Job Description
About 10a Labs: 10a Labs is the safety and threat-intelligence layer trusted by
frontier AI labs, AI unicorns, Fortune 10 companies, and leading global
technology platforms. Our adversarial red teaming, model evaluations, and
intelligence collection enable engineering, safety, and security teams to stay
ahead of evolving threats and deploy AI systems safely.
COMPLIANCE MANAGER
ABOUT THE ROLE
We're seeking a Compliance Manager to build, own, and continuously improve our
security and privacy compliance programs. This individual will serve as the
operational lead for implementation of frameworks including SOC 2, GDPR, ISO
27001, Cyber Essentials Plus, and other regulatory and customer-driven
compliance initiatives while partnering closely with engineering, security,
legal, HR, and leadership.
You'll be responsible for ensuring the organization maintains a strong security
and compliance posture while enabling rapid product development and customer
growth. This is a highly cross-functional role for someone who enjoys creating
scalable processes, driving audits from start to finish, translating complex
requirements into practical controls, and helping customers trust how we protect
sensitive information.
WHAT YOU'LL DO
* Own the company's compliance program across SOC 2, GDPR, ISO 27001, Cyber
Essentials Plus, and additional security, privacy, and governance frameworks.
* Lead all phases of external audits, certifications, and annual compliance
assessments.
* Develop, maintain, and continuously improve security policies, standards,
procedures, and internal controls.
* Partner with engineering and security teams to implement, document, and
validate technical, administrative, and operational controls.
* Manage evidence collection, audit readiness, and ongoing compliance
activities using GRC platforms and internal tooling.
* Coordinate enterprise risk assessments and track remediation efforts through
successful completion.
* Own third-party risk management, including vendor security reviews and due
diligence.
* Respond to customer security questionnaires, support enterprise procurement
processes, and maintain customer trust documentation.
* Build and maintain customer-facing compliance resources, including trust
portals, security documentation, and compliance artifacts.
* Monitor changes to global privacy and security regulations, recommending
updates to policies and controls as requirements evolve.
* Help develop and operationalize AI governance practices aligned with emerging
regulations and industry frameworks, including the EU AI Act and NIST AI Risk
Management Framework.
* Develop compliance metrics, dashboards, and executive reporting to
communicate organizational risk and program maturity.
- Deliver security awareness and compliance training across the organization.
- Collaborate with engineers, analysts, and leadership to embed compliance
throughout product development, infrastructure, and business operations.
* Serve as the primary internal subject matter expert for compliance and
governance initiatives.
REQUIRED QUALIFICATIONS
* Bachelor's degree in Information Security, Cybersecurity, Computer Science,
Information Technology, Business, Risk Management, Law, or a related field.
* 5+ years of experience in compliance, information security, governance, risk
management, or audit.
- Experience owning or managing SOC 2 compliance programs and external audits.
- Strong understanding of GDPR and modern data privacy requirements.
- Experience implementing and maintaining security controls aligned with
frameworks such as ISO 27001, NIST CSF, CIS Controls, HIPAA, or similar.
* Experience working with cloud environments such as Amazon Web Services (AWS)
or Google Cloud Platform (GCP).
* Experience using Governance, Risk, and Compliance (GRC) platforms such as
Vanta, Drata, Secureframe, or similar.
* Experience supporting customer security reviews and enterprise procurement
processes.
* Strong project management skills with the ability to manage multiple
initiatives simultaneously.
* Excellent written and verbal communication skills with both technical and
non-technical audiences.
* Exceptional organizational skills and attention to detail.
PREFERRED QUALIFICATIONS
- Experience leading multiple successful SOC 2 Type II audits.
- Familiarity with AI systems, AI governance, or AI security concepts.
- Experience supporting compliance programs within high-growth technology or
SaaS companies.
* Experience with privacy impact assessments, data governance, or international
privacy regulations.
* Experience automating compliance workflows or integrating compliance into
engineering processes.
* Familiarity with security tooling, identity and access management, or cloud
security best practices.
* Professional certifications such as CISA, CISM, CRISC, CISSP, ISO 27001 Lead
Implementer, ISO 27001 Lead Auditor, or Certified Information Privacy
Professional (CIPP).
WE'RE LOOKING FOR SOMEONE WHO IS
- Highly organized with exceptional attention to detail.
- Comfortable owning complex programs with minimal oversight.
- Proactive and able to identify risks before they become problems.
- Practical and solutions-oriented when balancing security, compliance, and
business objectives.
* Able to influence cross-functional teams and build strong working
relationships.
* Curious about evolving regulatory requirements and emerging AI governance
standards.
* Comfortable working in a fast-moving environment with evolving priorities.
COMPENSATION & BENEFITS
- Salary Range: $105K–$125K, depending on experience and location
- Bonus: Performance-based annual bonus
- Professional Development: Support for conferences, continuing education, and
professional certifications
- Work Environment: Fully remote, U.S.-based
- Health Benefits: Comprehensive health, dental, and vision coverage
- Time Off: Generous PTO and paid holiday schedule
- Retirement: 401(k) plan
Job Tags
Full time, Remote work