Security and Compliance Manager
London • FullTime
Posted 6mo ago
About the job
Sierra is building a platform to enable companies to create better, more human customer experiences with AI. We are a primarily in-person company based in San Francisco, with growing offices globally. Our co-founders have extensive experience from leading tech companies like Salesforce, Facebook, and Google. We are seeking a Security and Compliance Manager to act as a primary point of accountability for customer trust enablement, contributing to AI governance, and ensuring security and compliance requirements are embedded into our product and operations.
Responsibilities
- Act as the primary point of accountability for customer trust enablement, including customer meetings, security reviews, and AI governance.
- Contribute to AI Governance by building guardrails aligned with AI regulations (EU AI Act, ISO 42001, NIST AI RMF, and local EU laws).
- Partner with Legal and Privacy to interpret regulatory requirements and support complex, security-sensitive contractual discussions.
- Collaborate with Engineering and Product to ensure security and compliance expectations are reflected in system design and operational effectiveness.
- Translate regulatory and privacy expectations into scalable, region-aware technical controls for model governance, agent security and safety, and data handling.
- Own and evolve customer-facing trust materials and narratives related to AI, privacy, and security.
- Represent Sierra in customer audits and formal assessments, explaining security posture, governance decisions, and risk management approaches.
- Support resilience and response expectations as part of broader governance, focusing on learning and continuous improvement.
- Continuously improve trust by identifying opportunities to streamline workflows, increase automation, and improve signal quality.
Requirements
- 8+ years of experience in security compliance, privacy, or regulatory roles in SaaS, fintech, or AI companies.
- Deep experience with EU regulatory frameworks (GDPR, DORA, EU AI Act) and awareness of US and APAC regulatory norms.
- Demonstrated ability to operate globally, understanding where requirements must diverge and where alignment is possible.
- Experience engaging directly with enterprise and regulated customers as a trusted representative of security, privacy, and compliance.
- Ability to translate abstract or evolving regulatory requirements into defensible, real-world practices.
- Comfort operating in ambiguity, making reasoned judgment calls, and clearly articulating rationale and tradeoffs.
- Strong written and verbal communication skills, including close collaboration with Legal and external stakeholders.
Benefits
- Flexible (unlimited) paid time off
- Medical, dental, and vision benefits for you and your family
- Life insurance and disability benefits