SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
SingleStore is seeking a Senior Compliance Specialist to scale its security, privacy, and compliance programs. The role is responsible for maintaining key certifications (ISO/IEC 27001, SOC 2 Type II, HIPAA, PCI DSS), driving cross-functional compliance initiatives, overseeing privacy program development and management, supporting Digital Operational Resilience Act (DORA) compliance, and maturing the Business Continuity Management System (BCMS).
Key responsibilities include: supporting governance activities and maintaining Information Security Management System documentation; coordinating certification and attestation maintenance with business stakeholders; driving readiness for new compliance objectives and customer-driven assurance requirements; participating in enterprise risk management activities including risk assessments and treatment planning; overseeing privacy program implementation in partnership with Legal, Security, IT and business teams; operationalizing privacy and data protection controls; leading DORA compliance activities including control mapping, gap assessments, and cross-functional readiness planning; developing and maturing the BCMS; supporting vendor risk and third-party security management; defining corrective action plans and tracking remediation of audit findings; contributing to security and compliance awareness initiatives; partnering with Legal on regulatory and contractual obligations; and communicating compliance priorities to technical, business, and executive stakeholders.
The ideal candidate is practical, organized, and collaborative, with experience translating regulatory and framework requirements into durable operational processes. Required qualifications include 3+ years in security, privacy, or compliance; 2+ years at an ISV, SaaS provider, or technology company; strong understanding of ISO 27001, SOC 2 Type II, HIPAA, PCI DSS, GDPR, CCPA, and DORA; experience with compliance operations, audits, risk management, and control-based programs; ability to coordinate cross-functional workstreams; working knowledge of cloud technologies; and strong communication skills. Preferred qualifications include experience with managed cloud services, privacy or business continuity program building, DORA and operational resilience programs, emerging AI governance frameworks, customer-facing compliance topics, and professional certifications (CISSP, CISA, CISM, CIPM, CIPT, CDPSE, or ISO 27001 Lead credentials).