Head of IT/Compliance
Listed on 2026-09-21
-
Engineering
Cybersecurity, Regulatory Compliance Specialist
Head of IT/Compliance Location
New York City;
Remote;
San Francisco
Full time
Location TypeHybrid
DepartmentEngineering
Compensation- $175K – $210K Offers Equity
Footprint is the agentic platform that learns your compliance program and runs it end to end.
Compliance teams at banks and fintechs are drowning in financial crimes investigations. Transaction volumes are surging, regulators keep raising the bar, and the work still runs on manual review queues stitched together from legacy vendors. Percy, our agentic system, learns each team's procedures and makes the same calls their analysts would: clearing false positives, escalating real risk, writing the case narrative, and documenting every decision for audit.
It cuts review workloads by 70%+.
The harder problem is underneath. Every investigation is grounded in the data sources compliance teams already trust, and every case commits to an organizational memory that compounds — so a pattern one analyst caught in March surfaces automatically in October, across KYC, EDD, sanctions, and monitoring. Whether the team is five analysts or 500, they share one brain. Every memory carries provenance.
Agents propose; humans approve. That's four years of identity infrastructure sitting under the agent, and it's the part nobody can bolt on later.
We're backed by QED, Index, and Box Group, and trusted by FDIC- and OCC-regulated banks plus fintechs like Bilt, Nuvei, and Moon Pay. We 5x'd revenue last year. The team is small, senior, and ships fast.
The RoleFor four years, Footprint's security and compliance work has been the CTO's responsibility. SOC 2 Type 2, PCI DSS Level 1, GDPR, and ISO 27001 all got stood up and kept live. The internal systems underneath them got built the same way: SSO, device management, access control, and dozens of vendor relationships.
We are hiring this first dedicated IT and Compliance role early for two reasons. First, Footprint helps companies be compliant, so we hold ourselves to the highest standards here. Our customers are banks and fintechs who trust us with some of the most sensitive data there is, and proving we deserve that trust - security questionnaires, report requests, audits - is core to how we sell, not a cost center.
Second, we believe our compliance program should push the frontier on what a secure organization touching this kind of data should be.
You're inheriting a real program with all four frameworks live and passing. We're in good health; we need you to take us to the next level. The mandate is to take a compliance program that passes its audits and build one that's ahead of them: vendor management, data lifecycle, endpoint coverage, and the system of record itself all become yours to systematize, and to keep pace with everything we're building next, including agentic systems.
You'll own these decisions and have the trust and ownership to change how we approach this today.
You'll report directly to Alex Grinman, our CTO.
What You'll OwnThe compliance programs. SOC 2 Type 2, PCI DSS Level 1, GDPR, and ISO 27001, with Vanta as the system of record. You own the control state, the evidence, and the audits with our external auditors. You also own the judgment underneath them: which findings we fix now, which risks we accept and document, and where an auditor's ask deserves an argument
Identity and access. SSO, directory management, and the authentication and authorization policies behind them. Onboarding and offboarding run end to end through you, including the revocation path that has to be airtight the day someone leaves. You set the access standard for every internal service and tool we use
The device fleet. Endpoint protection and device security across every workforce machine. You own the coverage…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).