SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 150,000 - 200,000 / annual
Polymarket is the world's largest prediction market platform, enabling individuals to trade on real-world outcomes across politics, economics, sports, culture, and current affairs. The platform processed $21B in trading volume in 2025 and is positioned as an alternative news source reflecting collective expectations about the future.
You will own governance, risk, and compliance (GRC) and privacy operations for a small, senior IT and Security team. This is a hands-on senior individual contributor role where you will independently make judgment calls, build new processes, and create documentation for the team. The role spans three core areas: third-party vendor risk management, audit execution, and privacy operations.
Key responsibilities include:
- Triaging vendor intake requests daily, assessing inherent risk based on data sensitivity and system connectivity, and routing appropriately (flagging vendors requiring PIAs or DPA review before onboarding)
- Analyzing vendor assurance documentation (SOC 2 reports, ISO certifications, PCI AOCs, penetration test summaries) and producing clear written risk memos with defensible dispositions
- Gathering and organizing evidence for the active SOC 2 Type II engagement, coordinating with control owners to close requests on time, and managing submissions through the auditor portal
- Processing DSAR requests across multiple corporate entities, applying correct retention exemptions and routing logic, and tracking fulfillment to meet statutory deadlines
- Running privacy impact assessments for new product features and vendor onboarding, working directly with product and engineering to identify risks before they ship
- Maintaining the policy library, tracking review and acknowledgment cycles, and owning remediation tracking for vendor and audit findings through to resolution
- Implementing and operationalizing the privacy compliance platform, including building out the data inventory and mapping data flows
Polymarket operates under privacy obligations spanning GDPR, CCPA/CPRA, BIPA, CUBI, and specific data flows related to KYC and identity verification at scale.
REQUIREMENTS:
- Hands-on SOC 2 Type II audit experience: you have personally gathered evidence, coordinated with control owners, and managed auditor requests through a full engagement cycle
- Demonstrated experience conducting third-party vendor risk assessments, including reading and interpreting SOC 2 reports, PCI AOCs, and pen test summaries, and writing risk memos with clear dispositions
- Working knowledge of GDPR, CCPA/CPRA, BIPA, and CUBI, and the ability to translate those obligations into concrete process steps that product and engineering teams can follow
- Experience building compliance or privacy processes from scratch, not just inheriting and maintaining them
- Comfort operating independently, triaging ambiguous situations, and making defensible decisions without waiting for escalation on routine assessments
PLUS (preferred):
- Experience with PCI DSS scoping or self-assessment activities
- Familiarity with KYC and identity verification data flows and privacy considerations specific to biometric and identity data
- Prior experience at a crypto, fintech, or prediction market company