
Compliance Lead
Added
9/8/2026
How Syndicated Job Posts Work
This Role is Closed
This is a Featured Job
Note: We've kept the name of the company private. If you'd like to know the company before requesting an intro, just email us at hello [at] fractionaljobs.io
Voltry is a neutral condition and provenance standard for high-value compute hardware. We issue cryptographically signed certificates that insurers and lenders rely on, so our compliance posture is not paperwork, it is part of the product. We are preparing for SOC 2 Type I, with a Type II window to follow, ahead of insurance carrier and enterprise partner diligence.
​
You would own the compliance program end to end for a very small, heavily automated team. Unusual context you should be comfortable with: most of our engineering is done by AI agents under human direction, our audit trails are append-only by construction, and much of the evidence an auditor wants (change management, review records, monitoring) already exists as data. Your job is to shape that into a certifiable program, not to build it from zero.
​
What you will do
- Run a SOC 2 readiness assessment against what exists and produce the gap plan with owners and dates
- Draft and right-size the policy suite (infosec, access control, vendor management, incident response, BC/DR, data retention) to a three-person company, no enterprise boilerplate
- Stand up a compliance automation platform (Vanta, Drata, or similar), wire it to GitHub, Google Cloud, and Netlify, and map controls to the evidence we already generate
- Define access review and offboarding cadence, log retention, and the monitoring story, including alerting that does not depend on the platform it monitors
- Select and manage the audit firm, run the Type I audit, then own the Type II observation window
- Support partner and carrier security questionnaires and diligence calls
​
First 90 days
- Readiness map delivered, policy suite adopted, platform live with controls mapped, auditor selected, Type I scheduled
​
You are probably
- Someone who has taken at least two startups through SOC 2 from zero, ideally under 20 people at the time
- Fluent in GCP-native infrastructure (IAM, Secret Manager, Cloud Run, audit logs) and GitHub-based change management
- Comfortable reading a technical control (branch rulesets, WIF, signed evidence chains) rather than asking engineering to fill in spreadsheets
- A plus: exposure to insurance or financial services diligence, ISO 27001, or working alongside AI-assisted engineering teams
​
Engagement
- Fractional, 5-10 hours per week to start, heavier around the audit itself
- Remote, reports directly to the founder
- Scope may extend to ISO 27001 and customer-driven SOC 1 if the business requires it later
How to Apply
Note: This is a syndicated job post. Fractional Jobs found it on the web, but we are not working with the client directly, so we don't have control over or knowledge of the application process. To apply, click on the "View Application" button and follow the application's instructions. Let us know how it goes!
How to Get in Touch
Hit that "Request Intro" button below. Include any relevant links so we can get to know you better.
Your brief intro note should clearly address:
If we think there's a fit, we'll reach out to schedule an intro call. Looking forward!
MoreOtherJobs
Send fractional jobs,
playbooks, and more to
%20(1).webp)