Compliance and IT Security Manager
Listed on 2026-09-07
-
IT/Tech
Cybersecurity, Information Security & Data Protection
About Slang AI
Slang AI is redefining customer engagement through conversational AI, making every interaction seamless and efficient. Our mission is to transform the restaurant industry by providing the ultimate voice AI solution for consistently outstanding customer experiences.
At Slang AI, we believe how we build matters just as much as what we build. We foster a culture rooted in hospitality, ownership, and clarity, where every “Slangsta” feels valued, supported, and connected to the broader impact of our work in the AI-powered future of restaurants.
Overview
We're looking for a Compliance & IT Security Manager to own and advance our compliance programs, security posture, and core IT functions. This is a senior individual contributor role, not a people management position. You'll be the person responsible for making sure our compliance obligations are met, our security controls are effective, and the systems our team relies on every day are well run and secure as the company grows.
Your primary focus is compliance. You'll own our SOC 2 program end to end, from evidence collection to auditor coordination, along with our risk registry and security policies. Alongside that, you'll own the day-to-day IT functions that keep the company running: administering Google Workspace, managing identity and access across our SaaS tools, configuring SSO, and supporting staff through their full lifecycle.
The ideal candidate is someone who can move between coordinating a SOC 2 audit and configuring SSO for a new SaaS tool, and who treats compliance as an ongoing discipline.
Responsibilities Compliance & Security
- Own and maintain the company's security and compliance programs, including SOC 2 audit readiness, evidence gathering, and coordination with external auditors
- Manage and keep current all company security policies, ensuring they reflect evolving business needs, regulatory requirements, and industry best practices
- Maintain and update the company's risk registry, tracking identified risks, mitigations, and remediation timelines
- Plan and execute all regularly scheduled compliance activities, including backup recovery tests, access reviews, business continuity exercises, and tabletop drills
- Scope, schedule, and coordinate annual penetration tests based on our active production web services and applications, and manage remediation of findings
- Maintain the company's vendor registry and perform security reviews on both existing and prospective vendors, including evaluating SOC 2 reports, data processing agreements, and security questionnaires
- Monitor and respond to security events and alerts, triaging issues and coordinating incident response when needed
- Manage and improve compliance automation workflows in Drata, reducing manual evidence collection and improving audit efficiency
- Evaluate and recommend security tooling improvements as the company's infrastructure and threat landscape evolve
- Develop and deliver security awareness training for staff on topics such as phishing, credential hygiene, and data handling
- Administer the company's Google Workspace environment, including user management, organizational units, and security configurations such as DLP policies, context-aware access controls, and authentication requirements
- Own staff account provisioning and deprovisioning across dozens of SaaS platforms via Rippling and Google Workspace, ensuring timely onboarding and thorough offboarding
- Set up and maintain Single Sign-On (SSO) connections between Rippling and SaaS tools, troubleshooting authentication issues as they arise
- Own staff onboarding and offboarding from an IT and security perspective, including device provisioning through Rippling, MDM compliance, endpoint security configurations, and timely access revocation
- Conduct periodic access audits to verify that user permissions are appropriate and that former staff have been fully deprovisioned across all systems
- Respond to IT help requests via Slack, assisting staff with technical issues, access problems, and general troubleshooting, escalating and documenting as appropriate
- 7+ years of experience across IT administration,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).