26 drata jobs at 24 companies in San Francisco, CA
1mo
Save
Mark Applied
Hide
1mo
Security & Compliance Operations Manager
San Francisco, California, United States
$120k-$180k/yrOnsiteFull Time
Mintlify: AI-powered platform for generating and hosting software documentation.
3+ YOE3+ years GRC/compliance program management with direct audit ownership, hands-on Drata (or Vanta) administration, vendor and auditor management, strong follow-through and automation bias.
Substack: Platform for independent writers to publish and monetize newsletters.
3+ YOE3–5 years in corporate IT/systems administration; hands-on Okta and Apple-focused MDM experience (Iru/Kandji/Jamf); familiarity with SOC 2 and compliance platforms (Vanta/Drata); strong communication and documentation skills.
Volta: Building and operating GPU-dense infrastructure for AI factories.
3+ YOE3+ years in information security with compliance/GRC/audit experience, hands-on ISO 27001 or SOC 2 work, GRC platform experience, risk assessment skills, strong writing and collaboration with engineers.
Replit: Cloud-based platform for building and hosting software applications.
8+ YOE8+ years in GRC or information security; deep cloud (GCP/AWS) and security architecture; strong regulatory experience; automation mindset with GRC tools.
GCP, AWS, Vanta, Drata, SOC 2, ISO 27001, PCI, HIPAA
Baseten: Scalable infrastructure platform for deploying and serving AI models.
5+ YOE5+ years GRC or security compliance experience in SaaS/cloud; strong knowledge of SOC 2, ISO 27001, NIST, GDPR; audit and certification management; third-party risk and cross-functional collaboration.
WindBorne Systems: Operates smart weather balloons to provide global atmospheric data.
3+ YOE3+ years in compliance audits and US government compliance; experience with CMMC, FedRAMP, NIST frameworks; security, cloud, and GRC tooling expertise; ability to obtain security clearance.
Drata, Vanta, eMASS, Tenable Security Center, Burp, SIEM, AWS, Azure
Vapi: Build and deploy AI-powered voice agents via flexible APIs.
5+ YOE5+ years engineering experience in cloud-native SaaS; strong security experience for multi-tenant cloud environments; proficiency with AWS, Kubernetes, and Postgres; ability to write/review code and implement shift-left security.
Obsidian Security: Provides cybersecurity and threat detection for enterprise SaaS applications.
8+ YOE8+ years building and operating identity, endpoint, or platform infrastructure; deep Okta and Jamf Pro experience; IaC with Terraform/OpenTofu; scripting in Python or PowerShell; strong written and verbal communication.
HEN Technologies: Building an AI-powered intelligent ecosystem for fire suppression.
12+ YOE4+ Mgmt12+ years in information security with 4+ years leading a security function; SOC 2 leadership; strong cloud (GCP) and product security experience; hands-on technical credibility with IaC/CI/CD and vendor risk/IR processes.
AKASA: Develops AI-powered automation software for healthcare revenue cycle management.
8+ YOE2+ MgmtRequires 8+ years in security compliance, GRC, or risk management, including 2+ years leading a team or function; expertise in HITRUST, SOC 2, HIPAA, AI governance, and compliance automation.
NIST AI RMF, Okta, Google Workspace, Kandji, Iru, SentinelOne, Nightfall, AWS, Vanta, Drata, Hyperproof, ChatGPT, Claude, Python, Zapier, Tray.io
San Francisco or New York City or London or Sydney
$190k-$215k/yrOnsiteFull Time
Sigma Computing: Cloud-native analytics platform featuring a spreadsheet-style interface.
4+ YOE4+ years GRC experience in SaaS/tech, proven track record building GRC programs and leading SOC 2/ISO 27001/HIPAA audits, experience with ERM frameworks (COSO, ISO 31000, NIST RMF), data privacy (GDPR/CCPA), policy and control development, strong communication.
Clearstory: SaaS platform for managing construction project change orders.
4+ YOE4-7 years in IT operations, security operations, or SaaS business operations; hands-on SOC 2 audit coordination; Google Workspace admin; experience with compliance platforms; SaaS vendor management; automation mindset; collaborates with CTO; proactive, process-driven.
Anomali: AI-powered platform for threat intelligence and security analytics.
8+ YOE3+ Mgmt8+ years in GRC/compliance with 3+ years leadership; hands-on FedRAMP, ISO 27001, SOC 2 experience; regional cloud frameworks (DESC, Saudi NCA/CCC, IRAP); cloud security (AWS/Azure/GCP); strong stakeholder and written communication.
SalesforceNYSE: CRM: Sells cloud-based customer relationship management and business software solutions.
2+ YOE2–4 years GRC/compliance/audit or information security experience; working knowledge of at least two of SOC 2, HIPAA, ISO 27001, or GxP; proficiency with GRC/audit tools and Microsoft Office or Google Workspace; strong communication skills.
SOC 2, HIPAA, ISO 27001, GxP, Microsoft Office Suite, Google Workspace, Drata, Vanta, OneTrust, ServiceNow GRC
Neurophos: Develops high-performance photonic processors for AI inference acceleration.
8+ YOERequires 8+ years in infrastructure security, security engineering, or cybersecurity management, including 3+ years leading security programs; expertise in cloud security, networks, IAM, endpoints, incident response, and compliance.
Anthropic: Developing safe and reliable artificial intelligence systems.
8+ YOE8+ years building backend systems, data pipelines, or internal platforms; proficiency in Python or Go; experience with cloud platforms and infrastructure-as-code; strong systems thinking and experience with integrations or data infrastructure.
Python, Go, AWS, GCP, Azure, Claude, ServiceNow, Vanta, Drata, OneTrust, REST APIs, webhooks, CI/CD, ELT, ETL, infrastructure-as-code, version control
FigmaNew York Stock Exchange: FIG: Collaborative interface design and prototyping software for teams.
4+ YOE4+ years in information security, compliance, or risk; hands-on experience with SOC 2, ISO 27001, FedRAMP, PCI-DSS, or SOX ITGC; audit experience; strong communication and cross-functional collaboration skills.
BackOps AI: AI-powered platform automating logistics and supply chain workflows
4+ YOE4+ years cloud security/DevSecOps experience; deep AWS/GCP and Kubernetes knowledge; Terraform/CloudFormation and CI/CD automation; IAM, secrets, SAST/DAST, container security; Python or Go programming.