Full-Time

Principal Security & Compliance Advisor

Outpost

Pliancy

Pliancy

51-200 employees

Provides IT services for Capital Management and Life Sciences

Compensation Overview

$150k - $180k/yr

+ Stock Options

Remote in USA

Remote

Fully remote, US-based role; occasional travel to client sites may be required.

Category
Legal & Compliance (1)
Required Skills
Vulnerability Analysis
SOC 2
Risk Management

Get referred to Pliancy

See people who can refer or advise you

Requirements
  • 5+ years of experience in security, compliance, GRC, vCISO, security consulting, advisory, MSP/MSSP, or a comparable client-facing security role.
  • Strong working knowledge of security and compliance domains such as governance, risk management, control assessments, access controls, audit readiness, vendor risk, incident response, vulnerability management, business continuity, and data protection.
  • Experience advising executives or senior operators on security and compliance decisions.
  • Experience translating frameworks, audit requirements, regulatory expectations, or emerging technology risks into practical workstreams.
  • Familiarity with frameworks and standards such as ISO 27001, NIST CSF, NIST 800-53, CIS Controls, CCPA, GDPR, and HIPAA.
  • Comfort working with finance, investment management, venture capital, private equity, hedge fund, family office, startup, technology, or biotech clients.
  • Comfort advising clients on responsible AI usage, including secure adoption, acceptable use, data protection, vendor review, employee enablement, and business-process implications.
  • Ability to communicate clearly with both technical and non-technical audiences.
  • Strong client-service instincts, including follow-up, follow-through, responsiveness, expectation-setting, and good judgment under pressure.
  • Ability and willingness to properly document processes, decisions, risks, controls, assets, and recommendations.
  • A practical understanding of common security tooling categories, including IAM, MDM, EDR/XDR, MDR, SIEM, vulnerability management, backup and recovery, compliance automation, and security awareness platforms.
  • A practical understanding of how AI tools are being adopted inside modern businesses, including common risks around sensitive data, access, vendor terms, employee usage, workflow design, and governance.
  • Demonstrated ability to learn new technologies, client environments, and business contexts quickly.
  • A sense of ownership and pride in your work.
  • A team-centric mentality, with a focus on collaboration, communication, documentation, improving processes, and succeeding together.
  • Authorization to work in the United States for any employer.
Responsibilities
  • Serve as a senior security and compliance advisor for Outpost clients, with an emphasis on finance firms, including VC, PE, hedge funds, family offices, both ERAs and RIAs, and other investment firms, as well as select technology and biotech startups.
  • Lead consultative client conversations around governance, risk, controls, compliance readiness, secure AI adoption, security roadmaps, vendor selection, audit preparation, DDQs, cybersecurity insurance, incident preparedness, and operational workflows.
  • Translate client business objectives into practical security and compliance action plans that are clear, prioritized, and realistic.
  • Help clients understand, evaluate, and securely adopt AI tools, including usage policies, data handling expectations, vendor risk considerations, access controls, employee guidance, and practical governance models.
  • Help design, document, and continuously improve Outpost’s service delivery playbooks, templates, project plans, assessment methods, and client-facing deliverables.
  • Deliver leadership-level roadmapping and project ownership across ongoing client engagements.
  • Support clients working toward or maintaining compliance with frameworks and requirements such as SOC 2, ISO 27001, NIST CSF, CIS Controls, CCPA, GDPR, HIPAA-adjacent requirements, and other relevant security or privacy obligations.
  • Assess and improve client processes such as onboarding, offboarding, access reviews, vendor risk management, business continuity, disaster recovery, incident response, policy management, and control monitoring.
  • Advise on and help implement systems and tools across categories such as compliance automation, identity and access management, endpoint security, MDR, SIEM, vulnerability management, MDM, backup and recovery, AI productivity platforms, and security awareness.
  • Partner with Pliancy teams to connect security and compliance recommendations to the underlying IT systems, workflows, and support model required to make them stick.
  • Create high-quality internal and client-facing documentation that improves clarity, repeatability, and client experience.
  • Share market observations, client feedback, recurring pain points, and delivery lessons with Outpost leadership to help productize the offering.
  • Help shape future hiring, operating processes, and service standards as Outpost grows.
Desired Qualifications
  • Experience supporting SEC-regulated investment advisers, Exempt Reporting Advisers, Registered Investment Advisers, private fund managers, broker-dealer-adjacent environments, or other financial services organizations.
  • Experience with compliance automation platforms such as Drata, Vanta, Secureframe, Tugboat Logic, or similar tools.
  • Experience developing AI acceptable-use policies, AI governance models, secure AI adoption plans, vendor review processes, or employee enablement materials.
  • Experience with MDR, SIEM, vulnerability management, BCDR, cyber insurance, TPRM, penetration testing coordination, or incident response planning.
  • Certifications such as CISSP, CISM, CISA, CCSP, CRISC, GIAC, or equivalent practical experience.
  • Experience building or scaling a service delivery model, advisory practice, managed service, or productized consulting offering.
  • Experience creating client-ready templates, assessment methods, roadmaps, policy libraries, or implementation playbooks.
  • Familiarity with scripting, automation, APIs, or lightweight technical implementation work.
  • Experience in MSP, MSSP, professional services, consulting, or high-touch client service environments.

Pliancy offers people-centric IT services, specializing in email, file management, identity management, security, and reporting for emerging companies. The company leverages cutting-edge technology to ensure scalable, secure, and user-friendly IT operations, catering to Capital Management and Life Sciences organizations across multiple locations.

Company Size

51-200

Company Stage

N/A

Total Funding

N/A

Headquarters

San Francisco, California

Founded

2016

Get referred to Pliancy

See people who can refer or advise you