Compliance Manager

Anyscale
San Francisco, CA
On-site

Who this role is best for

Compliance professionals with experience in SOC 2 and ISO 27001 programs and a background in high-growth startups will find this customer-facing, program-ownership role at a San Francisco-based company with significant funding.

Best fit for

  • Candidates with proven experience running SOC 2 and ISO 27001 audits end to end
    — “Demonstrated ownership of SOC 2 and ISO 27001 programs, including running audits end to end with external auditors.
  • Individuals who have managed security diligence for enterprise or regulated customers
    — “Experience fronting security diligence for enterprise or regulated customers.

Things to consider

  • The role requires direct collaboration across engineering, IT, legal, and sales teams
    — “You will work directly with the Head of Security and across engineering, IT, legal, and sales.
  • This is a program-ownership role with no senior compliance function to defer to
    — “You will not have a senior compliance function above you to defer to; you are that function.

How to stand out

  • Emphasize your ability to independently manage compliance programs and deliver audit-ready evidence
    — “This is a program-ownership role with the autonomy and accountability that implies.
  • Highlight your experience in high-growth startups and managing security diligence for regulated customers
    — “7+ years in governance, risk, and compliance, ideally including time at a high-growth startup.
  • Showcase your fluency in compliance automation platforms and their practical use for audits
    — “Working fluency with compliance automation platforms (such as Vanta or equivalent) and with turning tooling into genuinely audit-ready evidence.
Pace · SteadyCollaboration · HighAutonomy · HighDecision Impact · Company

Derived from job-description analysis by Serendipath's career intelligence engine.

What success looks like

  • Own SOC 2 Type II and ISO 27001 programs
  • Lead security diligence for enterprise and regulated customers
  • Mature risk management into a recorded program
Typical background
7+ years in governance, risk, and compliance

Skills & requirements

Required

SOC 2 Type IIISO 27001Security DiligenceRisk ManagementCompliance Automation

Preferred

Data ProtectionVendor Assessments

About the role

Original posting from Anyscale via Ashby

At Anyscale https://www.anyscale.com/, we're on a mission to democratize distributed computing and make it accessible to software developers of all skill levels. We’re commercializing Ray https://docs.ray.io/en/latest/, a popular open-source project that's creating an ecosystem of libraries for scalable machine learning. Companies like OpenAI https://thenewstack.io/how-ray-a-distributed-ai-framework-helps-power-chatgpt/, Uber https://www.uber.com/blog/horovod-ray/, Spotify https://engineering.atspotify.com/2023/02/unleashing-ml-innovation-at-spotify-with-ray/, Instacart https://www.youtube.com/watch?v=3t26ucTy0Rs&list=PLzTswPQNepXmLUiL4F_1VHrPcCz1OeILw&index=23&pp=iAQB, Cruise https://www.youtube.com/watch?v=gj0BqvfX_wI&list=PLzTswPQNepXmLUiL4F_1VHrPcCz1OeILw&index=46&pp=iAQB, and many more, have Ray in their tech stacks to accelerate the progress of AI applications out into the real world.

With Anyscale, we’re building the best place to run Ray, so that any developer or data scientist can scale an ML application from their laptop to the cluster without needing to be a distributed systems expert.

Proud to be backed by Andreessen Horowitz, NEA, and Addition https://www.wsj.com/articles/ai-startup-anyscale-adds-99-million-to-andressen-horowitz-led-funding-round-11661254200 with $250+ million raised to date.

ABOUT THE ROLE

Anyscale's security and compliance needs are growing as we work with larger and more demanding customers. Compliance is increasingly a customer-facing, contractual function rather than an internal exercise, and we are looking for someone to own it.

This role owns that function end to end: our audits, our evidence base, our risk register, and the security diligence that customers put us through before and during a contract. You will work directly with the Head of Security and across engineering, IT, legal, and sales. This is a program-ownership role with the autonomy and accountability that implies. You will not have a senior compliance function above you to defer to; you are that function.

In your first year, success looks like a complete and defensible evidence base with clean audit outcomes, a repeatable way to answer customer security diligence, and a risk register that leadership actually uses.

WHAT YOU'LL DO

  • Own our SOC 2 Type II and ISO 27001 programs, and future frameworks as we take them on, including scope, evidence, control operation, and the relationship with our external auditors.
  • Own and complete the control evidence base in our compliance automation platform, moving controls from partially substantiated to audit-ready and keeping them there.
  • Lead security diligence for enterprise and regulated customers: security questionnaires, audit responses, right-to-audit requests, and the recurring reporting these customers require.
  • Own the risk register and mature risk management from a security-team activity into a recorded, enterprise-aligned program.
  • Coordinate the compliance obligations that come with customer contracts, including data protection, breach-notification timelines, and vendor and subprocessor assessments, in partnership with legal.
  • Assess and stand up new certifications as the customer pipeline requires them.
  • Partner with engineering and IT to make evidence collection a byproduct of how systems already run, rather than a manual scramble before each audit.

WHAT YOU'LL BRING

  • 7+ years in governance, risk, and compliance, ideally including time at a high-growth startup.
  • Demonstrated ownership of SOC 2 and ISO 27001 programs, including running audits end to end with external auditors.
  • Experience fronting security diligence for enterprise or regulated customers. You have sat across from a customer's auditors or security reviewers and held your own.
  • Working fluency with compliance automation platforms (such as Vanta or equivalent) and with turning tooling into genuinely audit-ready evidence, not just dashboards.
  • A strong grasp of security controls and how they operate in a cloud and SaaS environment, enough to work credibly with engineers rather than only collecting their attestations.
  • The judgment and communication to run a program independently, coordinate across functions, and be trusted as the single owner of compliance.

NICE TO HAVE

  • Experience with regulated-customer contractual security obligations: data protection agreements, breach notification, and right-to-audit provisions.
  • Exposure to newer or higher-bar frameworks (for example FedRAMP) and a sense of what standing them up would take.
  • Experience building a compliance function or team, since this role can grow into one as the company scales.
  • Familiarity with cloud infrastructure or AI or ML platforms.

Source: Anyscale careers (Ashby)

Similar roles