Security & Compliance Manager
Remote
OTHER POSSIBLE TITLES
Compliance & Risk Manager · GRC Manager · Information Security & Compliance Manager · Head of Security & Compliance · Senior Compliance Manager
Role Mission
Build the foundation. Own the framework. Make compliance a competitive advantage.
harpin AI is transitioning from a managed security services model to a fully in-house GRC program. This role exists to lead that transition and make it permanent. The Security & Compliance Manager absorbs the operational complexity, runs the Vanta platform with intention, and ensures that harpin’s pursuit of SOC 2 Type II, ISO 27001, and ISO 42001 stays on track toward a Q4 2026 certification target. This is not a checkbox role. It is the person who builds the muscle that lets harpin sell into enterprise accounts in hospitality/travel and expand into other verticals with confidence — and who makes the Trust Center the thing that closes deals, not delays them.
About harpin AI
harpin AI is a patented, data science-driven platform generating more than $100 million in incremental revenue for clients today, while deploying next-generation service tools that enhance what happens on the contact center floor every single day. We are not a dashboard. We are not another point solution. We are not an LLM wrapper. We are the intelligence layer that sits above every system a contact center already runs and connects the signals none of those systems can see on their own.
Enterprise contact centers are running multiple disconnected AI tools simultaneously. Each produces signal in isolation. harpin synthesizes all of it — from quality scores and WFM actuals to NPS, CRM history, chatbot data, and marketing signals — into a Customer Intelligence Operating System that drives operational performance, financial outcomes, and a closed marketing intelligence loop.
We work with a rapidly growing portfolio of Fortune 500 companies, primarily in hospitality and travel, and are expanding rapidly into insurance, banking, and healthcare. The compliance expectations in those verticals are material. The Security & Compliance Manager is the person who makes that expansion trustworthy.
Why this role exists now
harpin AI’s prior managed security services relationship provided external support for GRC operations. That relationship is ending. What it leaves behind is a clear picture of what the program needs: a Vanta platform that is licensed and partially activated, and a compliance program that is structurally sound but operationally underutilized.
The in-house team is already in place. The COO owns executive risk oversight. The Principal AI Reliability & Quality Engineer owns product and engineering security. The interim S&C Program Director (Dir of Finance) provides program governance and policy approval. What the team does not yet have is a dedicated operator who owns the day-to-day compliance engine — the frameworks, the risk register, the policy lifecycle, the vendors, the audits, and the customer-facing compliance posture. In Vanta, not in spreadsheets.
This role is that person and they would be expected to assume the head of the S&C program based on performance success. And as harpin AI expands into other (regulated) verticals, this person becomes a direct contributor to revenue enablement — because enterprise clients only buy from vendors with a strong security & compliance profile who cannot pass a security review.
Core Responsibilities
1. Compliance Framework Execution
harpin AI is SOC 2 Type II compliant (audited) and pursuing ISO 27001, ISO 42001, and GDPR compliance simultaneously. The Compliance & Risk Manager owns the operational layer of all four — managing evidence collection, control testing, audit coordination, and remediation tracking in Vanta.
- Own the Vanta compliance dashboard and keep it current across all active frameworks.
- Coordinate with engineering and governance to ensure technical controls are evidenced and documented.
- Manage external audit relationships and audit request workflow when certification readiness is confirmed.
- Track ISO 27001 and ISO 42001 readiness milestones toward the Q4 2026 certification target.
2. Risk Management
Structured risk management is central to ISO 27001 and enterprise client trust. This role owns the risk register as a living document — not an annual artifact.
- Build and maintain the organizational risk register in Vanta’s risk module.
- Conduct periodic risk assessments across organizational, technical, and vendor domains.
- Present risk status for executive review and board reporting.
- Identify and track treatment plans for open risks: acceptance, mitigation, and transfer decisions.
3. Policy Lifecycle Management
Policies require drafting, review, approval, distribution, and annual refresh. This role owns that entire cycle and Vanta as the management platform.
- Draft, update, and manage the full information security policy library.
- Run the policy approval workflow through Vanta; track acknowledgment across the team.
- Ensure policies remain aligned with framework requirements as controls evolve.
- Flag expiring policies before they lapse; manage version control.
4. Vendor & Third-Party Risk
harpin AI’s enterprise clients expect rigorous vendor management. This role owns the third-party risk program — with Vanta Advanced TPRM as the platform once activated.
- Conduct and document vendor risk assessments for critical and high-risk vendors.
- Manage vendor questionnaire workflows and the vendor inventory in Vanta.
- Flag vendors requiring re-assessment and drive remediation or offboarding decisions.
- Replace the outgoing vendor review function previously managed externally.
5. Trust Center & Customer-Facing Compliance
The Trust Center at security.harpin.ai is an immediate priority. It is the single highest-leverage no-cost action available today — reducing inbound security questionnaire volume and accelerating enterprise sales cycles.
- Build out the Vanta-native Trust Center at security.harpin.ai.
- Populate security program overview, compliance badges, downloadable reports and policy library.
- Configure and manage Vanta Questionnaire Automation for inbound customer security assessments.
- Own turnaround time for customer questionnaire responses; target under 5 business days.
6. Privacy & Data Protection
harpin AI processes customer and contact center data on behalf of enterprise clients across multiple jurisdictions. This role owns the data protection posture.
- Maintain the data processing inventory and Records of Processing Activities (RoPA).
- Conduct and document Data Protection Impact Assessments (DPIAs) for new processing activities.
- Own vendor data processing agreements in collaboration with legal counsel.
- Respond to data subject access requests and privacy inquiries.
7. Security Awareness & Training
Every harpin team member is a participant in the security program. This role selects the platform, runs the campaigns, and tracks completion.
- Select and implement a security awareness training platform.
- Design and deliver the annual training program and new hire onboarding security module.
- Track completion rates; report compliance status to the executive team.
- Run targeted training for high-risk roles and in response to incidents or policy changes.
8. Vanta Platform Operations
Vanta is the GRC platform that runs this program. It is licensed and partially activated. The Compliance & Risk Manager is the primary Vanta operator — not a user, but the person who makes Vanta do its job.
- Manage the daily Vanta task queue: tests, evidence requests, open issues, overdue items.
- Configure and activate underutilized features: Policy Management, Access Reviews, Questionnaire Automation, Slack notifications.
- Coordinate with our Principal Site Reliability Engineer on Access Review and technical test workflows.
- Report Vanta platform health and program posture on a regular cadence.
9. Industry Vertical Expansion
As harpin AI enters other vertical industries, compliance becomes a direct revenue function. Candidates who can walk into a regulated enterprise prospect’s security review without a glossary create measurably more value.
- Develop and maintain compliance profiles for target verticals.
- Identify framework overlaps and gaps relevant to each vertical.
- Support the Sales team with vertical-specific compliance documentation and questionnaire responses.
- Advise on when additional frameworks should be added to the Vanta program scope.
Measurements of Success
The right person for this role is energized by building something that holds. These metrics exist to prove it is happening.
| Category | Primary Metric | Target Outcome |
|---|---|---|
| Certification | ISO 27001 & ISO 42001 Readiness | Program audit-ready by Q3 2026. All controls evidenced, policies approved, risk register current. |
| Framework Coverage | SOC 2 Type II | Continuous evidence collection active; clean report cycle established. |
| Platform Health | Vanta Utilization | All licensed features activated and in use; no chronic overdue items in the task queue. |
| Client Trust | Questionnaire Turnaround | 95%+ of inbound customer questionnaires completed within 5 business days via Vanta Questionnaire Automation. |
| Sales Enablement | Trust Center Live | security.harpin.ai fully built, publicly accessible, and referenced in enterprise sales processes by Q4 2026. |
| Program Integrity | Policy Coverage | 100% of required ISO 27001, ISO 42001 and SOC 2 policies drafted, approved, and acknowledged by all personnel. |
Required Competencies
Non-Negotiable:
- 7–10 years of hands-on experience. GRC, Information Security Compliance, or Information Security Management. You have run compliance programs, not just participated in them. You have been the person responsible for controls, not just the person documenting them for someone else. You know the difference between a program that is defensible and one that is decorated.
- ISO 27001 implementation experience. Led or been a primary contributor — not just audit prep. You have built the program from policy to evidence to certification. Lead auditor or implementer certification (ISO 27001 LA/LI) is a strong signal. Familiarity with the Annex A control set is a baseline expectation, not a differentiator.
- GRC platform fluency. You run compliance in a platform, not a folder. Vanta experience is directly valued. Drata, Tugboat Logic, or similar platforms are transferable. The expectation is that you can configure workflows, manage evidence, and run a task queue — not just read a dashboard.
Strongly Preferred:
- Regulated vertical experience. Insurance, Banking, or Healthcare/HIPAA. harpin AI’s expansion markets have distinct compliance expectations and procurement requirements. Candidates who can engage a CISO at a regional insurer or a healthcare system without a primer will move faster and create more value faster. This is ideally demonstrated, not just claimed.
- Privacy and data protection. GDPR operational experience — not just awareness. CIPP/E or equivalent is a plus. You have managed RoPAs, DPIAs, and data subject requests in a production environment. You understand the practical difference between controller and processor obligations.
- Policy writing. You write clearly. Policies that people actually read. Precision, appropriate scope, no padding. Audit narratives that stand on their own. A portfolio of policy work is a meaningful signal in the hiring process.
- ISO 42001 implementation experience. Led or been a primary contributor — not just audit prep.
Operating Philosophy Fit
harpin AI is not building a compliance program for optics. It is building the infrastructure of enterprise trust — the thing that lets our current and prospective customers say yes without hesitation. The Compliance & Risk Manager has to believe that, because the work is sometimes detailed and unglamorous, and the person doing it has to know why it matters.
The right candidate does not need a large team to make progress. They know how to prioritize, how to use the tools in front of them, and how to distinguish between what a framework genuinely requires and what theater adds. They work in Vanta because it is the most efficient path to a defensible program. They coordinate with key personnel without waiting to be managed.
This is a startup at enterprise scale. Real stakes, real tools, real autonomy. The person who thrives here sees that combination as the right environment — not a warning label.
Location & Structure
- US-based. 100% Remote. harpin AI operates as a distributed team.
- Reports to the interim S&C Program Director (Director of Finance) on day one; reporting line expected to evolve quickly based on progress of success measurements.
- Target start date: August 1, 2026.
- Compensation: Competitive and commensurate with experience. Includes benefits package.