{"id":2046970,"url":"https://alion.io/job/sourcegraph-compliance-manager-ic3","title":"Compliance Manager [IC3]","company":{"id":598,"name":"Sourcegraph","domain":"sourcegraph.com","url":"https://alion.io/company/sourcegraph","size_band":"201-500","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Greenhouse","truth_index":null},"role":"Management","role_family":"Management","seniority":"senior","employment_type":null,"work_mode":"remote","remote_scope":"worldwide","remote_scope_basis":"posting_text","remote_working_hours":{"label":"UTC-3","utc_offset_min":-3,"utc_offset_max":-3},"hiring_geo_confidence":"inferred","locations":[],"countries":[],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":96000,"max_usd":187000,"period":"year","method":"global_role_seniority_cell","sample_n":4431},"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"ISO 27001","optional":false},{"name":"SOC 2","optional":false},{"name":"Stripe","optional":false},{"name":"AI Agents","optional":true},{"name":"FedRAMP","optional":true},{"name":"GDPR","optional":true},{"name":"HIPAA","optional":true},{"name":"Model Context Protocol","optional":true},{"name":"PCI DSS","optional":true},{"name":"Rest-Assured","optional":true}],"status":"live","first_seen_at":"2026-10-07T18:58:30Z","employer_posted_date":"2026-10-07","last_verified_at":"2026-10-08T22:10:55Z","board_verified":true,"closed_at":null,"days_open":1,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":1},"description":"Who we are\nOur mission is to bring clarity and control to the world's most complex codebases. AI is accelerating code creation, but the infrastructure to understand, oversee, and evolve that code hasn't kept pace. Sourcegraph gives engineering organizations full visibility across their systems, precise context for their agents, and the ability to execute coordinated code changes at scale. As agentic development becomes the dominant engineering paradigm, we provide the context layer teams need to take control of their codebase.\nWith Code Search, Deep Search, MCP, and Agentic Batch Changes, we deliver on that mission today - giving engineering teams and their AI tools the cross-repo context to navigate massive codebases with confidence, and the ability to make changes across hundreds of repositories at once.\nCompanies like Stripe, Reddit, and Leidos rely on Sourcegraph to ship faster and with higher quality. We're backed by a16z, Sequoia, and Redpoint, and proud to operate as a globally distributed team that values high agency, direct communication, and customer love.\nIf you want to build the infrastructure that lets every engineering team - and every agent they deploy - operate on their codebase with confidence, join us.\nHours & location\nWhile we hire almost anywhere in the world, we have a preference for someone to reside in the following locations for this role. However, if you feel qualified, we welcome you to apply regardless of location. No matter what, working hours must overlap with GMT-3 for at least 20 hours/week.\nPreferred locations:\nUSA\nWhy this job is exciting\nAs our Compliance Manager, you will own and drive Sourcegraph’s governance, risk, and compliance program, with a primary focus on compliance. This is a highly cross-functional role that works closely with Security, Engineering, IT, Legal, People, Sales, and other teams across the company. \nYou will be responsible for maintaining and evolving our compliance program, including owning certifications such as SOC 2 and ISO 27001 and preparing Sourcegraph for additional frameworks as the business grows. This is not a role where you will simply coordinate work across a large compliance organization. We are looking for someone who has personally owned audit and certification programs end to end: designing and tailoring controls, collecting evidence, training internal teams, working directly with auditors, managing remediation, and driving follow-up work through completion.\nWithin one month, you will…\nYou will build strong working relationships across Security, Engineering, IT, Legal, People, Sales, and other key stakeholders.\nYou will develop a clear understanding of Sourcegraph’s existing governance, risk, and compliance program, including our ISMS, risk register, controls, certifications, audit processes, and current areas of focus.\nYou will understand how our SOC 2 and ISO 27001 programs operate today, including key owners, evidence requirements, open risks, and upcoming milestones.\nYou will begin participating directly in day-to-day compliance activities and identify opportunities to improve or simplify existing processes.\nWithin three months, you will…\nYou will have taken ownership of Sourcegraph’s ongoing SOC 2 and ISO 27001 compliance programs.\nYou will independently manage key audit activities, including control testing, evidence collection, stakeholder coordination, auditor requests, findings, and remediation.\nYou will evaluate existing controls and tailor them to Sourcegraph’s environment rather than relying on overly prescriptive or generic auditor recommendations.\nYou will actively maintain Sourcegraph’s risk register, ISMS processes, policies, and compliance documentation.\nYou will help internal teams understand their compliance responsibilities and provide practical guidance that allows them to meet requirements without creating unnecessary process.\nYou will support customer-facing compliance activities, including security questionnaires and compliance-related questions from prospective and existing customers.\nWithin six months, you will…\nYou will have successfully led Sourcegraph through an audit or major certification milestone.\nYou will own the operating rhythm of the GRC program, including ISMS meetings, risk management activities, control reviews, documentation updates, and audit preparation.\nYou will have established a forward-looking compliance roadmap covering renewals, upcoming audits, new frameworks, regulatory requirements, and opportunities to improve how the program operates.\nYou will be able to independently identify control gaps or deficiencies, assess their risk, recommend practical solutions, and drive remediation with both technical and non-technical stakeholders.\nYou will have introduced automation, AI, or other process improvements that reduce manual compliance work while maintaining or improving program quality.\nAbout you \nYou have built or operated compliance programs in a fast-moving technology environment and have personally owned major compliance initiatives from beginning to end.\nYou are comfortable operating independently, getting into the details, and doing the work yourself while coordinating with stakeholders across the organization. You understand that frameworks such as SOC 2 and ISO 27001 define requirements but often leave significant flexibility in how an organization satisfies them, and you know how to translate those requirements into controls that fit the business.\nYou are also comfortable working with technical teams and modern cloud environments. You can understand enough about infrastructure, systems, access controls, software development, and security processes to ask the right questions and effectively translate between auditors and technical teams.\n5+ years of experience in governance, risk, compliance, information security compliance, or a related role.\nDemonstrated end-to-end ownership of SOC 2 and ISO 27001 programs, ideally within a SaaS, technology startup, or similarly fast-moving environment.\nExperience personally managing external audits and certification processes, including audit preparation, evidence collection, control testing, stakeholder training, auditor interaction, remediation, and follow-up.\nStrong understanding of risk management, control design, ISMS governance, and compliance program operations.\nExperience adapting compliance controls to an organization's actual environment rather than applying generic or overly prescriptive requirements.\nFamiliarity with cloud-based technology environments and the security and compliance considerations associated with a distributed or remote workforce.\nStrong project management and organizational skills with the ability to drive cross-functional initiatives from inception through completion.\nExcellent written and verbal communication skills and the ability to explain compliance requirements clearly to both technical and non-technical audiences.\nA hands-on mindset and willingness to personally execute the work required to keep the compliance program operating effectively.\nCuriosity about AI, automation, and emerging technology, with an interest in using new tools to improve compliance workflows.\nNice-to-haves:\nExperience with additional security, privacy, or compliance frameworks such as GDPR, HIPAA, HITRUST, FedRAMP, FISMA, PCI DSS, or related standards.\nExperience supporting security questionnaires, customer assurance processes, or sales-related compliance activities.\nExperience with GRC platforms, compliance automation tools, or building internal automation for evidence collection and control monitoring.\nRelevant certifications such as CISA, CISSP, ISO 27001 Lead Implementer or Lead Auditor, CRISC, or similar credentials.\nLevel\nThis job is an IC3. You can read more about our job leveling philosophy in our Handbook.\nCompensation\nWe pay above-market salaries because we want to hire exceptional people who can focus on building great products, not worrying about paying bills. As anopen and transparent company, our compensation philosophy and pay bands are visible to every Sourcegraph teammate, and we strive to make our approach equitable, explainable, and competitive.\nYour base salary is determined by the IC3 pay band for your location zone (1-4). Our pay bands are informed by market data and designed to ensure competitive compensation wherever you live. During the recruiting process, we'll discuss the range applicable to you based on job level, relevant skills, experience, qualifications, and location zone.\n The starting salary for the IC3 pay band in each zone is:\nZone 2: $137,718 USD\n Zone 3: $102,899 USD\nIn addition to competitive cash compensation, we offer meaningful equity (because when Sourcegraph succeeds, we want you to succeed, too) and generousperks & benefits.\nInterview process \nBelow is the interview process you can expect for this role (you can read more about the types of interviews in our Handbook). It may look like a lot of steps, but rest assured that we move quickly and the steps are designed to help you get the information needed to determine if we’re the right fit for you… Interviewing is a two-way street, after all! \nWe expect the interview process to take 5 hours in total.\nIntroduction Stage - we have initial conversations to get to know you better…\n[30m] Recruiter Screen\n[30m] Hiring Manager Screen\nTeam Interview Stage - we then delve into your experience in more depth and introduce you to members of the team, including cross-functional partners…\n[Async] Working assignment\n[60m] Assignment Walkthrough + Review\n[60m] Resume Deep Dive\n[60m] Technical Interview\nFinal Interview Stage - we move you to our final round, where you gain a better understanding of our business and values holistically…\n[30m] Values\n[30m] Leadership\nWe check references and conduct your background check\nPlease note - you are welcome to request additional conversations with anyone you would like to meet, but didn’t get to meet during the interview process.\nLearn more about us\nYou can learn more about what it is like to work at Sourcegraph by reading our handbook.\nWe are an ambitious team who are collectively working hard to build the most influential company in the world. You can read more about our culture, competitive compensation and benefits here.\nSourcegraph is an equal opportunity workplace; we welcome people from all backgrounds. \nSourcegraph participates in E-Verify for U.S. Employees.","description_format":"text","description_chars":10455,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Equity"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Artificial Intelligence","Code Intelligence","AI Development Tools"],"lifecycle":[{"event":"open","at":"2026-10-07T19:59:54Z"}],"visa":[{"country":"US","licensed_sponsor":true,"evidence":"Filed H-1B visas in the last two years","filings_12m":0,"filings_prev_12m":1,"green_card_filings_12m":0,"median_offered_wage_usd":null,"route":null,"cap_exempt":false,"checked_at":"2026-10-03T21:08:04+00:00","sources":["US Department of Labor: LCA disclosure data (H-1B, H-1B1, E-3)"],"filings_for_role_12m":0}],"liveness":{"score":86,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.86,"p_room":1,"age_days":0,"expected_fill_days":40,"reasons":["conf:2","win:early","comp:remote"],"computed_at":"2026-10-08T05:49:30Z"},"pay":null,"html_url":"https://alion.io/job/sourcegraph-compliance-manager-ic3","json_url":"https://alion.io/job/sourcegraph-compliance-manager-ic3.json","meta":{"generated_at":"2026-10-09T00:25:22Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":508,"day_limit":5000,"remaining_today":4492,"minute_limit":60,"resets_at":"2026-10-10T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":598},"rest":"https://alion.io/mcp/rest/get_company?id=598"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fsourcegraph-compliance-manager-ic3"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fsourcegraph-compliance-manager-ic3"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fsourcegraph-compliance-manager-ic3"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/sourcegraph-compliance-manager-ic3\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fsourcegraph-compliance-manager-ic3"}]}