About The Position

Our client builds technology that helps families access public benefits and assists governments, health plans, and other organizations in running those programs more effectively. Their work with state and federal agencies, Medicaid organizations, and health plans is growing rapidly. As this growth occurs, trust, security, privacy, and compliance have become fundamental product requirements. This role is unique, going beyond a typical PM position where compliance is just one feature. It's not solely a policy-focused compliance job or a pure security engineering role. We are seeking a trust and compliance expert who also excels as a product leader. You will be responsible for the strategy and requirements of the company's Trust layer, which includes platform features that integrate security, privacy, compliance, and auditability into the software's functionality. Additionally, you will manage the day-to-day trust and compliance program and lead a company-wide trust transformation. This is a senior, hands-on individual contributor position. You will be expected to understand requirements, determine their business and software implications, bring together the appropriate teams, and ensure the successful completion of the work.

Requirements

  • Significant hands-on experience owning security, privacy, trust, risk, or compliance programs within a software company.
  • Experience in regulated environments such as government, public-sector tech, healthcare, Medicaid, health plans, or similar high-trust industries.
  • Working knowledge of SOC 2, NIST 800-series controls, HIPAA, and government security standards.
  • A track record of leading audits, security questionnaires, penetration-testing programs, and remediation.
  • Strong product management skills: problem definition, requirements gathering, prioritization, roadmap ownership, and cross-functional delivery.
  • Sufficient technical fluency to engage deeply with senior engineers on architecture, access models, data flows, and controls.
  • The credibility and communication skills to interact effectively with sophisticated customer security teams.
  • Comfort working autonomously in an environment where both the function and the product are still under development.
  • Must be based in the U.S.

Responsibilities

  • Lead the Trust Transformation, owning the company's new trust operating model across Product, Engineering, Customer Delivery, and company operations.
  • Translate regulatory, customer, security, and privacy requirements into clear product, technical, and operational requirements.
  • Partner with the Trust engineering lead to design and build the Trust layer.
  • Establish durable approaches for production access, data handling, environment separation, release governance, and evidence collection.
  • Own product direction for identity and access management (with least-privilege access), tenant and environment isolation, data classification, privacy, consent, data provenance, audit logging and change history, retention and data governance, secure release and deployment controls, and continuous control monitoring.
  • Transition controls from manual processes to reusable, software-enforced capabilities, making the compliant path the default.
  • Own the Trust & Compliance Program, maintaining policies, controls, and evidence in Vanta, and coordinating control owners across the company.
  • Manage the compliance roadmap and convert new requirements into cross-functional initiatives.
  • Maintain a clear view of risks, control gaps, exceptions, and remediation commitments.
  • Provide clear recommendations to leadership when trust requirements necessitate business or product trade-offs.
  • Lead Audits, Assurance & Security Programs, maintaining continuous readiness for SOC 2 audits.
  • Coordinate external audits, penetration tests, and vendor risk reviews, driving findings to closure.
  • Launch the NIST 800-series alignment program and contribute to establishing FedRAMP-aligned practices.
  • Serve as the External Trust Lead, acting as the primary contact for customer security, privacy, compliance, and AI-governance requirements.
  • Lead responses to security questionnaires, privacy and AI-use assessments, and procurement reviews.
  • Represent the company with security, legal, and procurement teams at government agencies, Medicaid organizations, and health plans.
  • Convert recurring customer requirements into reusable controls rather than addressing them on a per-customer basis.

Benefits

  • A fully remote role within the U.S.
  • Competitive compensation based on experience.
  • Real ownership: you'll shape how trust is built into both the platform and the way the company operates.
  • A team that may grow around you as the function scales.
  • Mission-driven impact: your work helps families access the public benefits they rely on.
  • Close collaboration with Product & Engineering leadership in a fast-growing company.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service