SlipstreamJobsFresh Startup & VC-Backed Jobs

Head of IT/Compliance

Footprint - New York, NY, USA - In-office - posted 2026-08-26

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Footprint is an agentic AI platform that automates compliance program execution for banks and fintechs, reducing manual review workloads by 70%+ while maintaining organizational memory across investigations. The company is backed by QED, Index, and Box Group, and serves FDIC- and OCC-regulated banks plus fintechs like Bilt, Nuvei, and MoonPay, having 5x'd revenue last year. This is Footprint's first dedicated IT and Compliance role, inheriting a mature program with SOC 2 Type 2, PCI DSS Level 1, GDPR, and ISO 27001 already live and passing audits. You will report directly to the CTO and own the full compliance and security infrastructure. Key responsibilities include: managing all four compliance frameworks and audit relationships with external auditors; owning identity and access control (SSO, directory management, authentication/authorization policies, onboarding/offboarding); managing the device fleet and endpoint security across the workforce; designing and executing the vendor security review process and technology spend decisions; overseeing security operations, penetration testing, scanning vendors, and disaster recovery; and serving as the customer-facing compliance resource for Sales (security questionnaires, report packages). You will use Vanta as the system of record, manage SSO and directory infrastructure, oversee MDM and endpoint security tooling, and work within AWS. The role requires end-to-end ownership of compliance programs, control state accountability in platforms like Vanta or Drata, modern device fleet management, SSO/directory expertise including offboarding procedures, and the ability to make documented risk-acceptance decisions under resource constraints. Must-haves include: prior end-to-end compliance program ownership (scoping, audits, findings closure); accountability for control state in a compliance platform; workforce device fleet management on modern MDM/endpoint stacks; SSO and directory management experience including secure offboarding; experience as the entire IT/compliance function at a company; documented risk-acceptance decision-making; and ability to explain technical controls to non-technical stakeholders. Nice-to-haves include PCI DSS Level 1 program ownership, engineering background, and fintech/payments industry experience.

Similar roles