← All roles
S

Compliance Manager [IC3]

Sourcegraph · Legal · Senior · Today · Checked today

✓

Anyone, anywhere in the world can apply.

WorldwideAny timezoneSOC 2ISO 27001GRCInformation Security

Direct from the employer's own careers page

Who can apply

Read straight from the listing, so you know before you spend time on it.

Anywhere in the world

Anyone, anywhere in the world can apply.

“While we hire almost anywhere in the world, we have a preference for someone to reside in the following locations for this role. However, if you feel qualified, we welcome you to apply regardless of location.”

Globally distributed team requiring at least 20 hours per week of working hours overlap with GMT-3.

Async-first
The listing doesn't promise async-first working.
Contractor / B2B
No mention of hiring international contractors or invoicing.
Global stipend
No home office or equipment budget mentioned.
Annual retreat
No company-paid get-togethers mentioned.

Read from the listing automatically. Always confirm the details with the company before you accept an offer.

About the role

As Compliance Manager, you will independently run Sourcegraph's governance, risk, and compliance initiatives, with an emphasis on owning certifications such as SOC 2 and ISO 27001 end to end. You will tailor controls, gather evidence, interact directly with external auditors, update policies and risk registers, and collaborate closely across Engineering, Security, IT, Legal, and Sales.

What you'll do

  • Own and evolve Sourcegraph's ongoing SOC 2 and ISO 27001 compliance and certification programs.
  • Manage external audits end to end, including evidence collection, control testing, and remediation.
  • Maintain the company's risk register, ISMS processes, policies, and compliance documentation.
  • Guide internal teams on compliance obligations and assist Sales with customer security questionnaires.
  • Introduce automation, AI, and process improvements to reduce manual compliance effort.

What you bring

  • 5+ years of experience in GRC, information security compliance, or a related discipline.
  • Demonstrated end-to-end ownership of SOC 2 and ISO 27001 programs in a SaaS or fast-moving tech environment.
  • Proven experience personally managing external audits and driving remediation with technical stakeholders.
  • Familiarity with cloud-based technology environments and security practices in remote/distributed teams.
  • Strong project management, control design, and risk management capabilities.

About Sourcegraph

Sourcegraph provides the context layer and developer tooling to understand, oversee, and evolve complex codebases at scale.

View Sourcegraph profile & open roles →

Get job alerts for new verified roles. No account needed.

Unsubscribe any time. See our Privacy Policy.