Security Compliance Manager
Charlotte, Mecklenburg County, North Carolina, 28245, USA
Listed on 2026-09-27
-
IT/Tech
Cybersecurity
Who we are:
Sardine is the leading agentic risk platform for fighting financial crime. Our integrated solution unifies data across risk teams to help organizations stop fraud in real time, prevent AI-driven attacks, and automate fraud and AML operations. Sardine’s platform is strengthened by one of the fastest-growing fraud consortiums in the market, spanning more than 6 billion profiled devices, 800 million consumers, and 3 million businesses worldwide.
Leading companies including FIS, GoDaddy, Intuit, Edward Jones, Zoom Info, and rely on Sardine to secure and grow trust in their products.
Our culture:
We have hubs in the Bay Area, NYC, Austin, Toronto, and São Paulo. However, we maintain a remote-first work culture. #Work From Anywhere
We hire talented, self-motivated individuals with extreme ownership and high growth orientation.
We value performance and not hours worked. We believe you shouldn’t have to miss your family dinner, your kid’s school play, friends get-together, or doctor’s appointments for the sake of adhering to an arbitrary work schedule.
Remote - US
From Home / Beach / Mountain / Cafe / Anywhere!
We are a remote-first company with a globally distributed team. You can find your productive zone and work from there.
As Security Compliance Lead, you own Sardine’s security compliance and GRC function end-to-end and reduce risk to our environment through effective communication, partnership, and program ownership. You are the primary point of contact for auditors, regulators, and industry stakeholders, and you partner with engineering, IT, product, security, and legal teams to run successful compliance and review exercises across multiple frameworks.
This is a senior, hands-on ownership role. You set how the compliance program runs rather than executing a plan handed to you, and you are accountable for keeping Sardine continuously audit-and customer-ready. You also lead and develop the team, with a Security Compliance Analyst reporting to you and room to grow the function as Sardine scales.
What you’ll doOwn compliance planning and the compliance program across SOC 2 Type II, PCI DSS (Level 1 Service Provider), ISO 27001, GDPR, CCPA, and DORA - responsible for the program’s design and direction, not only its execution.
Drive Sardine’s FedRAMP effort by working toward authorization, coordinating NIST SP 800-53 control implementation, 3
PAO assessment, and continuous monitoring across engineering and IT.Serve as the primary interface to auditors, regulators, and industry stakeholders, and partner with internal engineering, IT, product, security, and legal teams to drive reviews to clean outcomes.
Present objectives, scope, and results to senior management and the board (via the CISO), clearly articulating the business impact of control gaps in a highly professional and proficient manner.
Own the control framework - including rationalizing overlapping controls across standards into a coherent, evidence-efficient set - and the security policy and standards library.
Own the risk picture - the risk register, risk quantification, and reporting cadence - and validate that actions taken to address risks are appropriate and reported accurately.
Own the customer assurance and trust program - security questionnaires, attestations, and trust artifacts - so security review does not block deals.
Manage evidence and drive improvement - coordinate the assimilation of evidence, scans, and artifacts, and lead process improvements in response to findings from regulators, internal and external quality reviews, and maturity assessments.
Build product and technical fluency - understand Sardine’s platform and architecture well enough to ground control design and risk decisions in how…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).