Risk and Compliance Lead

Replit
United States
Workplace: HybridFull timeUSD 210,000 - 270,000 annuallyFunction: Legal, Risk & ComplianceExperience: 8+ yearsSkills: []

Own Replit’s security GRC program end to end for an AI-native product, including the certification roadmap and continuous compliance monitoring. Lead SOC 2 Type II and ISO 27001 efforts, plan for ISO 42001, maintain the master security risk register, and manage audit artifacts and external auditor relationships. Partner with Engineering and the GRC Engineer to ensure controls work in practice, and support GDPR/privacy compliance with Legal.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Replit
Replit
1 month ago

Risk and Compliance Lead

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 3 hours agoStatus: Live

Job Summary

Own Replit’s security GRC program end to end for an AI-native product, including the certification roadmap and continuous compliance monitoring. Lead SOC 2 Type II and ISO 27001 efforts, plan for ISO 42001, maintain the master security risk register, and manage audit artifacts and external auditor relationships. Partner with Engineering and the GRC Engineer to ensure controls work in practice, and support GDPR/privacy compliance with Legal.
Location: United States
Workplace: Hybrid
Employment Type: Full time
Job Function: Legal, Risk & Compliance

Key Responsibilities

  • •Own the end-to-end certification roadmap (SOC 2 Type II, ISO 27001, and future frameworks like ISO 42001), including scoping, gap assessments, remediation, and audit execution.
  • •Manage relationships with external auditors and drive the annual audit calendar so certifications renew smoothly.
  • •Own and maintain the company master security risk register, including risk identification, scoring methodology, treatment plans, and residual risk reporting.
  • •Build and maintain continuous compliance monitoring so control status reflects real-time state.
  • •Own core audit artifacts (ISMS documentation, Statements of Applicability, risk assessments, and potentially FedRAMP SSPs) and run audits/readiness assessments to closure.

Pay and Benefits

Salary: USD 210,000 - 270,000 annually
Perks:401kHealth InsuranceDentalVisionLife InsuranceDisabilityParental LeavePaid LeaveCommuter BenefitsWellness Stipend

Key Requirements

  • •8+ years in security compliance, IT audit, or GRC roles, with direct ownership of at least one SOC 2 and/or ISO 27001 certification cycle.
  • •Working knowledge of common frameworks (SOC 2, ISO 27001, NIST CSF) and how to map controls across them.
  • •Hands-on experience authoring or substantially maintaining an ISMS and/or SSP (or equivalent audit-facing documentation).
  • •Experience owning a formal risk register, including risk identification, scoring methodology, treatment plans, and residual risk reporting.
  • •Experience with GRC/compliance automation platforms (e.g., Anecdotes, Vanta, Drata) and continuous control monitoring.
Experience:8+ yearsSecurity complianceIT auditGRC
Certifications:CISACISSPISO 27001 Lead Auditor/Implementer
Tech Stack:SOC 2ISO 27001ISO 42001NIST CSFAnecdotesVantaDrataISMSSSPStatements of ApplicabilityFedRAMPGDPR

Company Brief

Replit
Provides a browser-based integrated development environment (IDE) and collaborative coding platform that lets developers write, run, and deploy code instantly across many languages and frameworks.
Industry: Developer Tools
Company Size: Large (251 to 1,000 employees)
Growth: Scaleup
Headquarters: San Francisco, United States
Founded: 2016
WebsiteLinkedIn