Security and Compliance Manager
$53k - $800k • San Francisco, CA • FullTime
Posted 7mo ago
About the job
Sierra is a leading platform for customer-facing AI agents, partnering with major global brands to transform customer service and business growth. We are primarily an in-person company based in San Francisco, with expanding offices internationally. Our culture is built on core values of Trust, Customer Obsession, Craftsmanship, Intensity, and a commitment to balancing Family. The company was co-founded by Bret Taylor, former co-CEO of Salesforce and CTO of Facebook, and Clay Bavor, who spent 18 years at Google leading initiatives like Google Labs, AR/VR, and Google Lens.
Responsibilities
- Lead independent audits and regulatory programs (ISO 42001, PCI DSS, NIST 800-53, FedRAMP, HIPAA).
- Manage audit scope, readiness, auditor engagement, remediation, and executive reporting.
- Understand Sierra's AI platform, model providers, and cloud architecture to design and implement controls across multi-cloud environments.
- Develop and maintain a security controls library mapped to compliance and customer requirements, assessing effectiveness and driving remediation.
- Define and enforce security baselines for cloud infrastructure, containers, Kubernetes, identity, encryption, logging, and network security.
- Integrate security requirements into configuration and change management processes.
- Design and operate automated compliance workflows using AI, IaC, and security tooling.
- Act as a strategic partner to Platform, Product, Engineering, Legal, and GTM teams to embed security and compliance into architecture and roadmaps.
Requirements
- 8+ years of experience in security compliance, GRC, or related roles in fast-growing tech companies.
- Deep expertise in security compliance frameworks (ISO 42001, PCI DSS, NIST 800-53, FedRAMP).
- Systems-oriented and engineering-focused GRC mindset, capable of reasoning about cloud architecture and control effectiveness.
- Experience managing complex audits and driving risk-based remediation across distributed teams.
- Hands-on experience with multi-cloud infrastructure (AWS, Azure, GCP).
- Strong experience implementing and automating security controls across cloud infrastructure, configuration management, container security, Kubernetes, encryption, and identity systems.
- Ability to clearly communicate compliance requirements to engineering teams and customers.
- Relevant certifications (CISSP, CISA, PCI ISA, ISO 27001 Lead Auditor) or equivalent experience.
- Experience supporting AI platforms, fintech, healthcare, or highly regulated environments is a plus.
- Familiarity with global regulatory environments (GDPR, DORA, EU AI Act) and emerging AI governance requirements is a plus.
- Experience supporting public sector or FedRAMP-aligned environments is a plus.