Full-Time

Lead Compliance Manager

Confirmed live in the last 24 hours

Snyk

Snyk

1,001-5,000 employees

Cybersecurity for open source software vulnerabilities

Enterprise Software
Cybersecurity

Senior, Expert

Boston, MA, USA + 1 more

More locations: Ottawa, ON, Canada

Category
Risk & Compliance
Legal & Compliance
Requirements
  • 8+ total years of experience in GRC roles, including 3+ years of experience in Lead or Senior Governance, Risk & Compliance related roles.
  • A proven track record of successful compliance program implementation and management, preferably in continuous compliance environments.
  • Good industry knowledge of compliance and security best practices and frameworks.
  • Experience working in technical and developer focused organizations and SaaS industry.
  • Exceptional communication and interpersonal skills and fundamentally believe in the importance of using compliance to enable business as well as protect it.
  • Ability to formulate recommendations for Senior Leaders.
  • Excellent analytical and problem-solving skills.
  • Knowledge of cloud security and infrastructure.
  • CISA or CISSP certification would be advantageous.
Responsibilities
  • Leading compliance program enablement and operations in support to the Senior Director of Risk, Compliance & Trust, including program design, implementation, and ongoing maintenance.
  • Evaluating internal compliance against required framework controls to identify known gaps in compliance.
  • Communicating found gaps in controls to peers, key stakeholders and leadership.
  • Developing plans and overseeing projects for treatment of compliance gaps, including working cross-functionally to hold stakeholders at all levels accountable to project objectives and timelines, while supporting the company's overall improvement initiatives.
  • Developing and providing effective reporting mechanisms and visibility of project status to support ongoing analysis and decision-making.
  • Promoting a culture of continuous improvement by providing training and guidance to employees on aspects of security and compliance where appropriate.
  • Contributing to the development of the other GRC team members through cross-training and ongoing communications.
  • Acting as an internal advisor / consultant, subject matter expert, and compliance advocate through the alignment of GRC activities with the overall company-wide goals and objectives.

Snyk specializes in cybersecurity for software-driven businesses, focusing on open source security. Its platform helps developers identify and fix vulnerabilities in their code by integrating into existing workflows, offering tools like a dependency scanner for open source dependencies and container images. Snyk differentiates itself by serving a wide range of clients, from startups to large enterprises, with tailored enterprise features. The goal is to enable organizations to develop software quickly while ensuring high security standards.

Company Stage

N/A

Total Funding

$1.5B

Headquarters

Boston, Massachusetts

Founded

2015

Growth & Insights
Headcount

6 month growth

2%

1 year growth

8%

2 year growth

0%
Simplify Jobs

Simplify's Take

What believers are saying

  • Snyk's recent $1.2 billion funding round underscores strong investor confidence and provides substantial capital for growth and innovation.
  • The acquisition of Helios and Enso Security enhances Snyk's platform with advanced runtime visibility and remediation capabilities, making it a more comprehensive security solution.
  • Snyk's leadership in developer security and its proactive approach to addressing vulnerabilities in Docker and Kubernetes position it as a key player in the cybersecurity landscape.

What critics are saying

  • The rapid pace of acquisitions, such as Helios and Enso Security, may lead to integration challenges and potential disruptions.
  • High-profile executive departures, like the recent exit of the Chief Marketing Officer, could signal internal instability and affect company morale.

What makes Snyk unique

  • Snyk's seamless integration with existing development workflows allows developers to maintain security without sacrificing speed, a critical advantage over competitors.
  • The company's focus on open source security and containerized applications addresses a niche but rapidly growing market, setting it apart from broader cybersecurity firms.
  • Snyk's subscription-based model with tiered pricing and premium features provides flexibility and scalability for clients of all sizes, from startups to large enterprises.

Help us improve and share your feedback! Did you find this helpful?