Security Compliance Manager

AI risk platform that helps financial institutions prevent fraud, ensure compliance, and detect money laundering through behavioral analysis and device intelligence.

Maintainer signals as of 8/23/2026

524 Broadway New York, NY 10012, USA, United States
About Sardine

Sardine helps financial institutions prevent fraud and ensure compliance by analyzing user behavior and device intelligence in real-time. Users can detect identity theft, payment fraud, account takeovers, and money laundering while streamlining KYC/AML processes. Sardine provides risk management with AI agents, case management, and regulatory reporting tools.

View jobs by Sardine

Skills

Candidate Availability

Required and preferred rules are kept separate and reflect the wording in the original posting.

About the Role

You will own the security compliance and GRC function end to end. You will plan compliance programs, drive FedRAMP authorization activities, coordinate with auditors and regulators, maintain control frameworks and policies, manage risk registers and evidence, support customer assurance, present results to senior stakeholders, improve processes, and lead a Security Compliance Analyst.

Requirements

  • At least 7 years of experience in security compliance GRC or audit
  • End-to-end ownership of audit or certification programs
  • Deep knowledge of PCI DSS SOC 2 ISO 27001 GDPR CCPA and DORA
  • Familiarity with NIST CSF and CIS control frameworks
  • Technical fluency and ability to work with engineering and product stakeholders
  • Excellent written and verbal communication skills
  • Executive-ready documentation skills
  • Experience in fast-paced high-growth environments
  • Fintech or payments experience preferred
  • Ability to work as a leader partner and individual contributor
  • Ability to travel as needed
  • Experience leading mentoring or managing others
  • Direct PCI DSS Level 1 service provider experience preferred
  • Hands-on DORA experience preferred
  • Familiarity with GRC tools Vanta Rippling and macOS

Responsibilities

  • Own compliance planning and programs across SOC 2 Type II PCI DSS ISO 27001 GDPR CCPA and DORA
  • Drive FedRAMP authorization activities and NIST SP 800-53 control implementation
  • Coordinate audits reviews and regulatory engagements
  • Present objectives scope results and control gaps to senior management and the board
  • Maintain the control framework and security policy library
  • Own the risk register risk quantification and reporting cadence
  • Manage customer security questionnaires attestations and trust artifacts
  • Coordinate evidence scans and compliance artifacts
  • Lead process improvements based on findings and assessments
  • Build technical and product fluency for control and risk decisions
  • Identify streamlining and automation opportunities
  • Produce executive-ready documentation presentations and meetings
  • Lead mentor and develop the Security Compliance Analyst

Benefits

  • Equity compensation
  • Early exercise for all options including pre-vested options
  • Remote-first work culture
  • Flexible paid time off
  • Year-end break
  • Health insurance dental and vision coverage for employees and dependents in the US and Canada
  • 4% 401k or RRSP matching in the US and Canada
  • MacBook Pro
  • One-time home office setup stipend
  • Monthly meal stipend
  • Monthly social meet-up stipend
  • Annual health and wellness stipend
  • Annual learning stipend