Security Program Manager enhancing compliance and security programs within cloud-based finance operations platform at Ramp. Driving initiatives across risk management, assurance and integrating AI governance.
Responsibilities
Lead and support security and compliance programs to achieve and maintain key certifications and attestations (e.g., SOC 2, ISO 27001, PCI-DSS, SOX, ISO 42001, AIUC-1), while building scalable processes to support future framework expansion and geographic growth.
Partner cross-functionally with Product, Engineering, IT, Finance, Legal, People, and Go-to-Market teams to translate regulatory, customer, and emerging requirements (including AI governance considerations) into practical, actionable controls.
Support the design, implementation, and monitoring of IT General Controls (ITGCs), automated controls, and financial system governance processes, including access management, change management, and configuration oversight.
Support and lead audit and assurance activities, including planning and coordination with external auditors and independent assessors, conducting control walkthroughs, managing evidence collection, and maintaining audit-ready documentation.
Strengthen customer assurance programs by evaluating vendor security practices, responding to customer due diligence requests, and identifying opportunities for automation and continuous monitoring within GRC workflows.
Build scalable audit management processes and documentation systems that will support future expansion to additional geographies and compliance frameworks
Requirements
5+ years of experience in security, risk, audit, or compliance roles within cloud-based or highly regulated environments (e.g., SaaS, financial services).
Working knowledge and experience supporting security certifications and regulatory audits (e.g., SOC 2, ISO 27001, PCI-DSS, SOX), including control documentation, testing, evidence collection, and auditor coordination.
Experience contributing to risk management and/or third-party risk programs, including performing risk assessments, maintaining risk documentation, or evaluating vendor security controls.
Strong written and verbal communication skills, and demonstrated ability to collaborate across technical and non-technical teams and clearly explain security and compliance requirements, including emerging areas such as AI governance.
Experience managing time-bound workstreams in fast-paced environments, and serve as a subject matter expert on evolving compliance and emerging risk areas, including AI governance considerations.
Benefits
100% medical, dental & vision insurance coverage for you
Partially covered for your dependents
One Medical annual membership
401k (including employer match on contributions made while employed by Ramp)
Flexible PTO
Fertility HRA (up to $10,000 per year)
Parental Leave
Unlimited AI token usage
Pet insurance
Centralized home-office equipment ordering for all employees
Director of Business Unit Security Officer leading risk assessments and safeguarding IT solutions across Canadian Technology Business Units. Collaborating with the Head of Information Security and Risk Management for compliance and security awareness.
Health and Safety Assistant responsible for analyzing workplace safety documentation and training service providers on compliance actions. This role involves direct training and guidance for clients.
Senior Security Engineer at Pave Bank enhancing security practices and addressing vulnerabilities in fintech. Focus on safeguarding programmable banking infrastructure through proactive security measures.
Assistant Security Director helping oversee hotel security operations and coordinating with local law enforcement. Involved in training security personnel and managing emergency responses.
Cybersecurity Auditor performing security analyses and CCRI for NexThreat. Ensuring compliance with cybersecurity regulations and providing actionable recommendations.
Security Engineer at Benchling responsible for safeguarding sensitive data through security programs and infrastructure. Collaborating with engineering teams to implement security features in AWS cloud environments.
Technicien QSSE supportant la politique de qualité et sécurité au sein de l’Adapei 63. Rattaché à la direction pour déployer les processus et aider les équipes dans leurs missions.
IT & Cybersecurity Manager overseeing IT systems and compliance for Crown Roofing. Leading digital transformation and AI strategy in a hybrid work environment.
Coordinating IT governance policies and managing risks at Instituto de Responsabilidade Social Sírio - Libanês. Ensuring compliance with regulations and effectively reporting IT governance KPIs.
Program Assistant providing administrative support for Community Security Initiative. Coordinating meetings, maintaining records, and assisting with event logistics.