GetGlobalJob

Compliance Manager [IC3]

Sourcegraph · Remote — United States

Remote$103K – $138K per year
Apply on the original site ↗Sign in to save

Sign in and upload your CV to see how well you match this job.

Sign in

Job overview

Location
Remote — United States
Workplace
Remote
Employment type
Full-time
Salary
$103K – $138K per year
Date posted
Oct 11, 2026
Last checked at the source
Oct 11, 2026
Job source
via Himalayas

Requirements

You have built or operated compliance programs in a fast-moving technology environment and have personally owned major compliance initiatives from beginning to end. You are comfortable operating independently, getting into the details, and doing the work yourself while coordinating with stakeholders across the organization. You understand that frameworks such as SOC 2 and ISO 27001 define requirements but often leave significant flexibility in how an organization satisfies them, and you know how to translate those requirements into controls that fit the business. You are also comfortable working with technical teams and modern cloud environments. You can understand enough about infrastructure, systems, access controls, software development, and security processes to ask the right questions and effectively translate between auditors and technical teams. • 5+ years of experience in governance, risk, compliance, information security compliance, or a related role. • Demonstrated end-to-end ownership of SOC 2 and ISO 27001 programs, ideally within a SaaS, technology startup, or similarly fast-moving environment. • Experience personally managing external audits and certification processes, including audit preparation, evidence collection, control testing, stakeholder training, auditor interaction, remediation, and follow-up. • Strong understanding of risk management, control design, ISMS governance, and compliance program operations. • Experience adapting compliance controls to an organization's actual environment rather than applying generic or overly prescriptive requirements. • Familiarity with cloud-based technology environments and the security and compliance considerations associated with a distributed or remote workforce. • Strong project management and organizational skills with the ability to drive cross-functional initiatives from inception through completion. • Excellent written and verbal communication skills and the ability to explain compliance requirements clearly to both technical and non-technical audiences. • A hands-on mindset and willingness to personally execute the work required to keep the compliance program operating effectively. • Curiosity about AI, automation, and emerging technology, with an interest in using new tools to improve compliance workflows.

Skills

Visa and relocation

The posting doesn't mention visa sponsorship. Check the original posting or ask the company.

The posting doesn't mention relocation.

Job description

Who we are Our mission is to bring clarity and control to the world's most complex codebases. AI is accelerating code creation, but the infrastructure to understand, oversee, and evolve that code hasn't kept pace. Sourcegraph gives engineering organizations full visibility across their systems, precise context for their agents, and the ability to execute coordinated code changes at scale. As agentic development becomes the dominant engineering paradigm, we provide the context layer teams need to take control of their codebase. With Code Search, Deep Search, MCP, and Agentic Batch Changes, we deliver on that mission today - giving engineering teams and their AI tools the cross-repo context to navigate massive codebases with confidence, and the ability to make changes across hundreds of repositories at once. Companies like Stripe, Reddit, and Leidos rely on Sourcegraph to ship faster and with higher quality. We're backed by a16z, Sequoia, and Redpoint, and proud to operate as a globally distributed team that values high agency, direct communication, and customer love. If you want to build the infrastructure that lets every engineering team - and every agent they deploy - operate on their codebase with confidence, join us. Hours & location 🌎 While we hire almost anywhere in the world, we have a preference for someone to reside in the following locations for this role. However, if you feel qualified, we welcome you to apply regardless of location. No matter what, working hours must overlap with GMT-3 for at least 20 hours/week. Preferred locations: • USA Why this job is exciting As our Compliance Manager, you will own and drive Sourcegraph’s governance, risk, and compliance program, with a primary focus on compliance. This is a highly cross-functional role that works closely with Security, Engineering, IT, Legal, People, Sales, and other teams across the company. You will be responsible for maintaining and evolving our compliance program, including owning certifications such as SOC 2 and ISO 27001 and preparing Sourcegraph for additional frameworks as the business grows. This is not a role where you will simply coordinate work across a large compliance organization. We are looking for someone who has personally owned audit and certification programs end to end: designing and tailoring controls, collecting evidence, training internal teams, working directly with auditors, managing remediation, and driving follow-up work through completion. 📅 Within one month, you will… • You will build strong working relationships across Security, Engineering, IT, Legal, People, Sales, and other key stakeholders. • You will develop a clear understanding of Sourcegraph’s existing governance, risk, and compliance program, including our ISMS, risk register, controls, certifications, audit processes, and current areas of focus. • You will understand how our SOC 2 and ISO 27001 programs operate today, including key owners, evidence requirements, open risks, and upcoming milestones. • You will begin participating directly in day-to-day compliance activities and identify opportunities to improve or simplify existing processes. 📅 Within three months, you will… • You will have taken ownership of Sourcegraph’s ongoing SOC 2 and ISO 27001 compliance programs. • You will independently manage key audit activities, including control testing, evidence collection, stakeholder coordination, auditor requests, findings, and remediation. • You will evaluate existing controls and tailor them to Sourcegraph’s environment rather than relying on overly prescriptive or generic auditor recommendations. • You will actively maintain Sourcegraph’s risk register, ISMS processes, policies, and compliance documentation. • You will help internal teams understand their compliance responsibilities and provide practical guidance that allows them to meet requirements without creating unnecessary process. • You will support customer-facing compliance activities, including security questionnaires and compliance-related questions from prospective and existing customers. 📅 Within six months, you will… • You will have successfully led Sourcegraph through an audit or major certification milestone. • You will own the operating rhythm of the GRC program, including ISMS meetings, risk management activities, control reviews, documentation updates, and audit preparation. • You will have established a forward-looking compliance roadmap covering renewals, upcoming audits, new frameworks, regulatory requirements, and opportunities to improve how the program operates. • You will be able to independently identify control gaps or deficiencies, assess their risk, recommend practical solutions, and drive remediation with both technical and non-technical stakeholders. • You will have introduced automation, AI, or other process improvements that reduce manual compliance work while maintaining or improving program quality. About you You have built or operated compliance programs in a fast-moving technology environment and have personally owned major compliance initiatives from beginning to end. You are comfortable operating independently, getting into the details, and doing the work yourself while coordinating with stakeholders across the organization. You understand that frameworks such as SOC 2 and ISO 27001 define requirements but often leave significant flexibility in how an organization satisfies them, and you know how to translate those requirements into controls that fit the business. You are also comfortable working with technical teams and modern cloud environments. You can understand enough about infrastructure, systems, access controls, software development, and security processes to ask the right questions and effectively translate between auditors and technical teams. • 5+ years of experience in governance, risk, compliance, information security compliance, or a related role. • Demonstrated end-to-end ownership of S
Apply on the original site ↗Job source: via Himalayas

GetGlobalJob is not the employer or a recruiting agency. You apply on the original publisher's site: always check the posting before sharing your details, and never pay for a job.

Check your fit for this job

Create your free account and upload your CV to see how well you match this job and which skills you're missing.

Check my fit