Senior Compliance Specialist
Position Description
SingleStore is building a real-time data platform that helps organizations transact, analyze and act on data in a single system. We are committed to operating with strong security, privacy and resilience standards across our products, services and internal operations.
We are seeking an experienced and highly motivated Senior Compliance Specialist to help scale our security, privacy and compliance programs. This role will be responsible for maintaining key certifications, driving cross-functional compliance initiatives, overseeing development and management of our privacy program, supporting compliance with the Digital Operational Resilience Act (DORA), and helping mature our Business Continuity Management System (BCMS).
The ideal candidate is practical, organized and collaborative, with experience translating regulatory and framework requirements into durable operational processes across technical and business teams.
Job Responsibilities
• Support governance activities across the security, privacy and compliance program, including maintaining Information Security Management System documentation, evidence, policies, procedures and audit trails.
• Help maintain and improve active certifications and attestations such as ISO/IEC 27001, SOC 2 Type II, HIPAA and PCI DSS, while coordinating with stakeholders across the business to ensure ongoing compliance.
• Drive readiness efforts for new compliance objectives, certifications and customer-driven assurance requirements.
• Participate in enterprise risk management activities, including risk methodology, risk assessments, treatment planning and follow-up with risk owners.
• Oversee the development, implementation and ongoing management of SingleStore’s privacy program in partnership with Legal, Security, IT and business stakeholders.
• Support compliance with applicable privacy and data protection requirements, including operationalizing controls and processes needed to meet regulatory and contractual obligations.
• Lead and coordinate DORA-related compliance activities, including control mapping, gap assessments, remediation tracking, evidence collection and cross-functional readiness planning.
• Help develop, maintain and mature the company’s Business Continuity Management System (BCMS), including associated governance, documentation, testing coordination and continuous improvement activities.
• Support vendor risk and third-party security management activities.
• Help define corrective action plans and track remediation of audit findings, non-conformities and control gaps with accountable owners.
• Contribute to security and compliance awareness initiatives and internal training efforts.
• Partner closely with Legal to support regulatory, contractual and policy compliance obligations across the business.
• Communicate compliance priorities, expectations and status clearly to technical, business and executive stakeholders.
Basic Qualifications
• 3+ years of experience in security, privacy or compliance.
• 2+ years of experience working for an Independent Software Vendor, SaaS provider or other technology company.
• Strong understanding of security and compliance frameworks and regulations such as ISO 27001, SOC 2 Type II, HIPAA, PCI DSS, GDPR, CCPA and DORA.
• Experience with compliance operations, audits, risk management processes and control-based programs.
• Experience coordinating cross-functional workstreams and driving follow-through across engineering, IT, legal and business teams.
• Working knowledge of cloud technologies and managed service environments.
• Strong written and verbal communication skills, with the ability to present clearly to both technical and non-technical audiences.
Preferred Qualifications
• Experience supporting compliance for managed cloud services or regulated technology environments.
• Experience building or operating a privacy program, business continuity program or related governance framework.
• Experience with DORA, business continuity, resilience, incident response governance or operational risk programs.
• Familiarity with and ability to support compliance initiatives related to the EU AI Act, NIST AI RMF, ISO/IEC 42001 and other emerging AI governance, risk and compliance frameworks.
• Familiarity with customer-facing compliance topics such as questionnaires, due diligence reviews and contractual security requirements.
• Professional certifications such as CISSP, CISA, CISM, CIPM, CIPT, CDPSE or ISO 27001 Lead Implementer/Lead Auditor.
• Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, Business or a related field.
• Demonstrated ability to work effectively across engineering, product, IT, sales, legal and executive leadership.
About SingleStore
SingleStore delivers our cloud-native database with the speed and scale to power the world’s data-intensive applications. With a distributed SQL database that introduces simplicity to your data architecture by unifying transactions and analytics, SingleStore empowers digital leaders to deliver exceptional, real-time data experiences to their customers. SingleStore is venture-backed and headquartered in San Francisco with offices in Sunnyvale, Raleigh, Seattle, Boston, London, Lisbon, Bangalore, Dublin and Kyiv.
Consistent with our commitment to diversity & inclusion, we value individuals with the ability to work on diverse teams and with a diverse range of people.
To all recruitment agencies: SingleStore does not accept agency resumes. Please do not forward resumes to SingleStore employees. SingleStore is not responsible for any fees related to unsolicited resumes and will not pay fees to any third-party agency or company that does not have a signed agreement with the Company.
SingleStore values individuals for their unique skills and experiences, and we’re proud to offer roles in a variety of locations across the United States. Salary is based on permissible, non-discriminatory factors such as skills, experience, and geographic location, and is just one part of our total compensation and benefits package. Certain roles are also eligible for additional rewards, including merit increases and annual bonuses.
For candidates residing in California, please see our California Recruitment Privacy Notice. For candidates residing in the EEA, UK, and Switzerland, please see our EEA, UK, and Swiss Recruitment Privacy Notice.