Krisp is looking for a Security Program Manager to own and drive key aspects of our security compliance and customer security assurance programs.
This role will be responsible for maintaining Krisp’s readiness for security and compliance certifications and supporting external audits, including SOC 2 Type II, PCI DSS, HIPAA, FedRAMP, and other frameworks applicable to our business and customers. The Security Program Manager will work closely with Security, Engineering, IT, Legal, Privacy, Finance, People, and other internal stakeholders to ensure that required controls are implemented, documented, tested, and continuously maintained.
A significant part of the role will also focus on customer security assurance. The Security Program Manager will serve as a key point of contact for security and privacy questions from customers and prospects, including completing security questionnaires, supporting customer security reviews, and providing accurate information about Krisp’s security, privacy, compliance, and risk management practices.
This is a hands-on role for someone who understands security and compliance requirements and can translate them into practical processes across a fast-moving technology organization.
Security Compliance & Audit Management
• Manage and continuously improve Krisp’s security compliance program.
• Coordinate and support external certification and compliance audits, including SOC 2 Type II, PCI DSS, HIPAA, FedRAMP, and other applicable frameworks.
• Own audit preparation and readiness activities, including evidence collection, control validation, documentation, auditor coordination, and remediation tracking.
• Partner with control owners across Engineering, Security, IT, People, Legal, Finance, and other functions to ensure controls are properly implemented and operating effectively.
• Maintain compliance calendars, evidence repositories, control documentation, policies, procedures, and other audit artifacts.
• Track audit findings, control deficiencies, exceptions, and remediation plans through closure.
• Identify opportunities to automate evidence collection and other recurring compliance activities.
• Support the evaluation and implementation of additional security certifications and frameworks based on customer and business requirements.
• Help map controls across multiple frameworks to reduce duplicated work and create a scalable compliance program.
Customer Security Assurance
• Own or coordinate responses to customer and prospect security questionnaires, including security, privacy, compliance, infrastructure, data protection, and risk-related questions.
• Support customer security assessments, due diligence reviews, and security discussions during enterprise sales and procurement processes.
• Partner with Sales, Customer Success, Legal, Privacy, Engineering, and Security teams to provide timely and accurate responses to customer security inquiries.
• Maintain a centralized and reusable knowledge base of approved security and privacy responses and supporting documentation.
• Provide customers with appropriate compliance documentation, reports, certifications, policies, and other security artifacts while following internal confidentiality requirements.
• Identify recurring customer security requirements and communicate them internally to help influence security and compliance priorities.
• Help streamline and scale the security review process as Krisp’s enterprise customer base grows.
Privacy & Regulatory Compliance
• Support Krisp’s compliance with applicable privacy and data protection requirements, including GDPR and CCPA/CPRA.
• Work closely with Legal and Privacy stakeholders on privacy assessments, customer privacy inquiries, data processing requirements, and related compliance activities.
• Maintain familiarity with evolving security and privacy regulations and assess their potential impact on Krisp’s products and operations.
• Support documentation of data protection, retention, access control, incident management, and other security/privacy processes as required.
Security Governance, Risk & Program Management
• Maintain and improve security policies, standards, procedures, and control documentation.
• Support security risk assessments and track identified risks and remediation activities.
• Help manage third-party/vendor security risk assessments and related compliance activities.
• Define and track security and compliance program metrics, milestones, risks, and dependencies.
• Coordinate security initiatives involving multiple teams and ensure deliverables are completed on schedule.
• Drive continuous improvement of Krisp’s governance, risk, and compliance processes.
Minimum Qualifications
• 3+ years of hands-on experience in security compliance, GRC, security assurance, or a similar role.
• Demonstrated hands-on experience supporting and/or managing audits and assessments for multiple frameworks, including SOC 2 Type II, PCI DSS, HIPAA, and/or FedRAMP.
• Practical experience with audit preparation, evidence collection, control testing, remediation tracking, and working directly with external auditors or assessors.
• Experience completing customer security questionnaires and supporting enterprise customer security assessments.
• Strong working knowledge of common security controls and practices, including identity and access management, vulnerability management, change management, incident response, business continuity, logging and monitoring, encryption, and third-party risk management.
• Working knowledge of GDPR and CCPA/CPRA requirements and their relationship to security and privacy programs.
• Ability to interpret security, regulatory, and compliance requirements and translate them into actionable controls and processes.
• Strong project and program management skills with the ability to coordinate multiple stakeholders, deadlines, audits, and workstreams simultaneously.
• Excellent written and verbal communication skills, including the ability to communicate security and compliance topics clearly to both technical and non-technical audiences.
• Strong attention to detail and ability to maintain accurate, audit-ready documentation.
• Professional proficiency in English.
Preferred Qualifications
• Experience working in a SaaS, cloud, or technology company, particularly in a B2B/enterprise environment.
• Experience building or scaling a security compliance/GRC program rather than only participating in individual audits.
• Familiarity with additional security and compliance frameworks such as ISO 27001, NIST CSF, NIST 800-53, CIS Controls, or CSA CCM.
• Experience with GRC and security questionnaire automation platforms.
• Familiarity with cloud security environments and major cloud providers such as AWS, Azure, or GCP.
• Understanding of modern software development and cloud infrastructure practices, including CI/CD, SDLC, vulnerability management, and infrastructure security.
• Experience supporting enterprise sales cycles and responding to security requirements from large or regulated customers.