Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Sourcegraph

Compliance Manager

Sourcegraph

. Own and drive Sourcegraph’s governance, risk, and compliance program, with a primary focus on compliance .

Posted 10/7/2026full-timeRemote • United StatesMid-LevelSenior💰 $102,899 - $137,718 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates extensive experience in managing governance, risk, and compliance programs, with a strong focus on SOC 2 and ISO 27001 certifications. Capable of leading audits, managing risk registers, and providing compliance guidance across cross-functional teams.

Highest-signal resume keywords
Governance, Risk, Compliance ManagementSOC 2 Program OwnershipISO 27001 Certification ManagementRisk Management and Control DesignProject Management Skills

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
GovernanceRisk ManagementCompliance Program OperationsControl TestingEvidence CollectionAudit PreparationISMS GovernanceControl DesignCompliance DocumentationStakeholder Training
Soft Skills
Excellent Written CommunicationExcellent Verbal CommunicationOrganizational SkillsCuriosity About AI and AutomationHands-On Mindset
Tools & Technologies
GRC PlatformsCompliance Automation ToolsCloud-Based Technology Environments
Certifications & Qualifications
CISACISSPISO 27001 Lead ImplementerISO 27001 Lead AuditorCRISC
Industry Keywords
SOC 2ISO 27001GDPRHIPAAHITRUSTFedRAMPFISMAPCI DSSSaaSTechnology Startup

Tech Stack

Tools & technologies
Cloud

About the role

Key responsibilities & impact
  • Own and drive Sourcegraph’s governance, risk, and compliance program, with a primary focus on compliance
  • Work cross-functionally with Security, Engineering, IT, Legal, People, Sales, and other teams
  • Maintain and evolve the compliance program, including SOC 2 and ISO 27001 certifications
  • Prepare Sourcegraph for additional compliance frameworks as the business grows
  • Design and tailor controls, collect evidence, train internal teams, work directly with auditors, manage remediation, and drive follow-up work to completion
  • Build relationships with key stakeholders and understand the existing ISMS, risk register, controls, certifications, audit processes, and focus areas
  • Manage SOC 2 and ISO 27001 audit activities, including control testing, evidence collection, stakeholder coordination, auditor requests, findings, and remediation
  • Maintain the risk register, ISMS processes, policies, and compliance documentation
  • Guide internal teams on compliance responsibilities and provide practical compliance guidance
  • Support customer-facing compliance activities, including security questionnaires and compliance questions
  • Lead audits or major certification milestones
  • Own the GRC operating rhythm, including ISMS meetings, risk management activities, control reviews, documentation updates, and audit preparation
  • Establish a forward-looking compliance roadmap
  • Identify control gaps, assess risk, recommend solutions, and drive remediation
  • Introduce automation, AI, or process improvements to reduce manual compliance work

Requirements

What you’ll need
  • 5+ years of experience in governance, risk, compliance, information security compliance, or a related role
  • Demonstrated end-to-end ownership of SOC 2 and ISO 27001 programs, ideally within a SaaS, technology startup, or similarly fast-moving environment
  • Experience personally managing external audits and certification processes, including audit preparation, evidence collection, control testing, stakeholder training, auditor interaction, remediation, and follow-up
  • Strong understanding of risk management, control design, ISMS governance, and compliance program operations
  • Experience adapting compliance controls to an organization's actual environment
  • Familiarity with cloud-based technology environments and security and compliance considerations for a distributed or remote workforce
  • Strong project management and organizational skills
  • Excellent written and verbal communication skills
  • Hands-on mindset and willingness to personally execute compliance work
  • Curiosity about AI, automation, and emerging technology
  • Working hours must overlap with GMT-3 for at least 20 hours per week
  • Nice-to-have: Experience with GDPR, HIPAA, HITRUST, FedRAMP, FISMA, PCI DSS, or related standards
  • Nice-to-have: Experience supporting security questionnaires, customer assurance processes, or sales-related compliance activities
  • Nice-to-have: Experience with GRC platforms, compliance automation tools, or internal automation for evidence collection and control monitoring
  • Nice-to-have: CISA, CISSP, ISO 27001 Lead Implementer or Lead Auditor, CRISC, or similar credentials

Benefits

Comp & perks
  • Meaningful equity
  • Generous perks and benefits
  • Competitive cash compensation