Compliance Manager

 

Description:

As our first dedicated Governance, Risk & Compliance Manager, you'll own the GRC framework end to end. This is the person who turns security from a checkbox into a competitive advantage building the continuous compliance posture that shortens enterprise sales cycles, unlocks larger contracts, and prepares us for stricter regulatory oversight and future liquidity events.

You'll operate as a senior individual contributor with broad ownership: designing controls, running audits inhouse, standing up vendor risk governance, and giving leadership real visibility into risk. You know how to build scrappy but compliant processes at a startup and how to mature them toward enterprise standards and you know the difference.

What You’ll Do
 

  • Own the GRC framework. Design, implement, and continuously test a unified controls framework, including IT General Controls (ITGCs), across a growing regulatory landscape.
  • Run audits inhouse. Maintain and mature our SOC 2 Type II and ISO 27001 certifications, driving toward automated, continuous evidence collection instead of manual scramble before audit cycles.
  • Build the SOX roadmap. Design and test internal controls over financial reporting (ICFR) and ITGCs aligned to AICPA / PCAOB standards, delivering a gap analysis and remediation roadmap that keeps us futureready.
  • Stand up vendor & third party risk. Replace manual, adhoc vendor reviews with an automated, enterprise grade third party risk program built for a complex SaaS ecosystem.
  • Operationalize a risk register. Run formal, continuous internal risk assessments, map them to a corporate risk register, and review it quarterly with leadership to prioritize security spend.
  • Enable the business. Build and maintain a centralized Trust Center that cuts the time sales and engineering spend answering security questionnaires.
  • Shift compliance left. Partner with engineering to embed compliance into the development lifecycle so new features ship without breaking existing controls.
  • Optimize the policy program. Maintain a policy suite that satisfies legal and security requirements while minimizing overhead on the teams that support our growth.
     

Who You Are

Required Qualifications
 

  • 5–8+ years in Information Security, IT Audit, or GRC.
  • Hands-on has experience designing, implementing, and defending controls for SOC 2 Type II, ISO 27001, SOX, and/or PCI DSS.
  • Strong working knowledge of SarbanesOxley compliance, including evidence preparation to AICPA or PCAOB standards.
  • A track record spanning both fast-paced Series B/C startups and a mature enterprise or Big 4 audit environment: you've built processes from scratch and you've seen what "good" looks like at scale.
  • Comfortably operates as a hands-on owner, not just a program overseer.
     

Preferred Qualifications
 

  • Experience with APIdriven / continuous GRC tooling (e.g., Vanta, Drata, or similar).
  • Exposure to cloud or GPU infrastructure security.
  • Relevant certifications (CISA, CISSP, CRISC, ISO 27001 Lead Auditor/Implementer).
  • Experience embedding compliance into CI/CD pipelines.

Organization Nexus Venture Partners
Industry Management Jobs
Occupational Category Compliance Manager
Job Location Dubai,UAE
Shift Type Morning
Job Type Full Time
Gender No Preference
Career Level Experienced Professional
Experience 5 Years
Posted at 2026-07-31 9:03 pm
Expires on 2026-10-29