Senior Manager, Compliance & Audit

Mpathic

Northern (KY)

On-site

USD 140,000 - 180,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

mpathic is seeking a Senior Manager, Compliance & Audit to own and scale the compliance programs supporting our technology and customers. This hands-on role spans regulatory requirements, technical controls, external audits, and internal teams to build a unified program across SOC 1, SOC 2, ISO 27001, ISO 42001, and Part 11.

You will translate requirements into practical controls, automate evidence where possible, and ensure systems can stand up to auditors, customers, and regulated partners.

Qualifications

  • 7+ years in IT compliance, GRC, audit, or computerized systems validation.
  • Hands-on experience applying Part 11 and GxP data integrity requirements to software/SaaS systems.
  • Experience leading SOC 1, SOC 2, ISO/IEC 27001 audits or certifications.
  • Familiarity with AI governance frameworks (NIST AI RMF, EU AI Act) is a plus.

Responsibilities

  • Plan and run the annual audit and certification cycle across SOC 1/2, ISO/IEC 27001, ISO/IEC 42001 and Part 11 readiness.
  • Own Part 11 compliance for systems handling regulated records and maintain risk-based validation.
  • Maintain a unified control framework to avoid duplicating evidence across audits.
  • Lead internal audits, track nonconformities and CAPAs through closure.
  • Collaborate with engineering, delivery, operations, and HR to embed controls into product development.
  • Represent the company with external auditors and certification bodies.
  • Develop policies and training related to Part 11 and GxP.

Skills

IT compliance
Audit management
FDA 21 CFR Part 11
GxP data integrity
ISO/IEC 27001
SOC 1 SOC 2
Cloud configurations review

Tools

GRC platform

Job description

About mpathic

mpathic is building the future of trustworthy AI. Grounded in behavioral science and human-centered design, we provide the infrastructure for building AI systems that are safe, aligned, and emotionally intelligent.

Building on our work in areas like RL gyms, red teaming, benchmarking, and human data, we are creating the foundation for training, probing, and measuring advanced AI systems reliably, auditably, and at scale.

Position Overview

mpathic is seeking a Senior Manager, Compliance & Audit to own and scale the compliance and audit programs that support our technology, customers, and continued growth.

This is a hands‑on role for someone who can move comfortably between regulatory requirements, technical systems, external auditors, and internal teams. You’ll lead our audit and certification lifecycle across SOC 1, SOC 2 Type II, ISO/IEC 27001, ISO/IEC 42001, and FDA 21 CFR Part 11, while building a unified compliance program that minimizes duplicate work and makes compliance part of how we operate—not simply something we prepare for at audit time.

You’ll partner closely with engineering, security, product, delivery, and operations to translate requirements into practical controls, automate evidence wherever possible, and ensure our systems and processes can stand up to scrutiny from auditors, customers, and regulated‑industry partners.

About You
  • Proven Experience: 7+ years in IT compliance, GRC, audit, or computerized systems validation, including direct ownership of external audits from scoping through final report or certification.
  • FDA 21 CFR Part 11 Depth: Hands‑on experience applying Part 11 and GxP data integrity requirements to software or SaaS systems, including audit trails, electronic signatures, access controls, record retention, and ALCOA+ principles. Familiarity with FDA Computer Software Assurance (CSA) guidance, GAMP 5, and EU Annex 11 is a strong plus.
  • Validation Experience: Experience writing or directing validation deliverables such as validation plans, requirements traceability, risk‑based test evidence (IQ/OQ/PQ or CSA‑style), and validation summary reports, as well as supporting customer or sponsor audits of validated systems.
  • Multi‑Framework Audit Experience: Experience leading or supporting SOC 1 and SOC 2 Type II examinations and ISO/IEC 27001 certification or surveillance audits. Experience with ISO/IEC 42001 or other AI governance frameworks, including NIST AI RMF or the EU AI Act, is a strong plus.
  • Technical Fluency: Comfortable reviewing cloud configurations across AWS, GCP, or Azure; IAM policies; CI/CD and change management records; logging; and infrastructure as code well enough to evaluate whether a control is actually operating—not simply whether documentation exists.
  • Internal Audit Skills: Able to plan and execute internal audits, sample and evaluate evidence, write clear findings, and drive corrective and preventive actions (CAPAs) through closure.
  • Auditor Credibility: Comfortable representing mpathic with external auditors, certification bodies, customers, and sponsor quality teams—and able to challenge findings constructively when the evidence supports a different conclusion.
  • Clear Communication: Able to write policies, findings, and customer responses that engineers can act on and executives can confidently approve.
  • Practical Mindset: You understand that strong compliance programs should enable teams to move quickly and responsibly rather than create unnecessary process.
  • Credentials: Certifications such as CISA, ISO/IEC 27001 Lead Auditor or Lead Implementer, ISO/IEC 42001 Lead Auditor, ASQ CQA, or CISSP are a plus.
Core Responsibilities
  • Audit Ownership: Plan and run the annual audit and certification cycle for SOC 1, SOC 2, ISO/IEC 27001, ISO/IEC 42001, and Part 11 readiness, including auditor selection, scoping, evidence collection, fieldwork, management responses, and final report or certificate delivery.
  • FDA Part 11 Program: Own Part 11 compliance for systems that create, modify, or store regulated records. Maintain the system inventory and GxP impact assessments, lead risk‑based validation, and ensure validation documentation remains current through releases and system changes.
  • Unified Control Framework: Maintain a unified control set mapped across applicable frameworks so evidence can satisfy multiple requirements and teams aren't duplicating work for every audit.
  • Internal Audit: Run a risk‑based internal audit program, including ISO-required internal audits and management reviews, and track nonconformities and CAPAs through closure.
  • Engineering & Delivery Partnership: Build controls into how mpathic develops and delivers its products and services, including change management, code review, access reviews, release validation, and data handling across customer work. Partner with engineering to automate evidence collection wherever possible.
  • Enforcement & Remediation: Monitor control health, identify and elevate gaps early, and drive remediation with control owners across engineering, delivery, operations, HR, and other teams.
  • AI Management System: Maintain mpathic’s ISO/IEC 42001 AI management system in partnership with ML, engineering, and product teams, including AI risk and impact assessments and documentation of model lifecycle controls.
  • Customer Security & Compliance Reviews: Own responses to security questionnaires, customer and sponsor quality audits, and compliance‑related portions of RFPs and contracts. Maintain and continuously improve our trust center.
  • GRC Tooling: Own our GRC platform and its integrations, ensuring control mappings, automated evidence collection, and policy workflows remain accurate and useful.
  • Policies & Training: Maintain the policies and SOPs required by our certifications and regulatory commitments, and deliver compliance training, including Part 11 and GxP training for employees working with regulated systems.
  • Regulatory Monitoring: Track changes to FDA guidance, AI governance requirements, and applicable data privacy laws, translating relevant changes into practical recommendations for mpathic’s compliance program.
What Success Looks Like

You’ll build a compliance program that is rigorous enough to meet the expectations of auditors, regulated customers, and enterprise partners while remaining practical for a fast‑moving technology company.

Audits and certifications will become increasingly predictable, evidence will be reusable and automated wherever possible, and teams will understand what controls they own and why they matter. You’ll also help ensure mpathic stays ahead of emerging expectations around AI governance and regulated technology as our platform and customer base grow.

Compensation

The base salary range for this role is $140,000–$180,000, depending on experience, skills, and qualifications.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Program Manager, Human Data Operations (East Coast)
Program Manager, Human Data Operations (East Coast)

mpathic • Boston (MA)

On-site
USD 140,000 - 190,000
Program Manager, Human Data Operations (Utah)
Program Manager, Human Data Operations (Utah)

mpathic • Utah

On-site
USD 120,000 - 160,000
Senior Software Engineer (Back End)
Senior Software Engineer (Back End)

mpathic • United States

On-site
USD 140,000 - 190,000
Senior Software Engineer (Back End)
Senior Software Engineer (Back End)

Mpathic • Northern (KY)

On-site
USD 120,000 - 180,000
Senior Compliance & Audit Lead - AI Governance
Senior Compliance & Audit Lead - AI Governance

Mpathic • Northern (KY)

On-site
USD 140,000 - 180,000
Technical Product Manager
Technical Product Manager

Mpathic • Bellevue (WA)

On-site
USD 140,000 - 190,000
Security and Compliance Manager
Security and Compliance Manager

Clinically AI • San Diego (CA)

On-site
USD 110,000 - 165,000
Healthcare coverage
Unlimited PTO
401(k) with company match
+1
Senior Software Engineer (Front End)
Senior Software Engineer (Front End)

Mpathic • United States

Remote
USD 110,000 - 165,000
Recruiter
Recruiter

Mpathic • Northern (KY)

Hybrid
USD 60,000 - 90,000
Senior Manager of IT SOX
Senior Manager of IT SOX

Anthropic • San Francisco (CA)

On-site
USD 180,000 - 240,000
Health insurance
Parental leave
Flexible time off
+3