Senior Security Compliance Manager
San Francisco, San Francisco County, California, 94199, USA
Listed on 2026-06-03
-
IT/Tech
Cybersecurity, Information Security, Data Security, IT Consultant
What you’ll do
The Senior Security Compliance Manager is responsible for maintaining and managing new and ongoing Docu Sign security commercial certification audits and self‑assessments. These include ISO 27001, 27017, 27018, PCI‑DSS 4.0, IRAP, APEC PRP, C5, ISMAP, FISC, SIG, and CSA STAR, among others. The role builds scalable, efficient processes for the APAC region and overall security compliance programs, working closely with the U.S. Compliance team.
The incumbent will monitor the security compliance landscape, identify relevant standards and certifications, and translate findings into program actions such as gap analysis, remediation, and controls effectiveness testing. The position is an individual contributor reporting to the Director of Security Compliance.
- Analyze the security compliance landscape continuously to identify relevant standards and certifications for the APAC region and translate requirements into program actions, including gap analysis, remediations, and controls effectiveness testing.
- Lead end‑to‑end ANZ IRAP technical compliance with external auditors and ANZ government agencies, including mapping IRAP controls to cloud‑native architectures, automating evidence collection, and embedding IRAP requirements into Docu Sign’s security controls framework.
- Perform security requirements mappings and develop or enhance controls to meet additional requirements; document evidence requirements and supplemental guidance to support GRC programs and engage control owners.
- Maintain technical expertise in domains such as logging and detection, configuration management, vulnerability management, and network security.
- Implement technical controls or AI across audit, certification, and compliance activities to streamline processes such as evidence automation.
- Identify automation opportunities and implement scalable solutions that integrate with GRC platforms, cloud services, and ticketing tools.
- Manage and optimize security compliance audits and assessments, including customer audits independently end‑to‑end while meeting strict deadlines and maintaining executive‑level metrics and reporting.
- Partner with engineering and product teams to embed compliance into system design, architecture, and operational solutions, reducing audit fatigue and streamlining compliance operations using tooling and AI.
- Define and publish technical security and compliance requirements and controls guidance using technology or AI, enabling control owners to commit to actionable outcomes.
Hybrid:
Employees divide their time between in‑office and remote work. Access to an office location is required (minimum 2 days per week, with a weekly in‑office expectation). The designations of In Office, Hybrid, or Remote are specific to each role and may change based on business needs and local law.
Basic
- Experience with Security Compliance frameworks such as ANZ IRAP, Italy ACN, UK Cyber Essentials, and AI standards such as ISO 42001 and NIST AI RMF.
- Experience supporting compliance automation.
- Experience with cloud infrastructure (Azure, AWS, GCP) and SaaS technology.
- Bachelor’s degree in Computer Science, Information Systems, or related field, or equivalent work experience.
- 8+ years of relevant experience in Security Compliance, Auditing, Assessments, or GRC.
- 2+ years managing security compliance audits and/or customer audits.
- Experience with audit lifecycle, testing controls, and writing test scripts in various environments.
- Experience working with cross‑functional departments and stakeholders to provide security compliance risk recommendations.
- Industry certification such as CISSP, CISA, CISM, CRISC, ISO 27001 Lead Auditor, CompTIA Security+, AWS/Azure Security, or equivalent GRC certification.
- Experience reviewing compliance evidence required for audits.
- Experience engaging with internal, external, and customer auditors.
Preferred
- Self‑starter with excellent communication, collaborative, and presentation skills.
- Comfortable working in a fast‑paced, dynamic environment and managing multiple projects concurrently.
- Ability to coach and prepare technical teams/SMEs for audit interviews.
- Strong…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).