Sierra - Security and Compliance Manager
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT
Requirements
• At least 8+ years of experience in security compliance or governance risk and control (GRC) roles within fast growing technology companies. • Deep expertise in specific security compliance frameworks including ISO 42001, PCI DSS, NIST 800-53, FedRAMP, HIPAA, and related regulatory environments. • A systems oriented and engineering focused GRC mindset with experience partnering across multi cloud environments, infrastructure, inference and data platforms to design and operationalize controls. • Experience in developing a centralized security controls library mapped to compliance, regulatory, and customer requirements while continuously assessing control effectiveness, identifying gaps, prioritizing risk, and driving remediation efforts that strengthen the organization's security posture. • Ability to define and enforce security baselines for various aspects of cloud infrastructure such as containerized workloads, Kubernetes, identity management, encryption, logging, and network security controls while integrating these requirements into configuration and change management processes with engineering teams. • Experience in designing and operating automated compliance workflows using AI, infrastructure as code (IaC), and security tooling to reduce manual effort, improve control assurance, and scale with platform evolution.
Responsibilities
• Oversee security protocol implementation within company operations to ensure compliance with industry standards and regulations. • Develop comprehensive risk assessment strategies for the organization's data assets and information systems. • Collaborate closely with IT department, management team, and other stakeholders on cybersecurity initiatives and policies. • Monitor security news and trends to stay informed about emerging threats and vulnerabilities relevant to Sierra’s industry sector. • Conduct regular audits of the company's information systems for potential risks or non-compliance issues, documenting findings in detailed reports with recommendations for improvement. • Develop security awareness programs tailored to different levels within the organization and regularly update them based on evolving threats. • Review and approve access control policies ensuring that employees have appropriate level of access necessary for their roles while maintaining strict data privacy standards. • Manage incident response plans, coordinating with IT team during security breaches or incidents to mitigate impacts effectively. • Provide guidance on best practices in password management and multi-factor authentication methods across the organization. • Lead training sessions for employees about cybersecurity awareness including phishing prevention techniques and secure internet browsing habits.
Benefits
• $170K – $250K • Offers Equity • At Sierra, we’re creating a platform to help businesses build better, more human customer experiences with AI. We are primarily an in-person company based in San Francisco, with growing offices in Atlanta, New York, London, France, Singapore, and Japan. • We are guided by a set of values that are at the core of our actions and define our culture: Trust, Customer Obsession, Craftsmanship, Intensity, and Family. These values are the foundation of our work, and we are committed to upholding them in everything we do. • Our co-founders are Bret Taylor and Clay Bavor. Bret currently serves as Board Chair of OpenAI. Previously, he was co-CEO of Salesforce (which had acquired the company he founded, Quip) and CTO of Facebook. Bret was also one of Google's earliest product managers and co-creator of Google Maps. Before founding Sierra, Clay spent 18 years at Google, where he most recently led Google Labs. Earlier, he started and led Google’s AR/VR effort, Project Starline, and Google Lens. Before that, Clay led the product and design teams for Google Workspace. • You will operate at the center of AI systems, cloud infrastructure, and global compliance, shaping how security controls are designed and scaled for modern AI platforms. This role offers high ownership, deep technical partnership with engineering, and the opportunity to define what strong GRC looks like at Sierra. • Our values • Our values • Trust: We build trust with our customers with our accountability, empathy, quality, and responsiveness. We build trust in AI by making it more accessible, safe, and useful. We build trust with each other by showing up for each other professionally and personally, creating an environment that enables all of us to do our best work. • Trust: • Customer Obsession: We deeply understand our customers’ business goals and relentlessly focus on driving outcomes, not just technical milestones. Everyone at the company knows and spends time with our customers. When our customer is having an issue, we drop everything and fix it. • Customer Obsession: • Craftsmanship: We get the details right, from the words on the page to the system architecture. We have good taste. When we notice something isn’t right, we take the time to fix it. We are proud of the products we produce. We continuously self-reflect to continuously self-improve. • Craftsmanship: • Intensity: We know we don’t have the luxury of patience. We play to win. We care about our product being the best, and when it isn’t, we fix it. When we fail, we talk about it openly and without blame so we succeed the next time. • Intensity: • Family: We know that balance and intensity are compatible, and we model it in our actions and processes. We are the best technology company for parents. We support and respect each other and celebrate each other’s personal and professional achievements. • Family: • We want our benefits to reflect our values and offer the following to full-time employees: • Flexible (Unlimited) Paid Time Off • Medical, Dental, and Vision benefits for you and your family • Retirement Plan (e.g., 401K, pension) with Sierra match • Fertility and family building benefits through Carrot • Lunch, as well as delicious snacks and coffee to keep you energized • Discretionary Benefit Stipend giving people the ability to spend where it matters most • Free alphorn lessons • These benefits are further detailed in Sierra's policies and are subject to change at any time, consistent with the terms of any applicable compensation or benefits plans. Eligible full-time employees can participate in Sierra's equity plans subject to the terms of the applicable plans and policies. • Be you, with us • Be you, with us
No credit card. Takes 10 seconds.