Security Compliance Manager
What security roles in crypto pay
64 salaries · our own dataMost security roles in crypto pay between $145k and $268k, with a median of $202k.
As Security Compliance Manager at Sardine, you own the security compliance and GRC function end-to-end and reduce risk to the organization through effective communication, partnership, and program ownership. You are the primary point of contact for auditors, regulators, and industry stakeholders, and you partner with engineering, IT, product, security, and legal teams across multiple compliance frameworks. This is a senior, hands-on role where you set how the compliance program runs rather than executing a plan handed to you, and you are accountable for keeping Sardine continuously audit- and customer-ready. You also lead and develop the team, with a Security Compliance Analyst reporting to you.
What you'll do
- Own compliance planning and the compliance program across SOC 2 Type II, PCI DSS (Level 1 Service Provider), ISO 27001, GDPR, CCPA, and DORA, responsible for the program's design and direction, not only its execution
- Drive Sardine's FedRAMP effort by working toward authorization, coordinating NIST SP 800-53 control implementation, 3PAO assessment, and continuous monitoring across engineering and IT
- Serve as the primary interface to auditors, regulators, and industry stakeholders, and partner with internal engineering, IT, product, security, and legal teams to drive reviews to clean outcomes
- Present objectives, scope, and results to senior management and the board via the CISO, clearly articulating the business impact of control gaps
- Own the control framework, including rationalizing overlapping controls across standards into a coherent, evidence-efficient set, and the security policy and standards library
- Own the risk picture including the risk register, risk quantification, and reporting cadence, and validate that actions taken to address risks are appropriate and reported accurately
- Own the customer assurance and trust program for security questionnaires, attestations, and trust artifacts so security review does not block deals
- Manage evidence and drive improvement by coordinating the assimilation of evidence, scans, and artifacts, and leading process improvements in response to findings from regulators, internal and external quality reviews, and maturity assessments
- Build product and technical fluency in Sardine's platform and architecture well enough to ground control design and risk decisions in how the technology actually works, and to engage engineering and product as a peer
- Look for creative, alternative solutions that promote consistency and unlock streamlining and automation opportunities
- Produce executive-ready documentation and presentations, and run well-organized meetings with regulators and internal stakeholders where you set the objectives, plan, and content
- Lead and develop the team starting with a Security Compliance Analyst, setting priorities, reviewing work, mentoring, and scaling the function as obligations grow
What you bring
- 7+ years in security compliance, GRC, or audit, including end-to-end ownership of audit or certification programs such as SOC 2, PCI DSS, and/or ISO 27001
- Deep knowledge of security and privacy frameworks including PCI DSS, SOC 2, ISO 27001, GDPR/CCPA, and DORA, and familiarity with control frameworks such as NIST CSF and CIS
- Technical and product comfort, able to build fluency in a technical product such as device intelligence, behavioral biometrics, or transaction monitoring, and hold your own with engineering and product teams
- Excellent written and verbal communication skills, executive-ready documentation, and credible presence with auditors, regulators, and leadership
- Experience in a fast-paced, high-growth environment, with fintech or payments experience strongly preferred given Sardine's PCI Level 1 service provider obligations
- Ability to work as a leader, a partner, and an individual contributor as the situation calls for, and to travel as needed
- Experience leading, mentoring, or managing others, or clear readiness to step into managing a direct report
Nice to have
- Direct experience running a PCI DSS Level 1 service provider program
- Hands-on exposure to DORA (operational resilience) requirements
- Familiarity with GRC and security tooling such as Vanta, HRIS such as Rippling, and macOS environments
What we offer
- Generous compensation in cash and equity
- Early exercise for all options, including pre-vested
- Remote-first work culture, work from anywhere
- Flexible paid time off and year-end break
- Health insurance, dental, and vision coverage for employees and dependents (US and Canada)
- 4% matching in 401k or RRSP (US and Canada)
- MacBook Pro delivered to your door
- One-time home office setup stipend for desk, chair, screen, and equipment
- Monthly meal stipend
- Monthly social meet-up stipend
- Annual health and wellness stipend
- Annual learning stipend
About Sardine
Sardine is the leading agentic risk platform for fighting financial crime. The integrated solution unifies data across risk teams to help organizations stop fraud in real time, prevent AI-driven attacks, and automate fraud and AML operations. Leading companies including FIS, GoDaddy, Intuit, Edward Jones, ZoomInfo, and Checkout.com rely on Sardine to secure and grow trust in their products.
