Security and Compliance Manager

Sierra Sierra · AI Frontier · San Francisco, CA · Compliance

This role focuses on managing security and compliance for an AI platform, ensuring adherence to various regulatory frameworks like ISO 42001, PCI DSS, NIST 800-53, FedRAMP, and HIPAA. The manager will partner with engineering teams to operationalize controls, define security baselines, and automate compliance workflows using AI and infrastructure as code. While the role interacts with AI systems and uses AI for automation, its core function is security and compliance management, not direct AI/ML model development or research.

What you'd actually do

  1. Own independent audits and regulatory programs including ISO 42001, PCI DSS, NIST 800-53, FedRAMP, HIPAA, and related frameworks.
  2. Drive scope definition, readiness assessments, auditor engagement, remediation planning, and executive level reporting.
  3. Develop a strong working understanding of Sierra’s Conversational AI Platform, model providers, and cloud architecture. Partner with Platform and Agent Engineering to design and operationalize controls across multi cloud environments, infrastructure, inference and data platforms.
  4. Build a centralized and evolving security controls library mapped to compliance, regulatory and customer requirements. Continuously assess control effectiveness, identify gaps, prioritize risk, and drive remediation that strengthens Sierra’s security and compliance posture.
  5. Define and enforce security baselines for cloud infrastructure, containerized workloads, Kubernetes, identity, encryption, logging, and network security controls. Partner with engineering teams to integrate security requirements into configuration and change management.

Skills

Required

  • 8+ years of experience in security compliance or GRC or security adjacent roles
  • Deep expertise in security compliance frameworks including ISO 42001, PCI DSS, NIST 800-53, FedRAMP, and similar regulatory environments.
  • A systems oriented and engineering focused GRC mindset
  • Experience owning complex audits and driving risk based remediation across distributed teams.
  • Hands-on experience with multi-cloud infrastructure (AWS, Azure, GCP).
  • Strong experience implementing and automating security controls across cloud infrastructure, configuration management, container security, Kubernetes, encryption, identity, and authentication systems.
  • Ability to clearly communicate compliance requirements internally to engineering teams and externally to customers in a technically credible way.
  • Relevant certifications such as CISSP, CISA, PCI ISA, ISO 27001 Lead Auditor, or equivalent experience.

Nice to have

  • Experience supporting AI platforms, fintech, healthcare, or other highly regulated environments.
  • Familiarity with global regulatory environments including GDPR, DORA, the EU AI Act, and emerging security and AI governance requirements across APAC regions.
  • Experience supporting public sector or FedRAMP aligned environments.

What the JD emphasized

  • ISO 42001
  • PCI DSS
  • NIST 800-53
  • FedRAMP
  • HIPAA
  • security compliance frameworks
  • regulatory environments
  • AI Platform
  • cloud architecture
  • multi cloud environments
  • infrastructure
  • inference
  • data platforms
  • security controls library
  • compliance
  • regulatory
  • customer requirements
  • security posture
  • cloud infrastructure
  • containerized workloads
  • Kubernetes
  • identity
  • encryption
  • logging
  • network security controls
  • configuration management
  • automated compliance workflows
  • AI
  • infrastructure as code
  • security tooling
  • platform evolution
  • security compliance
  • GRC
  • cloud architecture
  • data flows
  • control effectiveness
  • multi-cloud infrastructure
  • cloud infrastructure
  • configuration management
  • container security
  • Kubernetes
  • encryption
  • identity
  • authentication systems
  • AI platforms
  • fintech
  • healthcare
  • highly regulated environments
  • global regulatory environments
  • GDPR
  • DORA
  • EU AI Act
  • security and AI governance requirements
  • APAC regions
  • public sector
  • FedRAMP aligned environments
  • AI systems
  • cloud infrastructure
  • global compliance
  • GRC