← Back to results

Security & Compliance Operations Manager

Join Mintlify as the first dedicated GRC Program Manager to lead security and compliance for a rapidly growing documentation platform.

Location
San Francisco
Compensation
Not disclosed
Level
mid
Type
full time

Requirements

Experience
3+ years

Benefits

Health Insurance 401k Match Equity/Stock Options Paid Time Off Wellness Stipend Free Meals Team Offsite

Joblaze summary

The Security & Compliance Operations Manager at Mintlify is responsible for overseeing multiple compliance programs, ensuring audits are managed effectively and maintaining relationships with vendors and auditors. This role requires expertise in compliance platforms like Drata and a strong background in GRC or security operations, ideally with experience in early-stage startups. The position suits someone who is meticulous and proactive, capable of driving automation and managing complex processes without getting bogged down in details. Mintlify's small but impactful team is focused on rapid growth and fostering a culture of learning and unique contributions.

Joblaze insights

Quick facts

How much experience is required?
At least 3 years of relevant experience for this Security & Compliance Operations Manager role.
What's the tech stack?
Joblaze extracted these technologies from the posting: ISO 42001, SOC 2, ISO 27001, Drata, Microsoft SSPA, GDPR.
What seniority level is this role?
Mintlify targets mid-level candidates for this position.
Is this full-time or contract?
Full-time for this Security & Compliance Operations Manager role at Mintlify.

From the original posting

Why Mintlify?

We're on a mission to empower builders.

  • Massive reach: Our docs platform serves 100 million+ developers every year and powers documentation for 20,000+ companies, including Anthropic, Microsoft, PayPal, Spotify, Coinbase, X, and over 20% of the last YC batch.

  • Small team, huge impact: We recently passed 65 employees and raised a $45 million Series B led by A16Z and Salesforce Ventures. Each new hire has a huge impact on shaping the company's trajectory.

  • Culture of slope over y-intercept: We value learning velocity, grit, and unapologetically unique personalities.

We grew in value faster than headcount and we’re looking to align the two quickly.

The Role

We're hiring our first dedicated GRC Program Manager to own the security & compliance program that our enterprise business runs on: SOC 2 Type II, ISO 27001, ISO 42001, GDPR, and Microsoft SSPA. The program exists and is well-documented — audits are mid-flight, the vCISO and auditors are engaged, the platform (Drata) is deployed. What it needs is a single accountable operator.

What You'll Do

  • Run five compliance programs end-to-end — own the audit calendar, evidence collection, remediation tracking, and auditor relationships (Sensiba for SOC 2/ISO; A-LIGN for Microsoft SSPA)

  • Administer Drata — keep monitors green, assign and validate evidence, manage policies and the trust center

  • Own the vendor bench — drive the weekly Rhymetec vCISO engagement, manage renewals and contracts across the security/compliance vendor portfolio

  • Run the standing processes — security questionnaire escalation, inbound vendor security reviews, bug bounty coordination (triage, researcher comms, payouts), trainings and access-review cadences

  • Be the customer-facing compliance voice — trust center, DPAs, subprocessor list, and enterprise security requirements (Microsoft, Coinbase, Okta-style programs)

  • Coordinate, don't silo — route technical work to Engineering DRIs with clear asks, and keep leadership out of the coordination loop

What We're Looking For

  • 3+ years in GRC / compliance program management / security operations with direct audit ownership

  • Hands-on compliance-platform administration (Drata, Vanta, or similar)

  • Vendor and auditor relationship management as the accountable owner

  • Meticulous follow-through — in this job, a dropped thread is an audit finding

  • Bias toward automation and pushing work to tests/vendors rather than doing it manually forever

  • Bonus Points: ISO 42001 / AI governance exposure. GDPR operations (DSARs, RoPA, consent tooling). Early-stage startup experience as a sole compliance owner.

Company Benefits:

  • Competitive compensation and equity

  • 20 days paid time off every year

  • 401k or RRSP

  • $420/month wellness stipend

  • 100% coverage for Health, dental, vision

  • Free Ubers to and from work

  • Free lunch and dinners

  • Annual team offsite (previously went to Alaska, Hawaii)

Similar positions

Discord
Senior Security Engineer, Enterprise Security
Discord · Remote (Western States)
Discord
Staff Software Engineer, Platform Security
Discord · San Francisco Bay Area or Remote
Discord
Director of Engineering, Safety
Discord · San Francisco Bay Area
Discord
Discord
Staff Software Engineer - Safety Experience
Discord · San Francisco Bay Area or Los Angeles Area