Fieldguide · 11 hours ago
Lead Compliance Manager
Fieldguide is establishing a new state of trust for global commerce and capital markets through automating and streamlining the work of assurance and audit practitioners specifically within cybersecurity, privacy, and financial audit. The Lead Compliance Manager will own and scale Fieldguide’s compliance programs end-to-end, managing SOC 2 and ISO programs, and automating compliance processes to support audit readiness and customer trust.
AccountingAgentic AIArtificial Intelligence (AI)Cyber SecurityDocument ManagementFinTech
Responsibilities
Lead SOC 2 and ISO programs through the full audit lifecycle, scoping, evidence collection, control testing, auditor management, and remediation tracking
Drive Fieldguide’s journey towards additional compliance frameworks and standards from gap assessment to audits
Own the mapping of controls across overlapping frameworks. Maintain corporate policies, standards, and procedures
Manage external relationships with auditors, assessors, consultants, and customers. Coordinate audit timelines, responses, and remediation plans
Build integrations that continuously gather compliance evidence from AWS, GitHub, identity providers, and internal systems. Replace manual screenshots and spreadsheets with automated, auditable pipelines
Design and implement continuous control monitoring: surface drift, alert on failures, and maintain dashboards for compliance program health and KPIs
Own and operate the GRC platform. Configure control mappings, manage integrations, and ensure the platform accurately reflects our posture
Integrate compliance checks into CI/CD pipelines, infrastructure-as-code reviews, and deployment processes. Make compliance a natural part of how engineers ship code
Build and maintain self-serve tools that streamline customer security questionnaires, trust center content, and due diligence processes
Partner with GTM teams to handle strategic customer security assessments. Help articulate Fieldguide’s compliance posture in sales processes
Reduce time-to-response on security reviews through automation and scalable processes
Evaluate and monitor third-party vendors for security and compliance risk. Build and maintain the vendor assessment program
Create and deliver security awareness training. Draft security best practices and drive company-wide adoption
Qualification
Required
6+ years in security compliance, GRC, or audit with direct experience managing SOC 2 and ISO 27001 programs through full audit cycles
Experience with compliance automation platforms, especially building and automating controls and integrations
Working knowledge of AWS security services, CloudTrail, Config, Security Hub, IAM, and the ability to query and integrate them programmatically
Familiarity with infrastructure-as-code tools (Terraform, CloudFormation) and CI/CD pipelines
Framework expert and operator: You've managed SOC 2 and ISO 27001 programs through full audit cycles. You know the difference between controls on paper and controls that actually work
AI-native instincts: You see AI and agents as a way to fundamentally change how compliance operates. You're excited to use LLMs for tasks like evidence narrative generation, control gap analysis, policy drafting, and security questionnaire responses, so compliance scales through automation rather than grinding through spreadsheets
Builder and automator: You instinctively look for ways to eliminate manual work. You write code or build integrations to automate evidence collection, monitoring, and reporting
Technically credible: You understand cloud architectures (AWS), CI/CD pipelines, and modern software development well enough to evaluate controls and have productive conversations with engineers
Clear communicator: You explain compliance requirements to engineers without being bureaucratic, present to auditors and customers with confidence, and write clear policies
Comfortable with ambiguity: You're building compliance infrastructure at a growth-stage company. You thrive in managing complex, multi-workstream programs with many moving pieces
Preferred
Experience with AI governance frameworks (ISO 42001) or the intersection of AI compliance and traditional security compliance is a plus
Prior experience in public accounting or audit firms, understanding our customers' world from the inside, is a plus
CISA, CISSP, CISM, or ISO 27001 Lead Auditor certification is a plus
(Nice to have) Hands-on technical skills: you write production-quality code or scripts (Python, TypeScript, or similar) and can build integrations with APIs and cloud services
(Nice to have) FedRAMP experience: you've been through at least one authorization or significant assessment, including SSP development, 3PAO coordination, and ConMon
Benefits
Competitive compensation packages with meaningful ownership
Flexible PTO
401k
Wellness benefits
Technology & Work from Home reimbursement
Flexible work schedules
Company
Fieldguide
Agentic AI for Audit and Advisory.
Funding
Current Stage
Growth StageTotal Funding
$125MKey Investors
Goldman Sachs AlternativesKPMGBessemer Venture Partners
2026-02-02Series C· $75M
2025-10-23Corporate Round
2024-03-26Series B· $30M
Recent News
2026-02-06
Venture Capital Firms
2026-02-03
thesaasnews.com
2026-02-03
Company data provided by crunchbase