Job Closed
This listing is no longer active.
Everybody works better together!
Compliance Manager
Location
Arizona
Posted
65 days ago
Salary
0
Seniority
Senior
Job Description
Compliance Manager
iT1
• Develop, maintain, and enforce compliance programs aligned with relevant standards (e.g., ISO, SOC 2 Type 2, GDPR, CMMC, NIST, CSF) consistent with the types of frameworks referenced across internal compliance dashboards. • Monitor regulatory updates and ensure policies and processes remain current. • Lead internal and external audits; prepare evidence and coordinate responses. • Ensure documentation aligns with legal and regulatory requirements, leveraging document control best practices. • Conduct ongoing risk assessments and collaborate with IT/Security teams to identify vulnerabilities — echoing risk assessment processes. • Develop mitigation plans, track corrective actions, and report risk posture to leadership. • Maintain centralized compliance dashboards and metrics. • Develop, revise, and publish corporate policies, procedures, and standards. • Ensure employees and vendors follow defined processes and frameworks. • Own library management and workflow processes. • Oversee training programs to ensure compliance with required regulations. • Partner with HR and department leads to improve compliance culture. • Track and report training completion, certifications, and recurring requirements. • Manage documentation repositories, version control, and audit trails. • Maintain readiness for customer, regulatory, and certification audits. • Produce and maintain evidence of compliance on demand. • Work closely with IT, Security, Legal, Client Success, and Operations teams. • Serve as a compliance subject matter expert in client discussions when needed. • Support incident response processes and post incident compliance documentation.
Job Requirements
- 3–5+ years of compliance, governance, risk, or audit experience.
- Strong understanding of relevant regulatory frameworks (ISO, SOC 2, GDPR, CMMC, NIST).
- Experience managing compliance programs audits, and documentation workflows.
- Experience using Vanta.
- Exceptional communication, organization, and analytical skills.
- Bachelor’s degree in Information Security, Business Administration, Compliance, or related field.
- Compliance or security certifications (CISA, CRISC, CCSK, ISO Lead Auditor, etc.).
- Certified to perform internal Audits.
- Background in IT services, managed services, or security operations.
Benefits
- Medical, dental, and vision benefits with highly subsidized premiums
- Two weeks paid time off in your first year, with increasing PTO as tenure increases, and most major holidays off
- 401(k) Plan with employer match
- Onsite Fitness Center
- Onsite Monthly Massages
Related Guides
Related Categories
Related Job Pages
More Compliance Jobs
Director, Compliance Services
MediSpendMediSpend solutions are designed to empower life sciences companies to grow their business compliantly.
• Maintain deep, current expertise in U.S. and global life sciences compliance requirements related to HCP/HCO engagements, interactions, and transparency reporting • Serve as the primary compliance advisor for SE customers, providing guidance on regulatory interpretation, risk mitigation, and industry benchmarking • Anticipate compliance trends, emerging regulations, and evolving industry expectations; translate updates into actionable internal recommendations • Develop and maintain an expert-level understanding of the Stakeholder Engagement product—including configuration, workflows, data dependencies, reporting logic, and upcoming roadmap features • Evaluate how product enhancements, defects, or configuration choices affect customer compliance obligations, data integrity, and operational workflows • Partner closely with Product and Engineering to provide compliance input on roadmap planning, requirement definition, and release readiness • Work closely with Implementation and Customer Success teams to ensure customers are configured and supported in a manner consistent with compliance expectations and best practices • Support Sales as the compliance SME during demos, RFPs, prospect discussions, and conference participation • Contribute to the design and delivery of internal training programs, playbooks, and knowledge-based content to elevate organizational expertise on compliance and SE product requirements • Build trusted, long-term relationships with customers, acting as their strategic compliance advisor and escalation point for complex issues • Proactively engage customers to understand evolving business needs, pain points, and strategic objectives; translate insights into product or process improvements • Participate in key customer meetings, governance forums, and business reviews to reinforce alignment and demonstrate product and compliance leadership • Lead or participate in specialized compliance engagements, including assessments, audits, policy reviews, customized training, and best-practice consultations • Represent the organization at industry conferences, webinars, and professional associations to strengthen brand reputation and support commercial growth • Develop thought-leadership content (whitepapers, presentations, guidance documents) to support customers and internal teams
• Maintain and improve information security policies, standards, procedures, control documentation, and related governance materials. • Help map policies and controls to frameworks such as SOC 2, ISO 27001/27002, HITRUST, NIST CSF 2.0, and other customer, regulatory, or security requirements. • Support policy exceptions, risk acceptances, remediation tracking, control owner follow-ups, and recurring governance workflows. • Support SOC 2, ISO 27001, and HITRUST readiness, audit preparation, evidence collection, auditor coordination, and audit response management. • Maintain recurring evidence-gathering and control testing workflows, helping ensure controls operate consistently across the business. • Track audit findings, control gaps, remediation plans, owners, due dates, and closure evidence. • Support risk assessments, control gap assessments, internal reviews, and maintenance of the risk register. • Translate technical and security risks into clear business language, including mitigations, ownership, timelines, and residual risk. • Own or support customer security questionnaires, RFP security sections, due diligence requests, and trust or compliance documentation. • Maintain reusable questionnaire content, approved responses, compliance artifacts, and customer-facing assurance materials. • Support employee security awareness programs and create clear internal guidance for policies, controls, and compliance responsibilities. • Support vendor security reviews, third-party risk assessments, remediation tracking, risk acceptance documentation, and vendor compliance evidence. • Use GRC platforms such as Vanta, Drata, Thoropass, Secureframe, or similar tools to improve evidence collection, control monitoring, task tracking, reporting, and repeatable compliance operations.
• Monitor and interpret gambling regulations across multiple jurisdictions. • Support licensing activities, audits, regulatory filings, and reporting. • Coordinate responses to regulators and maintain compliance records. • Advise internal teams on compliance obligations and regulatory requirements. • Lead and maintain the company’s data protection framework and GDPR compliance. • Improve privacy processes, policies, and internal controls.
Manager, GRC Subject Matter Experts, Product
VantaVanta is the leading trust management platform that helps simplify & centralize security for organizations of all sizes.
• Hire, mentor, and develop a team of SMEs covering commercial frameworks, government frameworks, test authoring, framework quality uplift, and framework maintenance — planning for current and future capacity needs, setting the bar for technical depth and content quality, and preparing high performers for broader scope • Build a stable, motivated team environment with clear operating rhythms, delegating effectively to grow ownership and capability, and partnering with your leader and People Business Partner to spot and address team health issues early • Connect the team's roadmap and content priorities to Vanta's broader product and company strategy, anticipating near-term shifts in customer needs, regulatory landscape, and product direction, and adjusting focus to keep the team aligned • Create open feedback loops within the team and adapt how you communicate priorities, decisions, and risks across different audiences — from individual contributors to engineering, GTM partners, customers, and executives • Lead the team through change with steadiness while holding yourself and them accountable for commitments — communicating progress and risks proactively, addressing misses directly, and creating an environment where mistakes are treated as learning opportunities rather than blame • Own and govern Vanta's framework release process end-to-end, partnering with Product and Engineering to define the playbook for how new frameworks, framework updates, automated tests, crosswalks, and content are scoped, built, reviewed, and shipped • Drive the program management work that surrounds GRC content — including new framework launches, framework updates, update notes, customer escalations, content and test requests, PMM material reviews, and licensing and pricing input • Track team performance and report KPIs and metrics to security and product leadership, including framework release velocity, content quality, adoption, time-to-evidence, and customer impact • Break down ambiguous and competing priorities — across framework launches, framework updates, test authoring, and quality uplift — into clear, actionable decisions, balancing customer demand, market opportunity, and engineering capacity, and escalating complex tradeoffs with context and a recommended path forward • Lead the quality uplift effort for older commercial frameworks, ensuring Vanta's full library meets a consistent and modern standard for control wording, evidence specificity, and testing method • Set direction for the team's work on crosswalks and mappings across security and privacy frameworks, including canonical control IDs, mapping confidence, and evidence data dictionaries, and partner with Engineering to operationalize them in-product • Steer the team's contribution to the broader GRC product surface — risk management, issue and corrective action management (POA&M), policy management, access reviews, Trust Center, and third-party risk management • Partner with Product Management and Design to ensure SMEs are effective product advisors across discovery, PRD authoring, UI/UX review, and usability testing • Champion AI-assisted compliance on the team — coaching SMEs to translate domain knowledge into machine-readable specs, evaluation sets, and guardrails, and partnering with Engineering and ML to ship LLM-powered guidance and automation • Partner with Sales, Customer Success, and Product Marketing to represent the framework portfolio externally and contribute to pricing, packaging, and licensing conversations (including frameworks such as HITRUST) • Serve as a senior escalation point for customer issues related to framework content, scoping, and interpretation • Provide input and feedback on the development of GRC product features that depend on the team's content and expertise




