Compliance Manager [IC3]
Sourcegraph · Legal · Senior · Today · Checked today
Anyone, anywhere in the world can apply.
Direct from the employer's own careers page
Who can apply
Read straight from the listing, so you know before you spend time on it.
Anyone, anywhere in the world can apply.
“While we hire almost anywhere in the world, we have a preference for someone to reside in the following locations for this role. However, if you feel qualified, we welcome you to apply regardless of location.”
Globally distributed team requiring at least 20 hours per week of working hours overlap with GMT-3.
- Async-first
- The listing doesn't promise async-first working.
- Contractor / B2B
- No mention of hiring international contractors or invoicing.
- Global stipend
- No home office or equipment budget mentioned.
- Annual retreat
- No company-paid get-togethers mentioned.
Read from the listing automatically. Always confirm the details with the company before you accept an offer.
About the role
As Compliance Manager, you will independently run Sourcegraph's governance, risk, and compliance initiatives, with an emphasis on owning certifications such as SOC 2 and ISO 27001 end to end. You will tailor controls, gather evidence, interact directly with external auditors, update policies and risk registers, and collaborate closely across Engineering, Security, IT, Legal, and Sales.
What you'll do
- Own and evolve Sourcegraph's ongoing SOC 2 and ISO 27001 compliance and certification programs.
- Manage external audits end to end, including evidence collection, control testing, and remediation.
- Maintain the company's risk register, ISMS processes, policies, and compliance documentation.
- Guide internal teams on compliance obligations and assist Sales with customer security questionnaires.
- Introduce automation, AI, and process improvements to reduce manual compliance effort.
What you bring
- 5+ years of experience in GRC, information security compliance, or a related discipline.
- Demonstrated end-to-end ownership of SOC 2 and ISO 27001 programs in a SaaS or fast-moving tech environment.
- Proven experience personally managing external audits and driving remediation with technical stakeholders.
- Familiarity with cloud-based technology environments and security practices in remote/distributed teams.
- Strong project management, control design, and risk management capabilities.
About Sourcegraph
Sourcegraph provides the context layer and developer tooling to understand, oversee, and evolve complex codebases at scale.
View Sourcegraph profile & open roles →