{"schemaVersion":"jobsearcher.job.v1","id":"32e62b78fd360e2c665ecedf","url":"https://jobsearcher.com/jobs/32e62b78fd360e2c665ecedf","canonicalUrl":"https://jobsearcher.com/jobs/32e62b78fd360e2c665ecedf","title":"Security Operations Manager","description":"Why Mintlify? We're on a mission to empower builders.\r\nMassive reach: Our docs platform serves 100 million+ developers every year and powers documentation for 20,000+ companies, including Anthropic, Microsoft, PayPal, Spotify, Coinbase, X, and over 20% of the last YC batch.\r\nSmall team, huge impact: We recently passed 65 employees and raised a $45 million Series B led by A16Z and Salesforce Ventures. Each new hire has a huge impact on shaping the company's trajectory.\r\nCulture of slope over y-intercept : We value learning velocity, grit, and unapologetically unique personalities.\r\nWe grew in value faster than headcount and we're looking to align the two quickly.\r\nThe Role We're hiring our first dedicated GRC Program Manager to own the security & compliance program that our enterprise business runs on: SOC 2 Type II, ISO 27001, ISO 42001, GDPR, and Microsoft SSPA. The program exists and is well-documented — audits are mid-flight, the vCISO and auditors are engaged, the platform (Drata) is deployed. What it needs is a single accountable operator.\r\nWhat You'll Do Run five compliance programs end-to-end — own the audit calendar, evidence collection, remediation tracking, and auditor relationships (Sensiba for SOC 2/ISO; A-LIGN for Microsoft SSPA)\r\nAdminister Drata — keep monitors green, assign and validate evidence, manage policies and the trust center\r\nOwn the vendor bench — drive the weekly Rhymetec vCISO engagement, manage renewals and contracts across the security/compliance vendor portfolio\r\nRun the standing processes — security questionnaire escalation, inbound vendor security reviews, bug bounty coordination (triage, researcher comms, payouts), trainings and access-review cadences\r\nBe the customer-facing compliance voice — trust center, DPAs, subprocessor list, and enterprise security requirements (Microsoft, Coinbase, Okta-style programs)\r\nCoordinate, don't silo — route technical work to Engineering DRIs with clear asks, and keep leadership out of the coordination loop\r\nWhat We're Looking For 3+ years in GRC / compliance program management / security operations with direct audit ownership\r\nHands-on compliance-platform administration (Drata, Vanta, or similar)\r\nVendor and auditor relationship management as the accountable owner\r\nMeticulous follow-through — in this job, a dropped thread is an audit finding\r\nBias toward automation and pushing work to tests/vendors rather than doing it manually forever\r\nBonus Points: ISO 42001 / AI governance exposure. GDPR operations (DSARs, RoPA, consent tooling). Early-stage startup experience as a sole compliance owner.\r\nCompany Benefits: Competitive compensation and equity\r\n20 days paid time off every year\r\n401k or RRSP\r\n$420/month wellness stipend\r\n100% coverage for Health, dental, vision\r\nFree Ubers to and from work\r\nFree lunch and dinners\r\nAnnual team offsite (previously went to Alaska, Hawaii)\r\nJ-18808-Ljbffr","company":"Mintlify","rawCompany":"mintlify","city":"Millbrae","state":"CA","isRemote":false,"isActive":false,"createdAt":"2026-08-08T01:59:22.230Z","occupations":[{"code":"13-1199.07","title":"Security Management Specialists","slug":"security-management-specialists"},{"code":"11-9199.02","title":"Compliance Managers","slug":"compliance-managers"},{"code":"11-3013.01","title":"Security Managers","slug":"security-managers"}],"industries":[{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"},{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Security Operations Manager","description":"Why Mintlify? We're on a mission to empower builders.\r\nMassive reach: Our docs platform serves 100 million+ developers every year and powers documentation for 20,000+ companies, including Anthropic, Microsoft, PayPal, Spotify, Coinbase, X, and over 20% of the last YC batch.\r\nSmall team, huge impact: We recently passed 65 employees and raised a $45 million Series B led by A16Z and Salesforce Ventures. Each new hire has a huge impact on shaping the company's trajectory.\r\nCulture of slope over y-intercept : We value learning velocity, grit, and unapologetically unique personalities.\r\nWe grew in value faster than headcount and we're looking to align the two quickly.\r\nThe Role We're hiring our first dedicated GRC Program Manager to own the security & compliance program that our enterprise business runs on: SOC 2 Type II, ISO 27001, ISO 42001, GDPR, and Microsoft SSPA. The program exists and is well-documented — audits are mid-flight, the vCISO and auditors are engaged, the platform (Drata) is deployed. What it needs is a single accountable operator.\r\nWhat You'll Do Run five compliance programs end-to-end — own the audit calendar, evidence collection, remediation tracking, and auditor relationships (Sensiba for SOC 2/ISO; A-LIGN for Microsoft SSPA)\r\nAdminister Drata — keep monitors green, assign and validate evidence, manage policies and the trust center\r\nOwn the vendor bench — drive the weekly Rhymetec vCISO engagement, manage renewals and contracts across the security/compliance vendor portfolio\r\nRun the standing processes — security questionnaire escalation, inbound vendor security reviews, bug bounty coordination (triage, researcher comms, payouts), trainings and access-review cadences\r\nBe the customer-facing compliance voice — trust center, DPAs, subprocessor list, and enterprise security requirements (Microsoft, Coinbase, Okta-style programs)\r\nCoordinate, don't silo — route technical work to Engineering DRIs with clear asks, and keep leadership out of the coordination loop\r\nWhat We're Looking For 3+ years in GRC / compliance program management / security operations with direct audit ownership\r\nHands-on compliance-platform administration (Drata, Vanta, or similar)\r\nVendor and auditor relationship management as the accountable owner\r\nMeticulous follow-through — in this job, a dropped thread is an audit finding\r\nBias toward automation and pushing work to tests/vendors rather than doing it manually forever\r\nBonus Points: ISO 42001 / AI governance exposure. GDPR operations (DSARs, RoPA, consent tooling). Early-stage startup experience as a sole compliance owner.\r\nCompany Benefits: Competitive compensation and equity\r\n20 days paid time off every year\r\n401k or RRSP\r\n$420/month wellness stipend\r\n100% coverage for Health, dental, vision\r\nFree Ubers to and from work\r\nFree lunch and dinners\r\nAnnual team offsite (previously went to Alaska, Hawaii)\r\nJ-18808-Ljbffr","datePosted":"2026-08-08T01:59:22.230Z","dateModified":"2026-08-08T01:59:22.230Z","hiringOrganization":{"@type":"Organization","name":"Mintlify","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Millbrae","addressRegion":"CA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"32e62b78fd360e2c665ecedf"},"url":"https://jobsearcher.com/jobs/32e62b78fd360e2c665ecedf"}}