Helping companies overcome the second chasm
Group Security & Compliance Manager
Location
Serbia
Posted
3 days ago
Salary
$60K / year
Seniority
Senior
Job Description
Group Security & Compliance Manager
Ionic Partners
• Lead customer security reviews, RFPs, RFIs, and questionnaires, turning around accurate, complete responses fast enough to keep deals moving • Stand up and maintain a customer-facing trust portal (SafeBase / Vanta / Drata or equivalent), including a dedicated AI/ML section • Own SOC 2 Type II program management, driving audits across portfolio companies (including Sparkrock's Type II conversion and CXT scoping), coordinating evidence with the Senior Group Security Engineer, and managing auditor relationships • Author and maintain security policies and documentation, including DPAs, sub-processor lists, and incident-communication templates • Own AI compliance and trust, including AI questionnaire responses, AI sub-processor management, framework tracking (EU AI Act, ISO 42001, NIST AI RMF), AI use disclosure, AI acceptable-use policy, and AI incident-comms playbooks • Run third-party vendor security reviews and renewals • Build and deliver internal security awareness training, and onboard customers through the required security setup • Draft and coordinate customer-facing incident communications, including breach/incident notifications with legal and engineering
Job Requirements
- 6+ years in security GRC, customer trust, or SaaS compliance.
- Excellent spoken and written English. Articulate, polished, and credible in live calls with enterprise customers and third parties — this person represents the group externally.
- SOC 2 audit experience as a primary point of contact (Type II strongly preferred).
- Working understanding of cloud security concepts — able to read and translate technical findings, not produce them.
- Awareness of the AI compliance landscape and willingness to own it.
- Nice to have
- CISSP / CISA / CIPP/E; Vanta / Drata / SafeBase experience.
- PE-backed or multi-portfolio background.
- ISO 42001 / NIST AI RMF familiarity; EU AI Act awareness.
Benefits
- We are 100% remote and global. Live your best life wherever that may be, and never lose out on career opportunities because of it.
- Flexible work hours. We work asynchronously and don’t care when you’re online, just that you deliver great results and are there for our customers.
- We are dedicated to your growth with consistent and meaningful feedback, support in achieving your personal career goals, and access to leading-edge tools, playbooks, and technology to amplify your experience.
- Introductions to thought leaders in the space and webinars on cutting-edge tech hot topics.
- Stipend to help set up your ideal home office
- Focus on culture: coffee chats, happy hours, cooking classes, book clubs, and more!
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Lead customer security reviews, RFPs, RFIs, and questionnaires, turning around accurate, complete responses fast enough to keep deals moving • Stand up and maintain a customer-facing trust portal (SafeBase / Vanta / Drata or equivalent), including a dedicated AI/ML section • Own SOC 2 Type II program management, driving audits across portfolio companies (including Sparkrock's Type II conversion and CXT scoping), coordinating evidence with the Senior Group Security Engineer, and managing auditor relationships • Author and maintain security policies and documentation, including DPAs, sub-processor lists, and incident-communication templates • Own AI compliance and trust, including AI questionnaire responses, AI sub-processor management, framework tracking (EU AI Act, ISO 42001, NIST AI RMF), AI use disclosure, AI acceptable-use policy, and AI incident-comms playbooks • Run third-party vendor security reviews and renewals • Build and deliver internal security awareness training, and onboard customers through the required security setup • Draft and coordinate customer-facing incident communications, including breach/incident notifications with legal and engineering
• Lead customer security reviews, RFPs, RFIs, and questionnaires, turning around accurate, complete responses fast enough to keep deals moving • Stand up and maintain a customer-facing trust portal (SafeBase / Vanta / Drata or equivalent), including a dedicated AI/ML section • Own SOC 2 Type II program management, driving audits across portfolio companies (including Sparkrock's Type II conversion and CXT scoping), coordinating evidence with the Senior Group Security Engineer, and managing auditor relationships • Author and maintain security policies and documentation, including DPAs, sub-processor lists, and incident-communication templates • Own AI compliance and trust, including AI questionnaire responses, AI sub-processor management, framework tracking (EU AI Act, ISO 42001, NIST AI RMF), AI use disclosure, AI acceptable-use policy, and AI incident-comms playbooks • Run third-party vendor security reviews and renewals • Build and deliver internal security awareness training, and onboard customers through the required security setup • Draft and coordinate customer-facing incident communications, including breach/incident notifications with legal and engineering
Staff Security Engineer
AurorRetail Crime Intelligence built for retailers and law enforcement to make stores safer and communities stronger.
• Ship Code in the Platform: Work directly in the Auror codebase — writing patches, fixing vulnerabilities, refactoring weak patterns, and deploying changes. • Build Security Tooling and Automation: Write tools, automation, and detections that scale the security team's impact. • Application Security and Vulnerability Remediation: Lead threat modelling and architecture reviews for major platform changes. • Platform and Infrastructure Security: Partner with SRE and Platform on cloud and infrastructure security. Write Terraform, build pipelines, contribute to platform-as-code. • AI Security and AI-Augmented Engineering: Help define and harden how Auror builds with and defends against AI. • Detection and Response: Partner with the Blue Team workstream to design and tune detections. • Customer Security and Assurance: Be the credible technical voice when enterprise customers need depth. • Standards, Patterns, and Coaching: Set technical direction for security controls, tooling, and architecture.
• You will own, build, and run your startup in fields such as Cybersecurity. • You will embark on an extensive personal development journey crafted by unicorn founders and follow a fully customised programme enhancing your goal, time, and energy management. • You will receive support in hiring through our network to over 50,000 professionals and advice as well as best practices from serial entrepreneurs. • You will receive intensive coaching to make your startup ready to raise millions in funding. • You will iterate your product with us until having reached product-market-fit and receive support in building up a sales force or creating a marketing engine respectively.


