Replit
Risk and Compliance Lead
Foster City, CA · Full-time
Sponsorship not specifiedDetected 11 days ago
Machine LearningComplianceLeadershipCISSP
About the role
- You'll report to the Head of Security GRC, who retains overall accountability for the risk program, and work closely with Engineering to make sure controls hold up in practice, not just on paper.
- Run regular audits and readiness assessments, and track remediation of findings and control gaps to closure
- Track and report on compliance posture and audit findings to security leadership
Responsibilities
- Own the end-to-end certification roadmap (SOC 2 Type II, ISO 27001, and future frameworks like ISO 42001) including scoping, gap assessments, remediation, and audit execution
- Own and maintain the company's master security risk register including risk identification, scoring methodology, treatment plans, and residual risk reporting
- Build and maintain continuous compliance monitoring so control status reflects real-time state rather than point-in-time snapshots
- Own the core audit artifacts that back every certification including ISMS documentation, Statements of Applicability, risk assessments, and potentially FedRAMP System Security Plans (SSPs)
- Support GDPR and broader privacy compliance alongside the Legal/Privacy team, without owning the legal interpretation of requirements
- Partner with the GRC Engineer to define what evidence collection and control monitoring should be automated versus manually reviewed
Requirements
- Experience owning a formal risk register including risk identification, scoring methodology, treatment plans, and residual risk reporting to leadership
Nice to have
- Familiarity with FedRAMP or other government compliance regimes
- Experience standing up a compliance program from an early or pre-certification stage
- Meet the Replit Agent https://www.youtube.com/watch?v=IYiVPrxY8-Y
- This is a full-time role that can be held from our Foster City, CA office.
- The role has an in-office requirement of Monday, Wednesday, and Friday.
- 💹 401(k) Program with a 4% match (US Only)
- 🧑💻 Autonomous Work Environment
- 🚀 Quarterly Team Gatherings
Skills
- 8+ years in security compliance, IT audit, or GRC roles, with direct ownership of at least one SOC 2 and/or ISO 27001 certification cycle
- Working knowledge of common frameworks (SOC 2, ISO 27001, NIST CSF) and how to map controls across them
- Experience with GRC/compliance automation platforms (e.g., Anecdotes, Vanta, Drata, etc.) and continuous control monitoring
- Experience working directly with external auditors and managing an audit end to end
- Comfortable reading technical control evidence and having detailed conversations with engineers about how systems actually work
- Experience scoping or pursuing ISO 42001 or other AI governance frameworks
- Background in a developer tools, platform, or AI/ML product company
Compensation
- Manage relationships with external auditors and drive the annual audit calendar so certifications renew without last-minute scrambles
Benefits
- 💰 Competitive Salary & Equity
Company info
- Replit Blog https://blog.replit.com/
- Amjad TED Talk https://youtu.be/kCudFI4tcpg?si=l4ViCejV_f2RZkDi
- Operating Principles https://blog.replit.com/operating-principles
- Reasons not to work at Replit https://blog.replit.com/reasons-not-to-join-replit
This listing is sourced directly from Replit's careers page and normalized into a canonical job model.