Compliance and Security Lead

Ada
Canada
Workplace: RemoteFull timeFunction: Legal, Risk & ComplianceSkills: ["Strong writing","Customer-facing confidence","Proactive ownership","Program building","Process automation","Prioritization","Vendor management"]

Own Ada’s security compliance program end to end, including audits, customer trust, vendor risk, vulnerability management, and the control framework that ties it all together. Automate evidence collection and control monitoring so audit season (August–November) is smooth year-round. Lead RFP security responses and maintain the trust center, manage critical vulnerability SLAs, and translate emerging agentic AI governance (starting with AIUC) into actionable requirements for the platform team.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Ada
Ada
1 day ago

Compliance and Security Lead

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 5 hours agoStatus: Live

Job Summary

Own Ada’s security compliance program end to end, including audits, customer trust, vendor risk, vulnerability management, and the control framework that ties it all together. Automate evidence collection and control monitoring so audit season (August–November) is smooth year-round. Lead RFP security responses and maintain the trust center, manage critical vulnerability SLAs, and translate emerging agentic AI governance (starting with AIUC) into actionable requirements for the platform team.
Location: Canada
Workplace: Remote
Employment Type: Full time
Job Function: Legal, Risk & Compliance

Key Responsibilities

  • •Own Ada’s security audits end to end (including AIUC, PCI, and SOC 2), running evidence collection, control mapping, and auditor coordination with Drata.
  • •Automate evidence collection and control monitoring so audit season is smooth year-round instead of requiring seasonal heroics.
  • •Own security and compliance responses for customer RFPs and security questionnaires, maintaining the SafeBase trust center so security reviews don’t stall deals.
  • •Own vulnerability management as a program, driving the backlog down with clear prioritization, ownership, and SLAs for critical findings.
  • •Maintain the control framework and documentation (policies, data handling, retention, and evidence that controls operate) and translate emerging agentic AI governance into platform-team requirements.

Pay and Benefits

Perks:Health InsuranceDentalVisionTravel AllowanceLife InsurancePaid LeaveLearning BudgetRemote Work

Key Requirements

  • •Deep audit experience across SOC 1, SOC 2, PCI DSS, NIST frameworks, AICPA standards, and PII/privacy requirements, including end-to-end audit execution (evidence collection, control mapping, auditor coordination).
  • •Experience working directly with major audit firms (e.g., Deloitte or EY) and understanding gold-standard audit engagements.
  • •Experience inheriting manual compliance programs and driving automation toward tooling, process, and repeatability (e.g., Drata).
  • •Ability to manage vulnerability management at scale by prioritizing a large backlog and driving it down with clear ownership and SLAs.
  • •Comfort owning customer-facing security posture conversations, including RFP security sections, security questionnaires, and trust center work (e.g., SafeBase).
Skills:Strong writingCustomer-facing confidenceProactive ownershipProgram buildingProcess automationPrioritizationVendor management
Tech Stack:DrataSafeBaseKubernetesTerraformCI/CDLLMsAIUCSOC 1SOC 2PCI DSSNISTAICPA

Company Brief

Ada
Builds AI-powered customer service automation platform delivering chatbots and self-service experiences that help enterprises resolve inquiries, route complex issues, and scale support while integrating with existing systems and workflows.
Industry: SaaS
Company Size: Large (251 to 1,000 employees)
Growth: Scaleup
Funding: Series C
Headquarters: Toronto, Canada
Founded: 2016
WebsiteLinkedIn