SlipstreamJobsFresh Startup & VC-Backed Jobs

Security & Compliance Manager

ALICE Technologies - Prague, Czech Republic - Hybrid - posted 2026-08-28

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

ALICE Technologies, founded in 2015 and based on Stanford University research, has built the world's first construction optioneering platform using AI to help large general contractors reduce risk and plan, bid, and build more efficiently. The company works with leading construction firms including Parsons, Takenaka, Austin Bridges and Roads, and Skanska. As Senior Security & Compliance Manager, you will own the security and compliance program end-to-end and set the technical direction for protecting the platform, customers, and their data. Key responsibilities include driving compliance frameworks to certification (SOC 2, ISO 27001), hardening cloud infrastructure on AWS, leading incident response, and representing ALICE's security posture to enterprise customers. You will manage customer-facing security work at the enterprise level, including security questionnaires, RFP responses, trust-center content, and direct engagement with customer security teams. You'll translate privacy and data residency requirements (GDPR, DPAs, cross-border data handling) into technical and contractual controls, and mentor others on security best practices. Required qualifications include 5+ years in security with demonstrated ownership of a GRC program or equivalent security engineering experience. You must have proven track record taking at least one recognized framework through certification end-to-end, from gap assessment and control design to audit and continuous compliance. Deep working knowledge of privacy regulations and data residency requirements is essential, along with strong cloud security fundamentals on AWS (IAM, network segmentation, encryption, secrets management), solid HTTP and Linux foundations, and hands-on experience leading incident detection and response. Nice-to-have skills include experience with SIEM, compliance-automation tooling (Vanta, Drata, Secureframe), cloud and code security engineering, threat modeling, and relevant certifications (CISSP, CCSP). The company offers flexible vacation, openness to remote work, equity participation, and significant opportunity for professional growth in an early-stage, innovative AI-driven product company.

Similar roles