Logo for Sparkrock

Group Security & Compliance Manager ($60,000/year USD), Sparkrock

Role overview

Qualifications

  • 6+ years in security GRC, customer trust, or SaaS compliance.
  • Excellent spoken and written English.
  • SOC 2 audit experience as a primary point of contact.
  • Working understanding of cloud security concepts.

Responsibilities

  • Lead customer security reviews, RFPs, RFIs, and questionnaires.
  • Stand up and maintain a customer-facing trust portal.
  • Own SOC 2 Type II program management, driving audits across portfolio companies.
  • Author and maintain security policies and documentation.

Key facts

Other skills

  • Communication
  • Presentations
  • Problem Solving

About the company

Sparkrock logo

Sparkrock

Computer Software / SaaS

Sparkrock provides an all-in-one enterprise software (ERP) that includes finance, workforce management, payroll and employee scheduling built for Nonprofit & Human Services Organizations and K-12 & Educational Institutions. Our team is made up of industry experts that are inspired by their work as they support our customers who literally are changing the world. We enable social benefit organizations to succeed on their mission.

Company details

Company typeSME
IndustryComputer Software / SaaS
Company size51 - 200

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Are you a security and compliance leader who thrives on customer trust? Do you want to work for a best-in-class, 100% remote organization with the brightest talent from around the world? If so, then keep reading…

At Sparkrock, we help social benefit organizations, such as nonprofits, school boards, and government agencies, reach their full potential through technology. Every day, over 150,000 people use our ERP and product platforms to work more efficiently, freeing up time and resources to focus on the good they want to achieve.

As our Group Security & Compliance Manager, you will own the entire customer-trust and compliance function across a growing private-equity portfolio, not one slice of it at one company. Every enterprise deal that hinges on security passes through you, and you get to build the program from the trust portal up rather than inherit someone else's mess.

Unlike most GRC managers who sit inside a single company running one SOC 2, this role spans multiple portfolio companies on different clouds, and it owns the AI trust story as a first-class part of the job. You'll drive SOC 2 Type II audits, stand up the customer-facing trust portal, and own AI compliance as the frameworks are still settling, representing the group directly in every customer security review.

If you thrive at the intersection of broad ownership, direct influence on revenue, and building something before the playbook is written, this role is for you.

 

Responsibilities

*Lead customer security reviews, RFPs, RFIs, and questionnaires, turning around accurate, complete responses fast enough to keep deals moving

*Stand up and maintain a customer-facing trust portal (SafeBase / Vanta / Drata or equivalent), including a dedicated AI/ML section

*Own SOC 2 Type II program management, driving audits across portfolio companies (including Sparkrock's Type II conversion and CXT scoping), coordinating evidence with the Senior Group Security Engineer, and managing auditor relationships

*Author and maintain security policies and documentation, including DPAs, sub-processor lists, and incident-communication templates

*Own AI compliance and trust, including AI questionnaire responses, AI sub-processor management, framework tracking (EU AI Act, ISO 42001, NIST AI RMF), AI use disclosure, AI acceptable-use policy, and AI incident-comms playbooks

*Run third-party vendor security reviews and renewals

*Build and deliver internal security awareness training, and onboard customers through the required security setup

*Draft and coordinate customer-facing incident communications, including breach/incident notifications with legal and engineering

 

Requirements

*6+ years in security GRC, customer trust, or SaaS compliance.

*Excellent spoken and written English. Articulate, polished, and credible in live calls with enterprise customers and third parties — this person represents the group externally.

*SOC 2 audit experience as a primary point of contact (Type II strongly preferred).

*Working understanding of cloud security concepts — able to read and translate technical findings, not produce them.

*Awareness of the AI compliance landscape and willingness to own it.

 

Nice to have

*CISSP / CISA / CIPP/E; Vanta / Drata / SafeBase experience.

*PE-backed or multi-portfolio background.

*ISO 42001 / NIST AI RMF familiarity; EU AI Act awareness.

 

Benefits

We don’t call them perks; they’re just part of what makes working at Sparkrock great.

*We are 100% remote and global. Live your best life wherever that may be, and never lose out on career opportunities because of it.

*Flexible work hours. We work asynchronously and don’t care when you’re online, just that you deliver great results and are there for our customers.

*We are dedicated to your growth with consistent and meaningful feedback, support in achieving your personal career goals, and access to leading-edge tools, playbooks, and technology to amplify your experience.

*Introductions to thought leaders in the space and webinars on cutting-edge tech hot topics.

*Stipend to help set up your ideal home office

*Focus on culture: coffee chats, happy hours, cooking classes, book clubs, and more!

 

If you are a security and compliance professional who has lived and breathed customer trust and is ready to bring that expertise to a high-impact, high-ownership role, we would love to hear from you. Apply today and help us build a trust program that enterprise customers and an entire portfolio of companies can rely on.

We strive to build a team that reflects the diversity of the community we work in and encourage applications from traditionally underrepresented groups such as women, visible minorities, Indigenous peoples, people identifying as LGBTQ2SI, veterans, and people with disabilities.
 
 
All open roles are for existing vacancies unless otherwise communicated to the candidate. We are committed to keeping candidates informed throughout the process and will notify all interviewed applicants of our hiring decision within 45 days of their interview. Sparkrock retains all job postings and related recruitment information for a minimum of three years.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Compliance Manager Related jobs

Other jobs at Sparkrock

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.