Manager of Compliance & Risk
- Hiring from
- United States
- Work type
- Remote
- Posted
- Sep 29, 2026
Sembi is seeking a Manager of Compliance & Risk to own our compliance and risk program end to end. Sembi operates seven software brands including TestRail, Xblend, Testmo, Ranorex, Kiuwan, PreEmptive and Hexawise, and our enterprise customers hold us to a rising bar on security, privacy and third-party risk. This role owns Sembi’s audit and certification calendar, strengthens our risk management program, and will select and implement a GRC platform and lead the team that keeps it running. This is a build role, not a maintenance role. You will report to the VP of Operations and work directly with Security, Legal, Engineering and Sales leadership.
Responsibilities
- Own the compliance program for all Sembi brands, including SOC 2 audits, penetration testing, SIG and CAIQ responses and NIST self-assessments.
- Build and operate an enterprise risk management program. Stand up and maintain a risk register, define the assessment methodology, drive remediation with system owners and report risk posture to executive leadership on a quarterly cadence.
- Run third-party risk management. Review and strengthen the vendor assessment and tiering process, onboard and monitor subprocessors and own the ongoing review cycle.
- Lead the selection, implementation and administration of a GRC platform, including control mapping, evidence automation and vendor risk workflows.
- Own customer assurance. Oversee security questionnaires and compliance agreement requests against response SLAs, maintain our Vanta trust centers and build reusable artifacts that cut reactive work.
- Maintain our policy set and control framework against GDPR, CCPA, DORA, NIS2, HIPAA and the EU AI Act, and finalize and operationalize our AI governance policies.
- Handle data subject rights requests, deletion requests and DPA execution in partnership with Legal.
- Lead and develop the compliance team. Set priorities, define ownership and mature the function.
- Support incident response and post-incident compliance obligations alongside Security.
Skills and experience
- 7+ years in compliance, governance or risk within SaaS or technology, including 2+ years leading a program or a team.
- Hands-on ownership of SOC 2 Type II audits from scoping through report issuance, ideally across multiple entities or product lines.
- Demonstrated experience building a risk program, a risk register or a third-party risk process where none existed.
- Experience implementing or administering a GRC platform such as Vanta, Drata, AuditBoard or OneTrust. Full implementation ownership is strongly preferred.
- Working knowledge of ISO 27001, NIST and SOC 2 control frameworks, plus practical fluency in GDPR and US state privacy law.
- Familiarity with AI governance obligations and emerging requirements including the EU AI Act.
- Experience answering enterprise customer security and privacy diligence, and comfort engaging directly with customer security teams.
- Strong cross-functional operator. You can drive remediation through engineering and product teams you do not manage.
- Strong written and verbal communication skills, with the ability to manage multiple workstreams, prioritize effectively, and solve problems in a fast-moving environment.
- CISSP, CISA, CRISC or IAPP certifications preferred, not required.
An Equal Opportunity Employer - All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
By submitting your application, you acknowledge that Sembi, Inc. will process and retain your resume and related personal information solely for recruitment and hiring purposes. Resumes of unsuccessful candidates will be securely deleted within twelve (12) months of the hiring decision, unless a longer period is required by law or you provide explicit consent for continued retention (e.g., for consideration for future opportunities).
In compliance with applicable privacy laws, including the EU General Data Protection Regulation (GDPR), you have the right to request access to, correction of, or deletion of your personal information at any time by contacting compliance@sembi.com. Sembi, Inc. does not sell candidate data and will ensure that all personal information is processed securely and in accordance with relevant data protection regulations.