
Who we are
Our mission is to bring clarity and control to the world's most complex codebases. AI is accelerating code creation, but the infrastructure to understand, oversee, and evolve that code hasn't kept pace. Sourcegraph gives engineering organizations full visibility across their systems, precise context for their agents, and the ability to execute coordinated code changes at scale. As agentic development becomes the dominant engineering paradigm, we provide the context layer teams need to take control of their codebase.
Companies like Stripe, Reddit, and Leidos rely on Sourcegraph to ship faster and with higher quality. We're backed by a16z, Sequoia, and Redpoint, and proud to operate as a globally distributed team that values high agency, direct communication, and customer love.
Why this job is exciting
As our Compliance Manager, you will own and drive Sourcegraphโs governance, risk, and compliance program, with a primary focus on compliance. This is a highly cross-functional role that works closely with Security, Engineering, IT, Legal, People, Sales, and other teams across the company.
You will be responsible for maintaining and evolving our compliance program, including owning certifications such as SOC 2 and ISO 27001 and preparing Sourcegraph for additional frameworks as the business grows.
What you will achieve:
- Within 1 month: Build strong working relationships, understand existing GRC programs, ISMS, risk registers, and current SOC 2 and ISO 27001 operations.
- Within 3 months: Take full ownership of ongoing SOC 2 and ISO 27001 compliance programs, independently manage audit activities, tailor controls, and maintain the risk register.
- Within 6 months: Successfully lead Sourcegraph through an audit or major certification milestone, establish a forward-looking roadmap, and introduce automation or process improvements.
About you
- 5+ years of experience in governance, risk, compliance, information security compliance, or a related role.
- Demonstrated end-to-end ownership of SOC 2 and ISO 27001 programs within a SaaS or technology startup environment.
- Experience personally managing external audits, evidence collection, control testing, and remediation.
- Strong understanding of risk management, control design, ISMS governance, and compliance program operations.
- Familiarity with cloud-based technology environments and distributed or remote workforces.
- Strong project management, written, and verbal communication skills.
- Hands-on mindset with a curiosity about AI and automation for compliance workflows.
Hours & location
While we hire almost anywhere in the world with a preference for candidates in the USA, working hours must overlap with GMT-3 for at least 20 hours/week.
Timezone overlap
UTC-3
Culture
Async-friendly
Benefits
Open to
US
Sign in to track applications and earn points.