Security Compliance Manager
Auxo | Growth PartnerSecurity Compliance Lead
Location: Remote (Canada)
Salary: 130-180k$
Type: Full-time
Auxo is hiring a Security Compliance Lead for a Series A B2B SaaS company scaling fast in the industrial tech space.
Enterprise customers increasingly require rigorous security reviews before they buy, and the company is also expanding its compliance requirements as its AI-powered platform evolves.
This is the first dedicated hire to own security compliance, privacy and trust end-to-end. You'll take ownership of an existing SOC 2 program, enterprise security reviews, privacy requirements, vendor risk and the roadmap toward additional frameworks.
There is no large GRC team or established playbook. We're looking for someone who has owned these programs before and is comfortable building the function independently.
What You'll Do
- Own SOC 2 Type 2 end-to-end, from controls and evidence through audits and renewal
- Lead enterprise security questionnaires, vendor assessments and customer security reviews
- Build the company's AI governance approach as AI capabilities expand
- Own privacy requirements including Law 25, PIPEDA and GDPR
- Build third-party/vendor risk processes and maintain the company risk register
- Evaluate and lead future frameworks including ISO 27001, ISO 42001, NIST and potentially FedRAMP
- Partner with Engineering to translate compliance requirements into practical technical controls
Who You Are
- 6+ years in security compliance, GRC, IT audit or risk
- You've been the primary owner of a complete SOC 2 Type 2 cycle
- You've delivered another framework such as ISO 27001, NIST 800-53, PCI DSS or similar
- Hands-on with Vanta, Drata, Secureframe or similar
- Experience handling enterprise security questionnaires and customer audits
- Technically fluent enough to work credibly with software/cloud engineers
- Comfortable being the only person in your function and building from scratch
- Strong interest or experience in AI governance is a major plus
Important: This is not a SOC, AppSec or security engineering role. You won't be writing code, running pentests or owning incident response. This role owns compliance, governance, privacy and customer trust.