Security Governance & Compliance Manager
See all open roles at field nation →
Likely real
- 22 open roles at this company in 30 days (mass-hiring blitz)
See your fit for this role and apply with a truthfully tailored résumé.
About the role
What you'll get to do:
Own the SOC 2 Type II program: Run the annual cycle end to end - control operation, evidence collection, the auditor relationship, and the report our customers rely on. This is Field Nation's core compliance commitment today.
Lead ISO 27001 from scratch to certification: Scope the ISMS, remediate gaps, select an auditor, and achieve certification. This is a greenfield initiative and a first-year priority, driven by enterprise customer demand.
Own AI governance across the company: Cover both the AI embedded in our product and marketplace and the AI adopted internally. Maintain the AI inventory and risk register, set usage policy, and drive readiness for ISO 42001 following the 27001 certification.
Own policy, risk, and third-party governance: Manage the policy and standards lifecycle, the risk register, vendor and third-party risk assessments, and security awareness training. Serve as the primary point of contact for customer security questionnaires and internal audits.
Set the governance standard for identity and access: Own access review cadence, joiner-mover-leaver process design, and audit-trail integrity. While day-to-day access operations sit with partner teams, this role holds the policy, risk, and measurement standard to ensure Field Nation maintains one coherent access posture.
Build and lead a distributed team: Oversee two direct reports based in Bangladesh. Hire, develop, and set the standard for program execution as the team grows.
Direct compliance automation strategy: Partner with a GRC engineer who builds the automation; determine what's worth automating and validate that each automated control enforces what it claims to.
Share in security escalation response. Participate in a team-based escalation rotation alongside the Director and other US staff. Managed detection filters routine noise, so escalations represent genuine signals.
You might be a good fit if you have:
You've personally led an ISO 27001 implementation through to certification - or built a SOC 2 Type II program from scratch and completed credible 27001 gap analysis work.
You've owned a compliance or GRC program end to end at a company with real enterprise customers. You've sat across from an auditor and responded to customer security questionnaires yourself, not just maintained a control library.
You're comfortable reading technical control evidence and having detailed conversations with engineers about how systems actually work. You can evaluate a piece of compliance automation and determine whether the control it claims to enforce is genuinely enforced. You can also read an AI system's data flows well enough to know what data reaches a model, where it goes, and who can retrieve it.
You've directly managed security, GRC, or compliance professionals for two or more years, including hiring and performance management.
You have a clear point of view on which security work should be automated and which shouldn't.
You've managed a team across time zones and can speak concretely to how you used a narrow daily overlap window - what you protected it for, and how you made the rest of the work function asynchronously.
Why we think you'll love it here:
Exposure to cutting-edge technologies to solve meaningful problems
Collaborative, values-driven culture that balances rigor with innovation
Unlimited paid time off
Annual vacation bonus - yes, we’ll pay you a bonus to take paid time off!
Individualized growth + development plans
Strong values around work/life balance
Community involvement opportunities
Competitive benefits: medical, dental, vision, paid parental leave + 401K
Stop applying to ghosts.
OyaPilot surfaces only verified, real jobs, scores your fit, and tailors your application truthfully.
Do more with OyaPilot