The opportunity
The Security team at LangChain treats compliance as a business enabler, not a checkbox. We move fast, build customer trust across regulated industries, and are actively rethinking what modern security compliance looks like at an AI-native company.
What you'll do
Build and automate our compliance operations layer, including evidence: pipelines, control monitoring, and agentic systems for always-on visibility into our compliance posture.
Work directly with Engineering to embed security and privacy controls into: our products, including deletion pipelines, PII detection, access audit logging, and fine-grained data access controls.
Maintain and scale our certification and audit programs across SOC 2, ISO: 27001, ISO 27701, ISO 42001, HIPAA, GDPR, CCPA, EU-US Data Privacy Framework, and others. Drive audit readiness, identify overlapping requirements, and reuse evidence across frameworks to continuously strengthen our security story.
Partner with Legal on security and privacy contract execution, covering DPAs,: BAAs, security addenda, and vendor terms. Build the templates, playbooks, and review processes that enable fast, reliable execution in regulated verticals and unblock enterprise sales.
Monitor adherence to security and privacy contractual obligations across all: signed agreements, building the operational workflows and tracking mechanisms to stay on top of commitments as our customer base grows.
Contribute to LangChain's customer trust program: security questionnaire responses, due-diligence reviews, and the trust documentation and whitepapers that give regulated-industry customers confidence in our security posture.
What they're looking for
- Support vendor privacy risk assessments during onboarding and renewals.