Skip to content
← Back to job listings

Risk and Compliance Lead

Replit · United States

External listingfull-time21 days ago

About The Role

Join Replit, a leading AI-native product company, as the Risk and Compliance Lead. In this role, you will own the end-to-end certification and audit program, manage relationships with external auditors, and maintain the company's master security risk register. You will work closely with Engineering to ensure controls are effective in practice and report to the Head of Security GRC. This is a remote-first position with flexible work hours and a range of benefits.

  • Posséder le programme de certification et d'audit de l'entreprise de bout en bout, y compris la planification, l'évaluation des lacunes, la remédiation et l'exécution de l'audit.
  • Gérer les relations avec les auditeurs externes et diriger le calendrier annuel des audits afin que les certifications soient renouvelées sans précipitation de dernière minute.
  • Être responsable de l'enregistrement des risques de sécurité de l'entreprise, y compris l'identification des risques, la méthodologie de notation, les plans de traitement et les rapports sur les risques résiduels.
  • Hands-on experience authoring or substantially maintaining an ISMS, SSP, or equivalent audit-facing documentation set and not just filling out a template
  • Experience with GRC/compliance automation platforms (e.g., Anecdotes, Vanta, Drata, etc.) and continuous control monitoring
  • Working knowledge of common frameworks (SOC 2, ISO 27001, NIST CSF) and how to map controls across them
  • Experience working directly with external auditors and managing an audit end to end
  • 8+ years in security compliance, IT audit, or GRC roles, with direct ownership of at least one SOC 2 and/or ISO 27001 certification cycle
  • Working familiarity with GDPR/privacy fundamentals sufficient to partner effectively with a legal team
  • Experience owning a formal risk register including risk identification, scoring methodology, treatment plans, and residual risk reporting to leadership
  • Comfortable reading technical control evidence and having detailed conversations with engineers about how systems actually work
  • Experience scoping or pursuing ISO 42001 or other AI governance frameworks
  • Background in a developer tools, platform, or AI/ML product company
  • Relevant certifications (CISA, CISSP, ISO 27001 Lead Auditor/Implementer)
  • Familiarity with FedRAMP or other government compliance regimes
  • Experience standing up a compliance program from an early or pre-certification stage
  • We encourage people from all kinds of backgrounds to apply, including and especially candidates from underrepresented and non-traditional backgrounds

This is an external listing. JobSpring does not represent or verify the employer. Report this listing