Security & Compliance Lead

Dipp AI Technologies

New York, Northern (NY, KY)

Hybrid

USD 180,000 - 260,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Dipp AI Technologies is seeking a seasonedSecurity Compliance Lead to own our security programme and drive critical certifications for regulated enterprise deployments. You will own audits, regulatory mapping, and liaison with auditors, CISOs, and customers to validate our secure architecture and controls.

You will lead cross-functional efforts to implement controls in code, coordinate vendor risk programs, and guide engineering on security-first design.

Qualifications

  • 8+ years in security, GRC, or compliance engineering with 3+ years in a leadership role.
  • Has led at least one SOC 2 Type II or ISO 27001 audit.
  • Experience with financial services, healthcare, or government procurement is a plus.

Responsibilities

  • Own the security programme: policies, controls, vulnerability management, incident response.
  • Drive SOC 2 Type II, ISO 27001, and subsequent certifications end to end.
  • Map product behaviour to regulatory regimes and keep mappings current.
  • Lead customer security reviews, questionnaires, and penetration-test coordination.
  • Collaborate with engineering to enforce controls in code, not just docs.
  • Own vendor risk, access reviews, and internal control cadence.

Skills

Security governance
Leadership
Audit experience
SOC 2
ISO 27001
Regulatory mapping
Communication

Education

BS/MS in CS/InfoSec/Law
Certs welcomed (CISSP/CISA/CISM)

Job description

Own Dipp AI's security posture and the compliance evidence enterprises demand before deployment.

Enterprises will not route consequential actions through a control plane they cannot verify. You will own the programme that makes Dipp AI verifiable: internal security, certification, customer assurance, and the regulatory mapping behind our claims.

That includes running SOC 2 and ISO 27001, preparing for HIPAA and sector-specific obligations, mapping product behaviour to the EU AI Act, and being the person in the room when a CISO tests our architecture.

You will also work inside the product, because most of our compliance story is enforced in code rather than in policy documents.

What you will do
  • Own the security programme: policies, controls, vulnerability management, and incident response.
  • Drive SOC 2 Type II, ISO 27001, and subsequent certifications end to end.
  • Map Orcher behaviour to regulatory regimes and keep the mapping accurate as the product changes.
  • Lead customer security reviews, questionnaires, and penetration-test coordination.
  • Work with engineering to enforce controls in code rather than in documentation.
  • Own vendor risk, access review, and the internal control cadence.
What we look for
  • Experience running security and compliance at a company selling into regulated enterprises.
  • Hands-on certification experience — you have carried an audit, not just observed one.
  • Technical depth sufficient to challenge an engineering design.
  • Knowledge of AI-specific regulatory developments, including the EU AI Act.
  • Excellent written communication for auditors, customers, and engineers.
  • Pragmatism about which controls matter at this stage.
Experience
  • 8+ years in security, GRC, or compliance engineering, with 3+ years in a leadership role.
  • Has taken an organisation through at least one successful SOC 2 Type II or ISO 27001 audit.
  • Experience with financial services, healthcare, or public-sector procurement is a strong plus.
Education
  • BS or MS in Computer Science, Information Security, Law, or a related field.
  • CISSP, CISA, CISM, or equivalent certification is welcome but not required.
Compensation and benefits
  • Equity with a standard four-year vest.
  • Full medical, dental, and vision coverage.
  • 401(k) with company contribution and a certification budget.
  • Annual conference and learning budget.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security & Compliance Leader: SOC 2 & ISO 27001 Expert
Security & Compliance Leader: SOC 2 & ISO 27001 Expert

Dipp AI Technologies • New York (NY), Northern (KY)

Hybrid
USD 180,000 - 260,000
Senior Manager, Security & IT Ops
Senior Manager, Security & IT Ops

Hazelcast • Northern (KY)

Hybrid
USD 120,000 - 160,000
Unlimited PTO
Medical/Dental/Vision Insurance
HSA/FSA
+3
Senior Manager, Security & IT Ops
Senior Manager, Security & IT Ops

Hazelcast • United States

Remote
USD 150,000 - 190,000
Unlimited PTO
Medical/Dental/Vision Insurance
HSA/FSA
+4
Director Information Security
Director Information Security

InterContinental Hotels Group • Atlanta (GA)

Hybrid
USD 180,000 - 240,000
Hybrid work model
Security Engineer
Security Engineer

Clera • San Francisco (CA)

On-site
USD 180,000 - 250,000
Medical, dental, vision coverage
401k
Visa sponsorship
+2
Security & Compliance Engineer
Security & Compliance Engineer

Varick Agents LTD. • San Francisco (CA)

On-site
USD 150,000 - 210,000
Meaningful equity
Real ownership
Flexible PTO
+2
VP – AI Security and Data Protection Governance and Controls
VP – AI Security and Data Protection Governance and Controls

Jobtailor • United States

On-site
USD 180,000 - 280,000
Senior Analyst, Digital Trust and Resilience
Senior Analyst, Digital Trust and Resilience

Crypto.com • Abbeyville (CO)

On-site
USD 90,000 - 140,000
Security & Trust Lead
Security & Trust Lead

Alex AI • San Francisco (CA)

On-site
USD 150,000 - 180,000
Healthcare
Vision insurance
Dental insurance
+5
Security Assurance & GRC Lead
Security Assurance & GRC Lead

Wispr Flow • Northern (KY), New York (NY)

Hybrid
USD 150,000 - 210,000