Security & Compliance Manager

Relocity
$140,000 - $170,000Remote

About The Position

Relocity is seeking an experienced Security & Compliance Manager to maintain and strengthen our information security, privacy, and data governance programs. Reporting into leadership, you will partner closely with Engineering, Product, Operations, and G&A to keep our systems, processes, and policies aligned with evolving regulatory and security requirements as the company grows. Our compliance foundation is already established. You will own the ongoing maintenance of our SOC 2 Type II program, lead our ISO 27001 certification effort to completion, and continuously improve our governance and risk management practices. You will use Vanta as our compliance platform to streamline monitoring, evidence collection, and audit readiness.

Requirements

  • Three to Five years in information security, data privacy, governance, compliance, or risk management.
  • Direct experience maintaining SOC 2 Type II and leading or supporting ISO 27001 certification within a SaaS or cloud-first environment.
  • Hands-on experience with Vanta or comparable GRC platforms such as Drata, Secureframe, or Sprinto.
  • Strong working knowledge of GDPR, CCPA, and other applicable privacy regulations.
  • Demonstrated success designing and implementing data classification, retention, privacy, and security programs.
  • Familiarity with cloud infrastructure, SaaS environments, identity and access management, and security controls.
  • Ability to explain complex technical concepts to technical and non-technical audiences.
  • Proven ability to influence stakeholders and lead initiatives across multiple functions.
  • Bachelor's degree in Information Security, Computer Science, Information Systems, Business, Legal Studies, or a related field, or equivalent practical experience.

Nice To Haves

  • Professional certifications such as CIPP/US, CIPM, CISSP, CISM, or CRISC.
  • Experience in a high-growth SaaS or technology startup environment.
  • Knowledge of privacy-by-design principles.

Responsibilities

  • Maintain SOC 2 Type II compliance, including control operation, evidence collection, and annual audit readiness.
  • Lead the ISO 27001 certification effort, from gap assessment through certification and ongoing surveillance.
  • Own additional security and privacy frameworks, including GDPR, CCPA, and other applicable regulations.
  • Serve as the company's primary advisor on security, privacy, and compliance strategy.
  • Establish and continuously improve security controls, governance standards, policies, and risk management practices.
  • Conduct security risk assessments, manage incident response, and drive remediation efforts.
  • Administer Vanta and related tooling to automate compliance monitoring, continuous control testing, and audit workflows.
  • Partner with Engineering, Product, Operations, Legal, and leadership to embed security and privacy into products, systems, and business processes.
  • Translate technical risk into practical business recommendations that inform strategic decisions.
  • Define enterprise data governance standards, including data classification, retention, and lifecycle management.
  • Lead company-wide security awareness initiatives that promote responsible data stewardship.
  • Monitor evolving regulations, emerging threats, and industry best practices to strengthen our security program.
  • Evaluate and implement technologies and processes that improve automation, visibility, and operational efficiency.

Benefits

  • Competitive Compensation
  • Paid Time Off
  • Paid Parental Leave
  • Health, Dental, Vision, and LTD Insurance
  • 401(k)
  • Professional Development Opportunities
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service