Please mention DailyRemote when applying
See how much of this job your resume covers, and what’s missing.
Want a recruiter to go through it line by line?
Get professional reviewQuestions interviewers often ask for this role, with sample answers.
Upload your resume and we draft a letter for this exact role, tailored to what it asks for.
You will own the strategy and requirements for the company's Trust layer, integrating security, privacy, and compliance into the product lifecycle. Additionally, you will lead the trust transformation, manage audits, and serve as the primary external contact for customer security and compliance requirements.
Company Overview
Our client builds technology that helps families access public benefits. It also helps governments, health plans and other organizations run those programs more effectively. Their work with state and federal agencies, Medicaid organizations and health plans is growing fast. As it does, trust, security, privacy and compliance have become core product requirements.
Your Role
This is not a typical PM role where compliance is just one feature area. It's also not a policy-only compliance job, and not a pure security engineering seat. We're looking for a trust and compliance expert who is also an excellent product leader. You'll own the strategy and requirements for the company's Trust layer: the platform features that make security, privacy, compliance and auditability part of how the software works. You'll also run the trust and compliance program day to day, and own a company-wide trust transformation. This is a senior, hands-on individual-contributor role. You'll understand a requirement, work out what it means for the business and the software, bring the right people together, and see the work through.
You’ll:
Lead the Trust Transformation
Own the company's new trust operating model across Product, Engineering, Customer Delivery and company operations.
Turn regulatory, customer, security and privacy requirements into clear product, technical and operational requirements.
Partner with the Trust engineering lead to design and build the Trust layer.
Set durable approaches to production access, data handling, environment separation, release governance and evidence collection.
Build Trust Into the Product
Own product direction for:
identity and access management, with least-privilege access
tenant and environment isolation
data classification, privacy, consent and data provenance
audit logging and change history
retention and data governance
secure release and deployment controls
continuous control monitoring
Move controls out of manual processes and into reusable, software-enforced capabilities, so the compliant path becomes the default path.
Own the Trust & Compliance Program
Maintain policies, controls and evidence in Vanta, and coordinate control owners across the company.
Own the compliance roadmap and turn new requirements into cross-functional initiatives people can execute.
Keep a clear view of risks, control gaps, exceptions and remediation commitments.
Give leadership clear recommendations when trust requirements force business or product trade-offs.
Lead Audits, Assurance & Security Programs
Keep the company continuously ready for recurring SOC 2 audits.
Coordinate external audits, penetration tests and vendor risk reviews, and drive findings through to closure.
Launch the NIST 800-series alignment program and help chart the path toward FedRAMP-aligned practices.
Be the External Trust Lead
Act as the main contact for customer security, privacy, compliance and AI-governance requirements.
Lead responses to security questionnaires, privacy and AI-use assessments, and procurement reviews.
Represent the company with security, legal and procurement teams at government agencies, Medicaid organizations and health plans.
Turn recurring customer requirements into reusable controls instead of solving them one customer at a time.
You Bring:
Significant hands-on experience owning security, privacy, trust, risk or compliance programs inside a software company.
Experience in regulated environments such as government, public-sector tech, healthcare, Medicaid, health plans or similar high-trust industries.
Working knowledge of SOC 2, NIST 800-series controls, HIPAA and government security standards.
A track record of leading audits, security questionnaires, penetration-testing programs and remediation.
Strong product management skills: problem definition, requirements, prioritization, roadmap ownership and cross-functional delivery.
Enough technical fluency to go deep with senior engineers on architecture, access models, data flows and controls.
The credibility and communication skills to stand in front of sophisticated customer security teams.
Comfort working autonomously while the function and the product are both still being built.
You must be based in the U.S.
What’s Offered
A fully remote role within the U.S.
Competitive compensation based on experience.
Real ownership: you'll shape how trust is built into both the platform and the way the company operates.
A team that may grow around you as the function scales.
Mission-driven impact: your work helps families access the public benefits they rely on.
Close collaboration with Product & Engineering leadership in a fast-growing company.
Stop the endless job search. Our AI finds and applies to the best jobs for you.
Featuring 219,833+ Jobs in Product Manager
Answer easy questions
219,833+ jobs across 15+ categories
Get your best job matches
Only hand-screened, legit jobs
Find a remote job faster
No ads, scams, or junk
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”