Security Compliance Manager USA

Sardine

Northern (KY)

Hybrid

USD 140,000 - 210,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Generous compensation
Remote-first culture
Health insurance
401(k) match
Home office stipend
MacBook Pro provided
Meal stipend
Learning stipend

Job summary

Sardine is seeking a Security Compliance Lead to own the GRC program end-to-end in a remote US setting. You will partner with engineering, IT, product, security, and legal teams to run audits and control assessments across SOC 2 Type II, PCI DSS, ISO 27001, GDPR/CCPA, and DORA, while driving FedRAMP efforts.

You will manage a Security Compliance Analyst, lead regulatory readiness, and continuously improve the evidence and control framework to support growth and customer trust.

Qualifications

  • 7+ years in security compliance, GRC, or audit.
  • Deep knowledge of PCI DSS, SOC 2, ISO 27001, GDPR/CCPA, DORA.
  • Technical and product fluency with security tech.
  • Excellent written and verbal communication, executive-ready docs.
  • Experience in fast-growing fintech/payments environments.
  • People leadership or readiness to lead a team.

Responsibilities

  • Own compliance planning and the program across SOC 2 Type II, PCI DSS, ISO 27001, GDPR/CCPA, and DORA.
  • Drive FedRAMP efforts, coordinate NIST SP 800-53 controls and assessments.
  • Interface with auditors, regulators, and stakeholders; partner with engineering, IT, product and legal.
  • Present objectives, scope, and results to senior management and board.
  • Own the control framework and security policy library.
  • Own the risk picture, risk register, and reporting cadence.
  • Manage customer assurance work with security questionnaires and attestations.
  • Lead evidence collection, scans, and process improvements from findings.
  • Build product and technical fluency to ground controls in Sardine's tech.
  • Look for automation opportunities and streamlined controls.
  • Produce executive-ready documentation and lead regulator meetings.
  • Develop and scale the team starting with a Security Compliance Analyst.

Job description

Who we are:

Sardine is the leading agentic risk platform for fighting financial crime. Our integrated solution unifies data across risk teams to help organizations stop fraud in real time, prevent AI-driven attacks, and automate fraud and AML operations. Sardine’s platform is strengthened by one of the fastest-growing fraud consortiums in the market, spanning more than 6 billion profiled devices, 800 million consumers, and 3 million businesses worldwide. Leading companies including FIS, GoDaddy, Intuit, Edward Jones, ZoomInfo, and Checkout.com rely on Sardine to secure and grow trust in their products.

Our culture:

  • We have hubs in the Bay Area, NYC, Austin, Toronto, and São Paulo. However, we maintain a remote-first work culture. #WorkFromAnywhere

  • We hire talented, self-motivated individuals with extreme ownership and high growth orientation.

  • We value performance and not hours worked. We believe you shouldn't have to miss your family dinner, your kid's school play, friends get-together, or doctor's appointments for the sake of adhering to an arbitrary work schedule.

Location:
  • Remote - US

  • From Home / Beach / Mountain / Cafe / Anywhere!

  • We are a remote-first company with a globally distributed team. You can find your productive zone and work from there.

About the role

As Security Compliance Lead, you own Sardine’s security compliance and GRC function end-to-end and reduce risk to our environment through effective communication, partnership, and program ownership. You are the primary point of contact for auditors, regulators, and industry stakeholders, and you partner with engineering, IT, product, security, and legal teams to run successful compliance and review exercises across multiple frameworks.

This is a senior, hands-on ownership role. You set how the compliance program runs rather than executing a plan handed to you, and you are accountable for keeping Sardine continuously audit- and customer-ready. You also lead and develop the team, with a Security Compliance Analyst reporting to you and room to grow the function as Sardine scales.

What you’ll do
  • Own compliance planning and the compliance program across SOC 2 Type II, PCI DSS (Level 1 Service Provider), ISO 27001, GDPR, CCPA, and DORA — responsible for the program’s design and direction, not only its execution.

  • Drive Sardine's FedRAMP effort by working toward authorization, coordinating NIST SP 800-53 control implementation, 3PAO assessment, and continuous monitoring across engineering and IT.

  • Serve as the primary interface to auditors, regulators, and industry stakeholders, and partner with internal engineering, IT, product, security, and legal teams to drive reviews to clean outcomes.

  • Present objectives, scope, and results to senior management and the board (via the CISO), clearly articulating the business impact of control gaps in a highly professional and proficient manner.

  • Own the control framework — including rationalizing overlapping controls across standards into a coherent, evidence-efficient set — and the security policy and standards library.

  • Own the risk picture — the risk register, risk quantification, and reporting cadence — and validate that actions taken to address risks are appropriate and reported accurately.

  • Own the customer assurance and trust program — security questionnaires, attestations, and trust artifacts — so security review does not block deals.

  • Manage evidence and drive improvement — coordinate the assimilation of evidence, scans, and artifacts, and lead process improvements in response to findings from regulators, internal and external quality reviews, and maturity assessments.

  • Build product and technical fluency — understand Sardine’s platform and architecture well enough to ground control design and risk decisions in how the technology actually works, and to engage engineering and product as a peer.

  • Look for creative, alternative solutions that promote consistency and unlock streamlining and automation opportunities.

  • Produce executive-ready work — high-quality documentation and presentations, and well-run meetings with regulators and internal stakeholders where you set the objectives, plan, and content.

  • Lead and develop the team — starting with a Security Compliance Analyst — setting priorities, reviewing work, mentoring, and scaling the function as obligations grow.

What we’re looking for
  • 7+ years in security compliance, GRC, or audit, including end-to-end ownership of audit or certification programs (SOC 2, PCI DSS, and/or ISO 27001).

  • Deep knowledge of security and privacy frameworks — PCI DSS, SOC 2, ISO 27001, GDPR/CCPA, and DORA; familiarity with control frameworks such as NIST CSF and CIS.

  • Technical and product comfort — able to build fluency in a technical product (e.g., device intelligence, behavioral biometrics, transaction monitoring) and hold your own with engineering and product teams.

  • Excellent communication — strong written and verbal skills, executive-ready documentation, and credible presence with auditors, regulators, and leadership.

  • Fast-paced, high-growth experience — fintech or payments strongly preferred given Sardine’s PCI Level 1 service provider obligations.

  • Able to work as a leader, a partner, and an individual contributor as the situation calls for, and to travel as needed.

  • People leadership — experience leading, mentoring, or managing others, or clear readiness to step into managing a direct report.

Bonus points
  • Direct experience running a PCI DSS Level 1 service provider program.

  • Operational resilience — hands-on exposure to DORA requirements.

  • Tooling — familiarity with GRC and security tooling (compliance automation platforms such as Vanta; HRIS such as Rippling) and with macOS environments.

Benefits we offer:

  • Generous compensation in cash and equity

  • Early exercise for all options, including pre-vested

  • Work from anywhere: Remote-first Culture

  • Flexible paid time off and Year-end break

  • Health insurance, dental, and vision coverage for employees and dependents - US and Canada specific

  • 4% matching in 401k / RRSP - US and Canada specific

  • MacBook Pro delivered to your door

  • One-time stipend to set up a home office — desk, chair, screen, etc.

  • Monthly meal stipend

  • Monthly social meet-up stipend

  • Annual health and wellness stipend

  • Annual Learning stipend

Join a fast-growing company with world-class professionals from around the world. If you are seeking a meaningful career, you found the right place, and we would love to hear from you.

To learn more about how we process your personal information and your rights in regards to your personal information as an applicant and Sardine employee, please visit our Applicant and Worker Privacy Notice.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Compliance Manager
Security Compliance Manager

Mixpeek • Northern (KY)

Hybrid
USD 140,000 - 220,000
Remote-first culture
MacBook Pro delivered to your door
Home office stipend
Technical Program Manager
Technical Program Manager

Mixpeek • United States

Hybrid
USD 140,000 - 190,000
Remote-first culture
Work from anywhere
401k matching (US/Canada)
+4
Strategic Account Manager
Strategic Account Manager

Sardine • United States

Remote
USD 150,000 - 180,000
Generous compensation in cash and equity
Early exercise for all options
Flexible paid time off
+5
Solutions Architect Lead - US/CAN, West Coast
Solutions Architect Lead - US/CAN, West Coast

JobCubby • Northern (KY)

Hybrid
BRL 780,000 - 1,092,000
Generous compensation in cash and equi
Early exercise for all options
Work from anywhere: Remote-first
+9
Head of Cloud and Banking Partnerships
Head of Cloud and Banking Partnerships

Sardine • United States

On-site
USD 210,000 - 250,000
Generous compensation in cash and equity
Flexible paid time off
Work from anywhere
+6
Support Engineering Lead
Support Engineering Lead

Sardine • United States

Remote
USD 140,000 - 200,000
Cash and equity
Remote-first culture
Flexible PTO
+7
Solutions Architect, Integrations (AUS)
Solutions Architect, Integrations (AUS)

Sardine • Austin (TX), New York (NY), San Francisco (CA)

Hybrid
USD 120,000 - 180,000
Remote-first culture
Health insurance
401(k) matching (US)
Senior Data Scientist
Senior Data Scientist

Triwill Group • United States

On-site
USD 140,000 - 190,000
Remote-first culture
Work from anywhere
Health insurance
+7
Account Executive, Mid-Market
Account Executive, Mid-Market

Sardine • Northern (KY)

Hybrid
USD 260,000 - 320,000
Remote-first culture
Equity upside potential
Flexible paid time off
+3
Data Engineer - Onboarding
Data Engineer - Onboarding

Sardine • San Francisco (CA)

Hybrid
USD 180,000 - 260,000
Generous compensation
Remote-first culture
401k/RRSP matching
+6