SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 115,000 - 155,000 / annual
FloQast, an AI-powered accounting transformation platform, is seeking a Risk & Controls Manager to join its InfoSec & Compliance department, which reports directly to the General Counsel. This role serves as a risk and controls advisor, ensuring adherence to key compliance frameworks across the organization and evaluating business initiatives from a risk and controls perspective.
Key responsibilities include:
- Collaborating with cross-functional stakeholders to review, maintain, and align documentation, policies, and procedures with audit and regulatory expectations
- Conducting and documenting compliance impact assessments covering risk, privacy, and AI considerations
- Providing strategic, risk-informed guidance on compliance-related inquiries from internal teams
- Supporting security and compliance programs by ensuring adherence to SOC and ISO standards
- Owning execution of FloQast's privacy program, including maintaining privacy documentation, supporting data subject requests, and ensuring compliance with applicable privacy laws
- Managing FloQast's sub-processor program, including maintaining notification workflows and coordinating updates
- Supporting privacy-related product and vendor reviews
- Owning third-party risk management processes and associated due diligence activities
- Owning policy management processes across the organization, including facilitating annual reviews and coordinating updates
- Supporting identification, tracking, and remediation of compliance and policy-related issues
- Identifying opportunities for process improvement and automation within the risk management and compliance function, including developing AI-driven workflows
The InfoSec & Compliance department is a team of in-house subject matter experts who advise, direct, train, and monitor the organization, resulting in daily interactions with all departments. This role has a requirement of working in office 3 days per week, subject to change based on team and business needs.
Requirements:
- Bachelor's degree
- 6+ years of experience in compliance, risk management, information security, privacy, or a related field (SaaS industry experience preferred)
- Strong general compliance expertise, including privacy, security, and IT general controls
- Experience applying and maintaining compliance with frameworks such as SOC and ISO standards
- Foundational knowledge of privacy regulations and frameworks such as GDPR, CCPA, and related international privacy laws
- Strong communication and interpersonal skills with ability to collaborate effectively across teams and functions
- Highly organized, detail-oriented, and proactive in identifying and addressing compliance risks
- Ability to operate autonomously and drive risk and compliance initiatives with limited oversight
- Flexible and adaptable in a high-growth, fast-paced environment
Nice to haves:
- Certifications such as CIA, CISA, CISSP, CISM, CIPP/E, CIPM, or similar
- Experience with cloud hosting environments such as AWS, Azure, or GCP
- Experience with emerging technologies, including AI-driven features and associated risk considerations
- Prior experience supporting international compliance initiatives or privacy regulatory readiness across multiple jurisdictions