Senior Compliance Manager

Harvey Harvey · AI Frontier · San Francisco, CA · Security

This role is for a Senior Compliance Manager at Harvey, an AI company transforming legal and professional services. The manager will own end-to-end compliance programs, focusing on establishing and scaling certifications and compliance programs for expansion into regulated markets. Responsibilities include building business cases, leading gap assessments, managing third-party assessors, driving audit readiness, supporting customer reviews, and building/leading a team. The role requires significant experience in information security and compliance for commercial SaaS/PaaS, cross-functional influence, and experience with AI tools for program efficiency. The company emphasizes rapid scaling, customer trust, and a strong mission.

What you'd actually do

  1. Build the business case and strategic roadmap for compliance investments, articulating ROI, certification sequencing, and market opportunity to leadership
  2. Lead gap assessments and compliance readiness evaluations across applicable frameworks, producing maturity baselines and prioritized remediation roadmaps
  3. Select, onboard, and manage third-party assessors and compliance advisors; hold partners accountable to timelines and escalate risks early
  4. Drive audit readiness — coordinating evidence collection, continuous monitoring, and audit documentation management with Engineering and Security
  5. Support customer security reviews, RFP responses, and due diligence conversations as the authoritative internal voice on Harvey's compliance posture
  6. Build and lead a small team: hire, set direction, develop members, and scale program operations as Harvey's footprint grows

Skills

Required

  • 10+ years in information security or compliance
  • 5+ years leading compliance programs for commercial SaaS or PaaS
  • Deep command of the compliance lifecycle (scoping, gap analysis, control documentation, assessment coordination, continuous monitoring)
  • Proven cross-functional influence at the senior level
  • Track record selecting and managing third-party assessors and compliance advisory firms
  • Experience building and leading small teams
  • Experience with AI tools for program efficiency

Nice to have

  • Experience in regulated markets

What the JD emphasized

  • compliance programs critical to Harvey's expansion into regulated markets
  • customer security reviews, RFP responses, and due diligence conversations
  • 10+ years in information security or compliance, with 5+ years leading compliance programs for commercial SaaS or PaaS
  • Deep command of the compliance lifecycle
  • Proven cross-functional influence at the senior level
  • Track record selecting and managing third-party assessors and compliance advisory firms
  • Experience building and leading small teams in fast-paced environments
  • 1–2+ years using AI tools to improve program efficiency