Logo for mpathic

Senior Manager, Compliance & Audit

Role overview

Qualifications

  • 7+ years in IT compliance, GRC, audit, or computerized systems validation
  • Hands-on experience applying FDA 21 CFR Part 11 and GxP data integrity requirements
  • Experience leading or supporting SOC 1 and SOC 2 Type II examinations and ISO/IEC 27001 certification
  • Comfortable reviewing cloud configurations across AWS, GCP, or Azure

Responsibilities

  • Plan and run the annual audit and certification cycle for various standards
  • Own Part 11 compliance for systems managing regulated records
  • Maintain a unified control set across applicable frameworks to avoid duplication of work
  • Run a risk-based internal audit program and track nonconformities and CAPAs

Key facts

Hard skills

Other skills

  • Open Mindset

About the company

mpathic logo

mpathic

Computer Software / SaaS

mpathic is keeping humans safe in the AI era through technology-enabled, expert-led human data and evaluation services. We work with frontier AI builders to prevent harmful or unwanted model behaviors, spanning use cases from user wellbeing and mental health to financial risk and customer support, across the full AI model lifecycle. mpathic Experts create multi-modal ground-truth datasets, trajectories, annotations and role plays for use in red teaming and benchmarking. Experts have specialization in behavioral analysis, conversational design, and high-risk/high-accuracy areas. We partner with Responsible AI and Trust & Safety teams to support global deployment, policy enforcement, and ongoing risk mitigation to strengthens both model quality and real-world safety. Learn more at mpathic.ai

Company details

Company typeStartup
IndustryComputer Software / SaaS
Company size11 - 50

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

About mpathic

mpathic is building the future of trustworthy AI. Grounded in behavioral science and human-centered design, we provide the infrastructure for building AI systems that are safe, aligned, and emotionally intelligent.

Building on our work in areas like RL gyms, red teaming, benchmarking, and human data, we are creating the foundation for training, probing, and measuring advanced AI systems reliably, auditably, and at scale.

Position Overview

mpathic is seeking a Senior Manager, Compliance & Audit to own and scale the compliance and audit programs that support our technology, customers, and continued growth.

This is a hands-on role for someone who can move comfortably between regulatory requirements, technical systems, external auditors, and internal teams. You’ll lead our audit and certification lifecycle across SOC 1, SOC 2 Type II, ISO/IEC 27001, ISO/IEC 42001, and FDA 21 CFR Part 11, while building a unified compliance program that minimizes duplicate work and makes compliance part of how we operate—not simply something we prepare for at audit time.

You’ll partner closely with engineering, security, product, delivery, and operations to translate requirements into practical controls, automate evidence wherever possible, and ensure our systems and processes can stand up to scrutiny from auditors, customers, and regulated-industry partners.

About You

  • Proven Experience: 7+ years in IT compliance, GRC, audit, or computerized systems validation, including direct ownership of external audits from scoping through final report or certification.
  • FDA 21 CFR Part 11 Depth: Hands-on experience applying Part 11 and GxP data integrity requirements to software or SaaS systems, including audit trails, electronic signatures, access controls, record retention, and ALCOA+ principles. Familiarity with FDA Computer Software Assurance (CSA) guidance, GAMP 5, and EU Annex 11 is a strong plus.
  • Validation Experience: Experience writing or leading validation deliverables such as validation plans, requirements traceability, risk-based test evidence (IQ/OQ/PQ or CSA-style), and validation summary reports, as well as supporting customer or sponsor audits of validated systems.
  • Multi-Framework Audit Experience: Experience leading or supporting SOC 1 and SOC 2 Type II examinations and ISO/IEC 27001 certification or surveillance audits. Experience with ISO/IEC 42001 or other AI governance frameworks, including NIST AI RMF or the EU AI Act, is a strong plus.
  • Technical Fluency: Comfortable reviewing cloud configurations across AWS, GCP, or Azure; IAM policies; CI/CD and change management records; logging; and infrastructure as code well enough to evaluate whether a control is actually operating—not simply whether documentation exists.
  • Internal Audit Skills: Able to plan and execute internal audits, sample and evaluate evidence, write clear findings, and drive corrective and preventive actions (CAPAs) through closure.
  • Auditor Credibility: Comfortable representing mpathic with external auditors, certification bodies, customers, and sponsor quality teams—and able to challenge findings constructively when the evidence supports a different conclusion.
  • Clear Communication: Able to write policies, findings, and customer responses that engineers can act on and executives can confidently approve.
  • Practical Mindset: You understand that strong compliance programs should enable teams to move quickly and responsibly rather than create unnecessary process.
  • Credentials: Certifications such as CISA, ISO/IEC 27001 Lead Auditor or Lead Implementer, ISO/IEC 42001 Lead Auditor, ASQ CQA, or CISSP are a plus.

Core Responsibilities

  • Audit Ownership: Plan and run the annual audit and certification cycle for SOC 1, SOC 2, ISO/IEC 27001, ISO/IEC 42001, and Part 11 readiness, including auditor selection, scoping, evidence collection, fieldwork, management responses, and final report or certificate delivery.
  • FDA Part 11 Program: Own Part 11 compliance for systems that create, modify, or store regulated records. Maintain the system inventory and GxP impact assessments, lead risk-based validation, and ensure validation documentation remains current through releases and system changes.
  • Unified Control Framework: Maintain a unified control set mapped across applicable frameworks so evidence can satisfy multiple requirements and teams aren't duplicating work for every audit.
  • Internal Audit: Run a risk-based internal audit program, including ISO-required internal audits and management reviews, and track nonconformities and CAPAs through closure.
  • Engineering & Delivery Partnership: Build controls into how mpathic develops and delivers its products and services, including change management, code review, access reviews, release validation, and data handling across customer work. Partner with engineering to automate evidence collection wherever possible.
  • Enforcement & Remediation: Monitor control health, identify and escalate gaps early, and drive remediation with control owners across engineering, delivery, operations, HR, and other teams.
  • AI Management System: Maintain mpathic’s ISO/IEC 42001 AI management system in partnership with ML, engineering, and product teams, including AI risk and impact assessments and documentation of model lifecycle controls.
  • Customer Security & Compliance Reviews: Own responses to security questionnaires, customer and sponsor quality audits, and compliance-related portions of RFPs and contracts. Maintain and continuously improve our trust center.
  • GRC Tooling: Own our GRC platform and its integrations, ensuring control mappings, automated evidence collection, and policy workflows remain accurate and useful.
  • Policies & Training: Maintain the policies and SOPs required by our certifications and regulatory commitments, and deliver compliance training, including Part 11 and GxP training for employees working with regulated systems.
  • Regulatory Monitoring: Track changes to FDA guidance, AI governance requirements, and applicable data privacy laws, translating relevant changes into practical recommendations for mpathic’s compliance program.

What Success Looks Like

You’ll build a compliance program that is rigorous enough to meet the expectations of auditors, regulated customers, and enterprise partners while remaining practical for a fast-moving technology company.

Audits and certifications will become increasingly predictable, evidence will be reusable and automated wherever possible, and teams will understand what controls they own and why they matter. You’ll also help ensure mpathic stays ahead of emerging expectations around AI governance and regulated technology as our platform and customer base grow.

Compensation

The base salary range for this role is $140,000–$180,000, depending on experience, skills, and qualifications.


Compensation: $140,000 - $180,000

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Audit Manager Related jobs

Other jobs at mpathic

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.