Sembi Logo

Sembi

Manager of Compliance & Risk

Posted 2 Days Ago
Remote
Hiring Remotely in TX, USA
Senior level
Remote
Hiring Remotely in TX, USA
Senior level
Own and build Sembi’s enterprise compliance, risk, third-party risk, customer assurance, and AI governance programs across multiple software brands. Lead SOC 2 audits, risk assessments, vendor reviews, GRC platform implementation, privacy requests, policy and control frameworks, customer security diligence, incident compliance obligations, and compliance team development. Partner closely with Security, Legal, Engineering, Sales, and executive leadership.
The summary above was generated by AI

Sembi is seeking a Manager of Compliance & Risk to own our compliance and risk program end to end. Sembi operates seven software brands including TestRail, Xblend, Testmo, Ranorex, Kiuwan, PreEmptive and Hexawise, and our enterprise customers hold us to a rising bar on security, privacy and third-party risk. This role owns Sembi’s audit and certification calendar, strengthens our risk management program, and will select and implement a GRC platform and lead the team that keeps it running. This is a build role, not a maintenance role. You will report to the VP of Operations and work directly with Security, Legal, Engineering and Sales leadership.

 

Responsibilities

  • Own the compliance program for all Sembi brands, including SOC 2 audits, penetration testing, SIG and CAIQ responses and NIST self-assessments. 
  • Build and operate an enterprise risk management program. Stand up and maintain a risk register, define the assessment methodology, drive remediation with system owners and report risk posture to executive leadership on a quarterly cadence.
  • Run third-party risk management. Review and strengthen the vendor assessment and tiering process, onboard and monitor subprocessors and own the ongoing review cycle.
  • Lead the selection, implementation and administration of a GRC platform, including control mapping, evidence automation and vendor risk workflows.
  • Own customer assurance. Oversee security questionnaires and compliance agreement requests against response SLAs, maintain our Vanta trust centers and build reusable artifacts that cut reactive work.
  • Maintain our policy set and control framework against GDPR, CCPA, DORA, NIS2, HIPAA and the EU AI Act, and finalize and operationalize our AI governance policies.
  • Handle data subject rights requests, deletion requests and DPA execution in partnership with Legal.
  • Lead and develop the compliance team. Set priorities, define ownership and mature the function.
  • Support incident response and post-incident compliance obligations alongside Security.
 

Skills and experience

  • 7+ years in compliance, governance or risk within SaaS or technology, including 2+ years leading a program or a team.
  • Hands-on ownership of SOC 2 Type II audits from scoping through report issuance, ideally across multiple entities or product lines.
  • Demonstrated experience building a risk program, a risk register or a third-party risk process where none existed.
  • Experience implementing or administering a GRC platform such as Vanta, Drata, AuditBoard or OneTrust. Full implementation ownership is strongly preferred.
  • Working knowledge of ISO 27001, NIST and SOC 2 control frameworks, plus practical fluency in GDPR and US state privacy law.
  • Familiarity with AI governance obligations and emerging requirements including the EU AI Act.
  • Experience answering enterprise customer security and privacy diligence, and comfort engaging directly with customer security teams.
  • Strong cross-functional operator. You can drive remediation through engineering and product teams you do not manage.
  • Strong written and verbal communication skills, with the ability to manage multiple workstreams, prioritize effectively, and solve problems in a fast-moving environment.
  • CISSP, CISA, CRISC or IAPP certifications preferred, not required.
HQ

Sembi Austin, Texas, USA Office

4001 W. Parmer Lane, Suite 125, Austin, TX, United States, 78727

Similar Jobs

13 Days Ago
Remote
United States
115K-140K Annually
Senior level
115K-140K Annually
Senior level
eCommerce • Manufacturing
Own end-to-end remediation projects addressing SOC 2, ITGC, security, privacy, AI governance, and regulatory requirements. Coordinate cross-functional stakeholders, translate compliance requirements into technical work, manage risks and dependencies, track risk treatment plans, and report progress to executives. Support annual risk assessments, auditor coordination, GRC tooling, dashboards, and process improvements across concurrent projects.
Top Skills: AgileAPIsCloud InfrastructureGrc/Irm PlatformsItgcJIRAMs ProjectOptroSoc 2Software Development LifecycleWaterfall
One Month Ago
Remote
United States
100K-130K Annually
Senior level
100K-130K Annually
Senior level
Software • Cybersecurity • Renewable Energy
Leads the Compliance & Risk team supporting NERC-registered renewable energy projects. Oversees regulatory filings, project registrations, audits, stakeholder meetings, compliance workflows, budgets, staffing, and cross-functional initiatives. Manages and mentors employees, supports business development, improves processes, and ensures delivery against schedules and performance requirements. The role requires substantial NERC compliance and renewable energy experience, strong project and people management skills, and proficiency with Microsoft Office and Adobe PDF tools.
Top Skills: Adobe Acrobat/PdfCaisoErcotFercIso/RtoLean Six SigmaExcelMicrosoft PowerpointMicrosoft WordNerc
One Month Ago
Easy Apply
Remote
USA
Easy Apply
162K-191K Annually
Senior level
162K-191K Annually
Senior level
Artificial Intelligence • Blockchain • Fintech • Financial Services • Cryptocurrency • NFT • Web3
Lead enterprise-wide compliance and financial-crime risk assessments, evaluate controls and residual risk, produce executive reports, partner with MLROs/CCOs globally, drive transaction monitoring and customer risk scoring coverage, update geographic risk ratings, develop threat assessment frameworks, and pioneer AI-powered automation while maintaining human oversight.
Top Skills: Ai PlatformsExcelGenerative AiSQL

What you need to know about the Austin Tech Scene

Austin has a diverse and thriving tech ecosystem thanks to home-grown companies like Dell and major campuses for IBM, AMD and Apple. The state’s flagship university, the University of Texas at Austin, is known for its engineering school, and the city is known for its annual South by Southwest tech and media conference. Austin’s tech scene spans many verticals, but it’s particularly known for hardware, including semiconductors, as well as AI, biotechnology and cloud computing. And its food and music scene, low taxes and favorable climate has made the city a destination for tech workers from across the country.

Key Facts About Austin Tech

  • Number of Tech Workers: 180,500; 13.7% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Dell, IBM, AMD, Apple, Alphabet
  • Key Industries: Artificial intelligence, hardware, cloud computing, software, healthtech
  • Funding Landscape: $4.5 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Live Oak Ventures, Austin Ventures, Hinge Capital, Gigafund, KdT Ventures, Next Coast Ventures, Silverton Partners
  • Research Centers and Universities: University of Texas, Southwestern University, Texas State University, Center for Complex Quantum Systems, Oden Institute for Computational Engineering and Sciences, Texas Advanced Computing Center

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account