage
Flexible vacation
401(k) plan
+1
Security Engineer - Detection & Response
Security Engineer - Detection & Response

Doist • San Francisco (CA)

On-site
USD 180,000 - 240,000
Medical, dental, and vision coverage
Equity and 401(k)
People Operations Specialist
People Operations Specialist

LangChain • San Francisco (CA)

On-site
USD 100,000 - 110,000
Medical, dental, vision coverage
401(k)
In-office meals
People Operations Specialist
People Operations Specialist

Neura Market • San Francisco (CA), Northern (KY)

Hybrid
USD 100,000 - 110,000
Medical, dental, and vision coverage
Flexible vacation
401(k) plan
+1
Deployed Engineer (Early Career-NYC)
Deployed Engineer (Early Career-NYC)

LangChain • New York (NY)

On-site
USD 155,000 - 165,000
Medical benefits
401(k) plan
Office meals
+1
Solutions Engineer (Texas)
Solutions Engineer (Texas)

LangChain • Dallas (TX)

On-site
USD 200,000 - 250,000
Medical, dental, and vision coverage
401(k) plan
Flexible vacation
Software Engineering Manager, AI Observability & Evals Platform
Software Engineering Manager, AI Observability & Evals Platform

LangChain • Cambridge (MA)

On-site
USD 200,000 - 240,000
Medical, dental, and vision coverage
401(k) plan
Flexible vacation
+1
Deployed Engineer (Early Career- SF/NY)
Deployed Engineer (Early Career- SF/NY)

LangChain, Inc. • San Francisco (CA)

On-site
USD 155,000 - 165,000
Medical benefits
401(k) plan
Meals on in-office days
Software Engineering Manager, AI Observability & Evals Platform
Software Engineering Manager, AI Observability & Evals Platform

LangChain, Inc. • Boston (MA), Northern (KY)

Hybrid
USD 200,000 - 240,000
Medical, Dental & Vision
Flexible vacation
401(k) plan
+1