Continuous, autonomous pentesting, powered by NodeZero. Are your systems secure? Don't wait for a breach to find out!
Manager, Compliance
Location
United States
Posted
18 days ago
Salary
$149.9K - $185K / year
Seniority
Senior
Job Description
Manager, Compliance
Horizon3.ai
• Lead, coach, and grow the Compliance team, including ownership of compliance operations, privacy, third-party risk management, and customer assurance • Set priorities and operating rhythms for the team, balancing strategic program maturity, customer-facing support, audit readiness, and cross-functional execution • Serve as the internal lead for compliance efforts, including control mapping, evidence collection, audit coordination, and continuous improvement of the control environment • Maintain and improve compliance against frameworks such as, but limited to: SOC 2, ISO 27001, NIST AI RMF, ISO 42001, DORA, UK Cyber Essentials, FedRAMP, and/or NIST 800-53 • Collaborate with cross-functional teams including Engineering, IT, Legal, HR, Product, Sales, and Customer Success to implement and validate control requirements • Oversee the organization’s data privacy program, ensuring compliance with GDPR, CCPA/CPRA, EU AI Act, and emerging U.S. state privacy laws • Maintain records of processing activities (RoPAs), manage data subject access requests (DSARs), and conduct privacy impact assessments (PIAs) • Partner closely with Legal and Product to advise on privacy-by-design, data minimization, and transparency practices • Own and manage the third-party risk management lifecycle, including onboarding reviews, periodic reassessments, contract/privacy reviews, and ongoing risk tracking • Conduct security and privacy due diligence on new vendors and partners supporting the SaaS product • Maintain a current inventory of vendors, subprocessors, and associated risk assessments • Serve as the primary point of contact for customer security questionnaires, RFPs, customer audits, and due diligence requests • Leverage existing documentation such as the SOC 2 report, pentest reports, whitepapers, and DPAs, while partnering with SMEs to provide accurate and timely responses • Support Sales, Customer Success, and Legal in accelerating deals by strengthening trust in our security and compliance posture • Create metrics, reporting, and risk narratives that communicate compliance posture, trends, and priorities to business owners and leadership • Identify opportunities to improve processes, tooling, and documentation that help the company scale its compliance and privacy programs efficiently • Demonstrate a commitment to integrity, process improvement, and customer satisfaction • Act as the primary owner for enterprise security risk, establishing and maturing the Risk Register to ensure all identified threats are centralized and tracked. • Manage the comprehensive risk lifecycle, overseeing everything from initial detection and impact analysis to remediation tracking and formal sign-off. • Implement a standardized risk scoring methodology that utilizes quantitative and qualitative metrics to drive objective prioritization across the entire organization. • Recruiting and onboarding talented individuals to support our organizational goals • Mentoring, coaching, equipping, and developing your team • Recognizing and retaining high performers • Leading horizontally with peer management and senior leaders.
Job Requirements
- Must have deep experience in Governance, Risk, and Compliance (GRC) within a B2B SaaS, cybersecurity, or similarly regulated technology environment
- Must have a deep understanding of compliance frameworks such as SOC 2, ISO 27001, NIST AI RMF, DORA, and NIST 800-53, including experience leading annual audits
- Must have expertise in GDPR, CCPA/CPRA, EU AI Act, and emerging U.S. state data privacy laws
- Must have strong working knowledge of third-party risk management, vendor due diligence, and privacy/security review processes
- Must have experience responding to security questionnaires, RFPs, customer audits, and due diligence requests
- Must be knowledgeable in common SaaS infrastructure and business systems such as AWS, Okta, MDM, SIEM, and DLP
- Must have strong written and verbal communication skills, with the ability to translate complex compliance concepts for both technical and non-technical stakeholders
- Must be able to work independently and as part of a team, with a strong sense of ownership and accountability
- Must have experience building metrics and reporting that communicate compliance risk and program health to leadership.
Benefits
- Health insurance
- Vision insurance
- Dental insurance
- Flexible vacation policy
- Generous parental leave
- Stock options
Related Guides
Related Categories
Related Job Pages
More Compliance Jobs
Role Description Spinwell is recruiting for a Landfill Regulations & Management Lead for an excellent opportunity within the public sector. - Provide expert advice on landfill operation and the impact of regulation on the landfill sector, including planning and performance at local or regional levels, ensuring policy proposals reflect operational realities. - Shape policy on landfill regulation, closure, and aftercare, advising on best practices to embed environmental protection and resource recovery within policy frameworks. - Contribute technical expertise on methane capture technologies and operations, helping define policy positions on net zero pathways and strategies. - Develop robust policy proposals, including defining issues, generating options, sourcing evidence, engaging stakeholders, and preparing papers and presentations for senior decision-makers. - Think strategically and programmatically, situating individual work within the wider residual waste roadmap and contributing to long-term planning and infrastructure strategy. - Work collaboratively within an interdisciplinary team, supporting a one-team ethos and integrating perspectives from policy, technical, and delivery colleagues. - Bring innovation and constructive challenge, introducing new ideas and approaches to improve policy and delivery outcomes. - Upskill Civil Servants, sharing specialist knowledge through mentoring, workshops, and technical guidance to build internal capability. - Engage with stakeholders across local government, industry, and regulators, building consensus and supporting practical implementation of policy changes. - Provide clear, evidence-based advice and briefings to senior officials and ministers, translating technical detail into actionable recommendations. Qualifications - Residual waste infrastructure planning and performance at a local or regional level. - Landfill regulation, closure, and aftercare management, able to advise on how best to ensure environmental protection and resource recovery are embedded in policy. - Knowledge of methane capture technologies and operations. - Developing policy proposals: define the issue to be addressed, devise options, source an evidence base, engage stakeholders, and recommend a preferred option, all involving preparation of papers and presentations. - Thinking strategically and programmatically: situate their individual work within the context of a wider programme and contribute to defining the long-term goal of the wider programme. - Working collaboratively: we are an interdisciplinary directorate and have a one team ethos. - Innovate: we are open to, and want our secondees to bring, new ideas and constructive challenge to our work. Benefits - We welcome all applications regardless of background, in line with our commitment to diversity, equality, and inclusion. - As a member of the disability confident scheme, the client guarantees to interview all candidates who have a disability and who meet all the essential criteria for the vacancy. - The client is proud to support the Armed Forces Covenant and guarantees to interview all veterans or spouses/partners of military personnel who meet all the essential criteria for the vacancy.
• Provide support of the ISO 13485 certification and CE schemes, for example investigating customer appeals, report reviewing and supporting activities during regulator audits • Deliver certification decisions for ISO 13485 certifications as eligible, with a goal to being qualified across all non-CE schemes, where resource allows • Competence verifier activities to support the auditor qualification process • Support the roll out of policy decisions and processes for medical device QMS audits globally • Participating in smaller improvement projects ensuring appropriate adherence to procedures • Provide advice and support to QMS auditors globally, technical specialists, scheme managers, sales, marketing and other BSI colleagues on BSI QMS requirements for medical devices
Senior Manager, Regulatory Compliance
MN8 EnergyMN8 Energy is one of the largest independent solar energy and energy storage owner-operators in the U.S., serving enterprise customers with clean energy and complementary solutions, such as battery storage and EV Charging, to enable an electrified, decarbonized world. Originally founded inside of Goldman Sachs in 2017, our fleet has grown to nearly 4-gigawatts of solar, including 850 projects across 28 states, and over 270 megawatts of battery storage projects, with each project tailored to achieve the bold decarbonization targets and goals of our more than 200 blue-chip customers. MN8 is headquartered in New York with offices in Dallas, Boca Raton, Florida and Madrid. For more information: mn8.com.
Role Description MN8 is seeking a highly motivated individual to join our Compliance organization as Manager, Regulatory Compliance and be responsible for evolving and overseeing an effective, risk-based regulatory compliance program across MN8’s solar and energy storage portfolio, with a focus on federal and regional energy regulations. The successful candidate will report to the Head of Compliance and Security and be responsible for evolving an effective compliance program that ensures the company complies with relevant laws and regulations. - Develop and implement regulatory compliance policies and procedures that ensure the company complies with relevant laws and regulations - Identify potential areas of compliance risk and develop strategies to mitigate those risks - Stay current with regulatory changes and industry trends that may impact the company's compliance obligations - Monitor and audit company operations to ensure compliance with relevant regulations and standards - Work with Asset Management, Solutions and other teams on regulatory compliance risks and mitigation strategies - Develop and deliver training programs to ensure employees are aware of and adhering to compliance obligations - Support internal investigations related to regulatory compliance matters and coordinate findings, remediation plans, and reporting with the Head of Compliance and Security - Partner across the organization to manage third-party and vendor compliance risk, including diligence, performance monitoring, and remediation Qualifications - Bachelor's degree in business administration, law, or a related field. M.S., M.B.A., or J.D. preferred - 10+ years of experience in a regulatory compliance role, preferably within the energy, utilities or infrastructure sectors, with a proven track record of reducing regulatory risk exposure - Experience in the energy industry, whether with a utility, IPP, renewable energy company, or similar - Experience performing risk assessments, identifying risks, and designing risk mitigation strategies - Strong understanding of FERC, NERC, ISO/RTO requirements (e.g., PJM, ERCOT, MISO) and State ICC/PUC regulations required - Excellent communication and interpersonal skills, with the ability to build strong relationships with internal and external stakeholders - Advanced analytical skills with the ability to identify potential areas of risk and develop effective strategies to mitigate those risks - Ability to work independently and as part of a team, with a high level of integrity and accountability - Permanent authorization to work for any employer in the U.S. without sponsorship Benefits - Medical/Dental/Vision Insurance beginning the 1st of the month following your date of hire - Paid Time Off - Paid holidays and floating holidays - 401(k) with competitive employer match - Parental leave Company Description MN8 Energy is one of the largest independent solar energy and energy storage owner-operators in the U.S., serving enterprise customers with clean energy and complementary solutions, such as battery storage and EV Charging, to enable an electrified, decarbonized world. Originally founded inside of Goldman Sachs in 2017, our fleet has grown to nearly 4-gigawatts of solar, including 850 projects across 28 states, and over 270 megawatts of battery storage projects, with each project tailored to achieve the bold decarbonization targets and goals of our more than 200 blue-chip customers. MN8 is headquartered in New York with offices in Dallas, Boca Raton, Florida and Madrid. For more information: mn8.com.
Manager – Governance, Risk and Compliance (GRC)
SpyCloudThe leader in operationalizing Cybercrime Analytics to prevent ATO, ransomware, and online fraud.
• Own and manage SpyCloud’s day-to-day GRC and compliance operations across multiple frameworks, including SOC 2, ISO 27001, NIST, and CMMC 2.0. • Lead internal and external audit coordination activities, evidence collection, remediation tracking, and control validation efforts. • Maintain and improve security policies, standards, procedures, and governance documentation. • Drive ongoing compliance readiness activities and operationalize scalable compliance processes across the business. • Partner closely with Legal, Security Engineering, DevOps, and Engineering teams to ensure alignment on security and regulatory requirements. • Conduct enterprise risk assessments and facilitate ongoing risk identification, tracking, remediation, and reporting processes. • Develop and maintain risk registers and support leadership reporting on security and compliance risks. • Lead third-party/vendor risk management activities, including security reviews and vendor assessments. • Support customer trust initiatives, including security questionnaires, compliance inquiries, and due diligence requests. • Partner with DevOps and Security Engineering teams to strengthen cloud security governance across AWS and cloud-native environments. • Ensure security controls are aligned with compliance frameworks and operational best practices. • Support implementation and monitoring of governance controls related to cloud infrastructure, identity management, logging, vulnerability management, and secure development practices. • Contribute to ongoing security awareness and compliance education initiatives across the organization. • Manage and mentor direct report(s), supporting professional growth and operational excellence within the GRC function. • Collaborate with technical and non-technical stakeholders to drive accountability and operational maturity. • Help prioritize remediation efforts and compliance initiatives based on business risk and organizational goals. • Support the Senior Director of Governance, Risk and Information Security in scaling SpyCloud’s overall security governance program.


