About The Position

Ada is an AI customer service company focused on making customer service extraordinary. The Security team at Ada is crucial for maintaining customer trust by ensuring security and compliance. This role, as the Compliance & Security Lead, will own Ada's security compliance program end-to-end, including audits, customer trust initiatives, vendor risk management, vulnerability management, and the control framework. The goal is to automate evidence collection and processes to ensure year-round audit readiness, moving away from seasonal scrambling. This role will also serve as the external face of Ada's security posture, engaging in security conversations with enterprise prospects and customers, and translating emerging AI regulations into concrete platform requirements.

Requirements

  • Deep audit experience across SOC 1, SOC 2, PCI DSS, NIST frameworks, AICPA standards, and PII/privacy requirements.
  • Experience running audits end to end: evidence collection, control mapping, and auditor coordination.
  • Experience working directly with major audit firms such as Deloitte or EY.
  • Experience inheriting manual compliance programs and driving them toward automation tooling, process, and repeatability (Drata or similar compliance automation platforms).
  • Experience with vulnerability management at scale: taking a large vulnerability backlog (thousands of findings) and driving it down through prioritization, ownership, and process.
  • Customer-facing confidence: owning the room in security posture conversations with enterprise prospects.
  • Understanding of modern infrastructure, Kubernetes, Terraform, CI/CD.
  • Experienced owner of RFP security sections, customer security questionnaires, and trust centers (SafeBase or similar).
  • Strong writer: policies, control documentation, and data handling standards that people actually follow.
  • Proactive owner who builds programs that outlast you: process, documentation, and tooling over heroics.
  • Track regulatory and framework movement interest in agentic AI governance (AIUC and emerging frameworks) is a strong plus.

Nice To Haves

  • An engineering background is preferred but not required.

Responsibilities

  • Own Ada's security audits end to end: the upcoming AIUC audit, PCI, and SOC 2. Evidence collection, control mapping, and auditor coordination, run through Drata.
  • Automate evidence collection and control monitoring so that audit season (August–November) no longer requires heroics the team is audit-ready year-round.
  • Own the security and compliance sections of customer RFPs and security questionnaires. Maintain the SafeBase trust center so deals stop stalling on security review.
  • Own vulnerability management as a program: drive the backlog down with clear prioritization, ownership, and SLAs for critical findings.
  • Run vendor security and privacy reviews as a standing process with clear SLAs, not one-off scrambles.
  • Maintain the control framework and its documentation: policies, data handling, retention, and the evidence that controls actually operate.
  • Be the point of contact for customer security, privacy, and legal teams, and the internal source of truth on compliance status.
  • Track regulatory and framework movement relevant to agentic AI, starting with AIUC, and translate it into concrete internal requirements for the platform team.
  • Take ownership of the compliance work currently spread across the team, and make it sustainable.
  • First 90 days: take full ownership of the AIUC audit, produce a current-state gap assessment against our target frameworks, and turn the RFP security response into a repeatable process.

Benefits

  • Unlimited Vacation
  • Comprehensive Benefits: Extended health coverage, dental, vision, travel, and life insurance.
  • Wellness Account
  • Employee & Family Assistance Plan
  • Flexible Work Schedule
  • Remote-First, In-Person Friendly
  • Learning & Development Budget
  • Work from Home Budget
  • Access to Cutting-Edge AI Tools
  • Hands-On with LLMs
  • A Thriving Industry
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service