×
Register Here to Apply for Jobs or Post Jobs. X

Security Governance & Compliance Manager

Job in Lakeville, Dakota County, Minnesota, 55044, USA
Listing for: Field Nation
Full Time position
Listed on 2026-08-26
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 120000 - 150000 USD Yearly USD 120000.00 150000.00 YEAR
Job Description & How to Apply Below

Who we are:

Field Nation brings companies and service professionals together through an integrated, easy-to-use platform. We support businesses looking to grow their service offerings while also empowering technicians to leverage their skills on their own terms. Our mission is to help the service delivery industry do great work, and we live that mission by doing great work for the companies and service professionals that depend on us.

Why

this role is important to Field Nation

Field Nation’s Information Security team works across the Technology organization to run and continuously improve our security, risk, and compliance programs. As Security Governance & Compliance Manager you will report to the Director, Information Security & Cloud Platforms and lead a small security team, owning our governance, risk, and compliance program end to end — SOC 2 today, ISO 27001 and ISO 42001 ahead of us, identity governance, vendor risk, and the governance of AI across both our product and our own operations.

What

you'll get to do
  • Own the SOC 2 Type II program:Run the annual cycle end to end - control operation, evidence collection, the auditor relationship, and the report our customers rely on. This is Field Nation's core compliance commitment today.
  • Lead ISO 27001 from scratch to certification: Scope the ISMS, remediate gaps, select an auditor, and achieve certification. This is a greenfield initiative and a first-year priority, driven by enterprise customer demand.
  • Own AI governance across the company:Cover both the AI embedded in our product and marketplace and the AI adopted internally. Maintain the AI inventory and risk register, set usage policy, and drive readiness for ISO 42001 following the 27001 certification.
  • Own policy, risk, and third-party governance: Manage the policy and standards lifecycle, the risk register, vendor and third-party risk assessments, and security awareness training. Serve as the primary point of contact for customer security questionnaires and internal audits.
  • Set the governance standard for identity and access: Own access review cadence, joiner-mover-leaver process design, and audit-trail integrity. While day-to-day access operations sit with partner teams, this role holds the policy, risk, and measurement standard to ensure Field Nation maintains one coherent access posture.
  • Build and lead a distributed team: Oversee two direct reports based in Bangladesh. Hire, develop, and set the standard for program execution as the team grows.
  • Direct compliance automation strategy: Partner with a GRC engineer who builds the automation; determine what's worth automating and validate that each automated control enforces what it claims to.
  • Share in security escalation response. Participate in a team-based escalation rotation alongside the Director and other US staff. Managed detection filters routine noise, so escalations represent genuine signals.
You might be a good fit if you have:
  • You've personally led an ISO 27001 implementation through to certification - or built a SOC 2 Type II program from scratch and completed credible 27001 gap analysis work.
  • You've owned a compliance or GRC program end to end at a company with real enterprise customers. You've sat across from an auditor and responded to customer security questionnaires yourself, not just maintained a control library.
  • You're comfortable reading technical control evidence and having detailed conversations with engineers about how systems actually work. You can evaluate a piece of compliance automation and determine whether the control it claims to enforce is genuinely enforced. You can also read an AI system's data flows well enough to know what data reaches a model, where it goes, and who can retrieve it.
  • You've directly managed security, GRC, or compliance professionals for two or more years, including hiring and performance management.
  • You have a clear point of view on which security work should be automated and which shouldn't.
  • You've managed a team across time zones and can speak concretely to how you used a narrow daily overlap window - what you protected it for, and how you made the rest of the work function asynchronously.
Why we…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary