Demo

Security & Compliance Lead

iFrame
San Francisco, CA Full Time
POSTED ON 7/25/2026
AVAILABLE BEFORE 8/23/2026
Trust & compliance

Security & Compliance Lead

Build and run the security and compliance program for a fast-growing GPU cloud. You'll own SOC 2 Type II, ISO 27001 certification, HIPAA-ready posture, and the BYOK / HYOK roadmap. You'll be the named person on every customer security questionnaire.

Apply by email All open roles

Team Trust & compliance

Location San Francisco / Remote (US)

Type Full-time

  • Senior

Stack SOC 2 / ISO 27001 / HIPAADrata or VantaLinuxAWS KMS / Cloud HSMCustomer questionnaire tooling

Apply by email

Hiring manager replies within 5 business days.

The team

About The Team

Trust & compliance is a small standalone function that reports to the founder. You'll start as the first dedicated hire on the team and pick up a security engineer in the first six months, with budget for an external auditor and a fractional vCISO if you want one.

Reports to the founder. Owns the trust pages, the audit calendar, and the security questionnaire library.

The role

What you'll do

  • 01 Run the annual SOC 2 Type II audit — scoping, evidence collection, control testing, report delivery — and keep the audit window stable each year.
  • 02 Drive ISO 27001 certification end-to-end (Statement of Applicability, ISMS, internal audit, certification body).
  • 03 Maintain HIPAA-ready posture and the BAA program; keep a small but real list of healthcare customers signable.
  • 04 Ship BYOK then HYOK on the platform with the runtime and cluster teams. Own the customer-facing key-management story.
  • 05 Own customer security questionnaires and pre-sales review (CAIQ v4, SIG, custom). Scale the answer library so AEs do not bottleneck on you.
  • 06 Handle incident response, breach-notification clock, and post-mortem write-ups for any security incident.

The bar

What we're looking for

  • Seven-plus years in security and compliance at a cloud / SaaS / infrastructure company; at least one full SOC 2 Type II under your name.
  • Operational experience running an ISMS — ISO 27001 certified or one cert away.
  • Real understanding of cloud-infra security primitives: KMS / HSM, hardware roots of trust, network segmentation, IDS/IPS, vulnerability management.
  • Comfort writing — questionnaire answers, customer-facing trust pages, board-level updates.
  • Calm decision-making under pressure. Real incident-response experience preferred.

Bonus

Nice to have, not required

  • FedRAMP Moderate or DOJ CJIS familiarity (we are not pursuing, but customers ask).
  • Experience with HSM / KMS engineering and key-management protocol design.
  • Privacy-program experience (GDPR Art. 28, CPRA service-provider).
  • Past CISO or security lead of a compute / GPU / inference business.

Compensation

In writing, like everything else

We publish bands. We meet them. The number you see on the offer is the same number your future peers got at the same level. We do not negotiate; we level.

Base

$240,000 – $310,000 USD.

Equity

Senior-leadership equity grant, refreshed on tenure milestones.

Notes

Budget for an external auditor and a fractional vCISO is approved on day one.

How to apply

One email is enough

Send a short note to careers@iframe.ai with the role title in the subject line. Include your CV or LinkedIn, one or two links to work you're proud of, and a sentence on why this role specifically. Hiring managers reply within five business days, regardless of outcome.

  • 01

Application

A hiring manager reads every email. Reply within five business days.

  • 02

Manager call

30–45 minutes. Scope, role, mutual fit. We share the comp band on this call.

  • 03

Technical loop

3–4 sessions on the same day. Real problems, no homework, no whiteboard riddles.

  • 04

Offer

Same-week offer at the published band for your level. Start dates are flexible.

Equal opportunity

We hire on the work. Race, gender, age, nationality, religion, sexual orientation, disability, and veteran status do not factor into our decisions. We sponsor visas for senior roles in the US, UK, and EU — bring it up on the manager call.

Need an accommodation for the interview process? Mention it in your application or write careers@iframe.ai.

Also open

Other roles you might consider

  • Runtime

Inference Acceleration Engineer

Ship the next 2× on the open-source model catalog. Triton, CUDA, ROCm. You will publish what you ship.

View role

  • Research lab

Distributed Training Researcher

Lead a paper / quarter on multi-thousand-GPU pre-training. Co-appointment with a partner university available.

View role

  • Cluster & SRE

Cluster Site Reliability Engineer

Bring up B300 racks, drive InfiniBand fabric to spec, run capacity planning across seven regions. Pager included.

View role

All open roles

One last thing

If this role isn't quite right but you'd be a fit at iframe.ai, write anyway.

Senior engineers and researchers can apply outside the listed roles. The bar is the same. The reply window is the same.

Apply: Security & Compliance Lead General application

Salary : $240,000 - $310,000

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Security & Compliance Lead?

Sign up to receive alerts about other jobs on the Security & Compliance Lead career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$101,515 - $131,950
Income Estimation: 
$123,739 - $165,355
Income Estimation: 
$150,417 - $183,047
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$220,784 - $286,649
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at iFrame

  • iFrame San Francisco, CA
  • Go-to-market Reserved Capacity Account Executive Close multi-year reserved-capacity contracts with sophisticated buyers — AI labs, neocloud resellers, AI-n... more
  • 22 Days Ago


Not the job you're looking for? Here are some other Security & Compliance Lead jobs in the San Francisco, CA area that may be a better fit.

  • Experis San Francisco, CA
  • Our client, a leading organization in the technology and cybersecurity sector, is seeking a Lead Cloud Security Compliance Engineer to join their team. As ... more
  • 12 Days Ago

  • Lila Sciences San Francisco, CA
  • Your Impact at LILA Cloud Security & Compliance Lead is responsible for the end-to-end security, governance, risk management, and regulatory compliance of ... more
  • 27 Days Ago

AI Assistant is available now!

Feel free to start your new journey!