SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Sardine is seeking a Security Compliance Manager to own the company's security compliance and GRC function end-to-end. This is a senior, hands-on leadership role where you will set the direction of the compliance program rather than execute a pre-defined plan. You will be the primary point of contact for auditors, regulators, and industry stakeholders, partnering with engineering, IT, product, security, and legal teams to run successful compliance and review exercises.
Key responsibilities include owning compliance planning across SOC 2 Type II, PCI DSS (Level 1 Service Provider), ISO 27001, GDPR, CCPA, and DORA frameworks. You will drive Sardine's FedRAMP authorization effort, coordinating NIST SP 800-53 control implementation and 3PAO assessment. You'll serve as the primary interface to external auditors and regulators while presenting compliance objectives and risk impact to senior management and the board.
You will own the control framework, rationalizing overlapping controls across standards into a coherent, evidence-efficient set. You'll manage the risk register, risk quantification, and reporting cadence, ensuring actions taken to address risks are appropriate and accurately reported. The role includes owning the customer assurance and trust program—security questionnaires, attestations, and trust artifacts—to prevent security reviews from blocking deals.
Additionally, you will manage evidence coordination, drive process improvements based on findings from regulators and quality reviews, and build product and technical fluency in Sardine's platform and architecture. You'll look for creative solutions that promote consistency and unlock automation opportunities. The role includes leading and developing a Security Compliance Analyst and scaling the function as the company grows.
Required qualifications: 7+ years in security compliance, GRC, or audit with end-to-end ownership of audit or certification programs (SOC 2, PCI DSS, ISO 27001). Deep knowledge of security and privacy frameworks including PCI DSS, SOC 2, ISO 27001, GDPR/CCPA, and DORA. Technical and product comfort with ability to build fluency in complex technical products and engage engineering teams as a peer. Excellent written and verbal communication skills with executive-ready documentation. Fast-paced, high-growth experience in fintech or payments strongly preferred. People leadership experience or clear readiness to manage direct reports.