Skip to main content
Back to jobs

Manager, Compliance

External
horizon3ai logoHorizon3ai · Remote
Full-timeRemote1mo ago
ComplianceDocumentationGDPRLeadershipProcess ImprovementRisk Management
Cover LetterConnect

Prepare for this interview

Elite

AI-generated questions, company research, and talking points tailored to this role


Responsibilities

  • This role will be responsible for.....
  • Lead, coach, and grow the Compliance team, including ownership of compliance operations, privacy, third-party risk management, and customer assurance
  • Set priorities and operating rhythms for the team, balancing strategic program maturity, customer-facing support, audit readiness, and cross-functional execution
  • Serve as the internal lead for compliance efforts, including control mapping, evidence collection, audit coordination, and continuous improvement of the control environment
  • Maintain and improve compliance against frameworks such as, but limited to: SOC 2, ISO 27001, NIST AI RMF, ISO 42001, DORA, UK Cyber Essentials, FedRAMP, and/or NIST 800-53
  • Collaborate with cross-functional teams including Engineering, IT, Legal, HR, Product, Sales, and Customer Success to implement and validate control requirements
  • Oversee the organization's data privacy program, ensuring compliance with GDPR, CCPA/CPRA, EU AI Act, and emerging U.S. state privacy laws
  • Maintain records of processing activities (RoPAs), manage data subject access requests (DSARs), and conduct privacy impact assessments (PIAs)
  • Partner closely with Legal and Product to advise on privacy-by-design, data minimization, and transparency practices
  • Own and manage the third-party risk management lifecycle, including onboarding reviews, periodic reassessments, contract/privacy reviews, and ongoing risk tracking
  • Conduct security and privacy due diligence on new vendors and partners supporting the SaaS product
  • Maintain a current inventory of vendors, subprocessors, and associated risk assessments
  • Serve as the primary point of contact for customer security questionnaires, RFPs, customer audits, and due diligence requests
  • Leverage existing documentation such as the SOC 2 report, pentest reports, whitepapers, and DPAs, while partnering with SMEs to provide accurate and timely responses
  • Support Sales, Customer Success, and Legal in accelerating deals by strengthening trust in our security and compliance posture
  • Create metrics, reporting, and risk narratives that communicate compliance posture, trends, and priorities to business owners and leadership
  • Identify opportunities to improve processes, tooling, and documentation that help the company scale its compliance and privacy programs efficiently
  • Demonstrate a commitment to integrity, process improvement, and customer satisfaction
  • Act as the primary owner for enterprise security risk, establishing and maturing the Risk Register to ensure all identified threats are centralized and tracked.
  • Manage the comprehensive risk lifecycle, overseeing everything from initial detection and impact analysis to remediation tracking and formal sign-off.
  • Implement a standardized risk scoring methodology that utilizes quantitative and qualitative metrics to drive objective prioritization across the entire organization.
  • As a Manager, you wi

Benefits

Remote work options

Additional Information

Get to Know Us Horizon3.ai is a fast-growing, remote cybersecurity company dedicated to the mission of enabling organizations to proactively find, fix and verify exploitable attack vectors before criminals exploit them. Our flagship product, the NodeZeroTM platform, delivers production-safe autonomous pentests and other key assessment operations that scale across the largest internal, external, cloud, and hybrid cloud environments. NodeZero has been adopted by organizations of all sizes, from small educational institutions to government agencies and Global 100 enterprises. It is used by IT Ops/SecOps teams, consulting pentesters, and MSSPs and MSPs. We are a fusion of former U.S. Special Operations cyber operators, startup engineers & operators, and formerly frustrated cybersecurity practitioners. We're committed to helping solve our common security problems: ineffective security tools and false positives, resulting in alert fatigue, blind spots, "checkbox" security culture, cybersecurity skills shortage, and the long lead time and expense of hiring outside consultants. Collectively, we are a team of learn it alls, committed to a culture of respect, collaboration, ownership, and results.


Your Match

How well this role fits your profile.

Company Intel

What employees say

Worked at horizon3ai? Share your experience

Interested in this role?

Apply on the company's website.

Cover LetterConnect