Security Compliance Manager
Sardine
See how well this job matches your profile
Sign up to get an AI match score and generate a tailored application in seconds.
Get your match scoreAbout the role
Join Sardine, a fast-paced fintech company, as a Security Compliance Manager. In this senior, hands-on role, you will own the security compliance and GRC function end-to-end, reducing risk through effective communication and program ownership. You will be the primary point of contact for auditors, regulators, and industry stakeholders, and will partner with various internal teams to drive successful compliance and review exercises. You will also lead and develop a team, with a Security Compliance Analyst reporting to you. Key missions: Own and manage Sardine’s security compliance and GRC function, ensuring effective communication and program ownership.. Lead and develop the compliance program across multiple frameworks, including SOC 2 Type II, PCI DSS, ISO 27001, GDPR, CCPA, and DORA.. Serve as the primary interface to auditors, regulators, and industry stakeholders, driving reviews to clean outcomes and presenting results to senior management. Profile: - Fast-paced, high-growth experience — fintech or payments strongly preferred given Sardine’s PCI Level 1 service provider obligations - Deep knowledge of security and privacy frameworks — PCI DSS, SOC 2, ISO 27001, GDPR/CCPA, and DORA; familiarity with control frameworks such as NIST CSF and CIS - Technical and product comfort — able to build fluency in a technical product (e.g., device intelligence, behavioral biometrics, transaction monitoring) and hold your own with engineering and product teams - Excellent communication — strong written and verbal skills, executive-ready documentation, and credible presence with auditors, regulators, and leadership - Able to work as a leader, a partner, and an individual contributor as the situation calls for, and to travel as needed - People leadership — experience leading, mentoring, or managing others, or clear readiness to step into managing a direct report - 7+ years in security compliance, GRC, or audit, including end-to-end ownership of audit or certification programs (SOC 2, PCI DSS, and/or ISO 27001) - Direct experience running a PCI DSS Level 1 service provider program - Operational resilience — hands-on exposure to DORA requirements - Tooling — familiarity with GRC and security tooling (compliance automation platforms such as Vanta; HRIS such as Rippling) and with macOS environments
Scraped 8/31/2026