Risk and Compliance Lead
Remote • Foster City, CA • FullTime
Posted 20d ago
Job Location
Foster City, CA
Remote Work Policy
Fully remote
Employment Type
FullTime
Categories
Applied AI Engineer
About the job
Replit is seeking a Risk & Compliance Lead to build and scale the security GRC function for an AI-native product. This role will own the company's certification and audit program, including SOC 2, ISO 27001, and ISO 42001. You will also be responsible for the master security risk register and continuous compliance monitoring. Reporting to the Head of Security GRC, you will collaborate closely with Engineering to ensure controls are effective in practice.
Responsibilities
- Own the end-to-end certification roadmap (SOC 2 Type II, ISO 27001, ISO 42001), including scoping, gap assessments, remediation, and audit execution.
- Manage relationships with external auditors and drive the annual audit calendar for timely certification renewals.
- Own and maintain the company's master security risk register, including risk identification, scoring, treatment plans, and residual risk reporting.
- Build and maintain continuous compliance monitoring for real-time control status.
- Own core audit artifacts such as ISMS documentation, Statements of Applicability, risk assessments, and potentially FedRAMP System Security Plans.
- Run regular audits and readiness assessments, and track remediation of findings and control gaps to closure.
- Support GDPR and broader privacy compliance in partnership with the Legal/Privacy team.
- Partner with the GRC Engineer to define automation for evidence collection and control monitoring.
- Track and report on compliance posture and audit findings to security leadership.
Requirements
- 8+ years in security compliance, IT audit, or GRC roles, with direct ownership of at least one SOC 2 and/or ISO 27001 certification cycle.
- Working knowledge of common frameworks (SOC 2, ISO 27001, NIST CSF) and control mapping.
- Hands-on experience authoring or substantially maintaining an ISMS, SSP, or equivalent audit-facing documentation.
- Experience owning a formal risk register including risk identification, scoring methodology, treatment plans, and residual risk reporting.
- Experience with GRC/compliance automation platforms (e.g., Anecdotes, Vanta, Drata) and continuous control monitoring.
- Experience working directly with external auditors and managing an audit end to end.
- Comfortable reading technical control evidence and discussing system functionality with engineers.
- Working familiarity with GDPR/privacy fundamentals to partner effectively with legal.
Benefits
- Competitive Salary & Equity
- 401(k) Program with a 4% match (US Only)
- Health, Dental, Vision and Life Insurance
- Short Term and Long Term Disability
- Paid Parental, Medical, Caregiver Leave
- Flexible Time Off (FTO) + Holidays
- Commuter Benefits (In-Office Only)
- Monthly Wellness Stipend
- Autonomous Work Environment
- In Office Set-Up Reimbursement (In-Office Only)
- Quarterly Team Gatherings
- In Office Amenities (In-Office Only)