Deepgram logo
Deepgram·

Compliance and Documentation Lead - Deepgram

Fully remoteFull-timeSeniorUTC-6–-5USA only#privacy#compliance#security

Company Overview

Deepgram is the leading platform underpinning the emerging trillion-dollar Voice AI economy, providing real-time APIs for speech-to-text (STT), text-to-speech (TTS), and building production-grade voice agents at scale. More than 200,000 developers and 1,300+ organizations build voice offerings that are ‘Powered by Deepgram’, including Twilio, Cloudflare, Sierra, Decagon, Vapi, Daily, Cresta, Granola, and Jack in the Box. Deepgram’s voice-native foundation models are accessed through cloud APIs or as self-hosted and on-premises software, with unmatched accuracy, low latency, and cost efficiency. Backed by a recent Series C led by leading global investors and strategic partners, Deepgram has processed over 50,000 years of audio and transcribed more than 1 trillion words.

The Opportunity

Deepgram is looking for a Compliance and Documentation Lead to own the written and evidentiary backbone of our compliance program — privacy and security both — and the documents that auditors, enterprise customers, and our own engineers rely on to know what we actually do.

This is one seat covering both halves deliberately. You will own our privacy program's operational work — assessments, data flow maps, deletion and rights workflows, subprocessor reviews — and our security compliance obligations under SOC 2, ISO 27001, and PCI DSS, along with the security questionnaires, policies, and public posture documents that sit on top of them.

Writing is the core skill in this role, and we mean writing that survives a skeptical reader — an auditor, an enterprise security reviewer, a customer DPO, or an engineer who knows the system better than you do. This role reports to the Director of Information Security and works closely with Security Engineering, Legal, Research, and Solutions/Sales Engineering.

Responsibilities

Privacy Program

  • Own customer and prospect privacy risk assessments, DPIAs, and transfer impact assessments end to end.
  • Build and maintain accurate data flow maps and records of processing across hosted, dedicated, and self-hosted deployments.
  • Own the operating model for our privacy controls: retention and deletion enforcement, DSAR and deletion workflows, consent and opt-out handling, de-identification and redaction.
  • Own the subprocessor and vendor privacy review process, and the artifacts behind our DPAs.
  • Translate GDPR, UK GDPR, CCPA/CPRA, and emerging AI regulation into concrete requirements for engineering and GTM teams.
  • Partner with Legal on DPAs, SCCs, transfer mechanisms, and residency commitments for dedicated deployments.

Security Compliance and Audit

  • Own audit evidence end to end for SOC 2, ISO 27001, and PCI DSS. Be the auditor's primary point of contact through fieldwork.
  • Own control mapping across frameworks to ensure efficiency and avoid redundant work.
  • Own security questionnaires and the security sections of RFPs, maintaining the answer library.
  • Partner with Security Engineering so evidence is generated once, by automation, and reused.

Documentation and Enablement

  • Author and own the lifecycle of internal policies and standards.
  • Own public-facing posture documents (Trust Center content, AI Safety statement, Model Cards, Privacy Policy, deployment-model documentation).
  • Own the documentation system itself: versioning, reviews, and ensuring customer-facing claims trace back to internal sources of truth.
  • Design and run operational auditing and remediation workflows to prevent drift.
  • Run compliance and privacy training and enablement, including clear guidance to Sales Engineering.

Skills Needed

  • Substantial experience in privacy operations, GRC, security compliance, or technical compliance documentation.
  • Exceptional writing skills capable of satisfying auditors, customers, and engineers.
  • Demonstrated ownership of compliance operational systems at scale (data maps, DSAR workflows, evidence collection, answer libraries, policy sets).
  • Hands-on involvement in at least one formal audit (SOC 2, ISO 27001, or PCI DSS).
  • Practical, applied experience with GDPR and CCPA/CPRA, and awareness of emerging AI regulation.
  • Technically fluent: able to read architecture diagrams, follow data flows, and understand log lines or retention settings.
  • Startup-friendly judgment and bias toward building systems and templates.

Nice to Have

  • Certifications such as CIPM, CIPT, CIPP/E, CISA, or ISO 27001 Lead Implementer/Auditor.
  • Experience with compliance automation platforms (Vanta, Drata) and trust center tooling.
  • Familiarity with AI governance frameworks (NIST AI RMF, ISO/IEC 42001, EU AI Act).
  • Experience with ML/AI data pipelines and training-data governance.
  • Compliance work in a hybrid model (multi-tenant SaaS alongside self-hosted/on-premise).
  • Comfort with SQL, light scripting, or AI/agentic tooling.
  • Exposure to HIPAA or FedRAMP.

Timezone overlap

UTC-6–-5

Open to

US

Sign in to track applications and earn points.

More roles at Deepgram

Similar remote roles