Risk and Compliance LeadActive$210K–$270K

The opportunity

Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation.

What you'll do

  • Own the end-to-end certification roadmap (SOC 2 Type II, ISO 27001, and: future frameworks like ISO 42001) including scoping, gap assessments, remediation, and audit execution

  • Manage relationships with external auditors and drive the annual audit: calendar so certifications renew without last-minute scrambles

  • Own and maintain the company's master security risk register including risk: identification, scoring methodology, treatment plans, and residual risk reporting

  • Build and maintain continuous compliance monitoring so control status: reflects real-time state rather than point-in-time snapshots

  • Own the core audit artifacts that back every certification including ISMS: documentation, Statements of Applicability, risk assessments, and potentially FedRAMP System Security Plans (SSPs)

  • Run regular audits and readiness assessments, and track remediation of findings and control gaps to closure

What they're looking for

  • Support GDPR and broader privacy compliance alongside the Legal/Privacy team,: without owning the legal interpretation of requirements
  • Partner with the GRC Engineer to define what evidence collection and control: monitoring should be automated versus manually reviewed
  • Track and report on compliance posture and audit findings to security leadership