Compliance Manager – Security & GRC (AI Start-up)
- Status
- Open
- Remote policy
- Not stated
- Employment type
- Not stated
- Salary
- 90,000-130,000 CHF / year
- Source
- swissdevjobs
- First observed
- 2026-10-03 18:27 UTC
- Last seen
- 2026-10-03 18:27 UTC
- Source claims posted
- 2026-10-01 22:00 UTC
- Consecutive misses
- 0 of 10
What the posting says
Salary: CHF 90'000 - 130'000 per year
Requirements:
You've run a certification programme (SOC 2, ISO 27001 or equivalent) end to end, through a real audit cycle, not just supported someone else's
You write precise, evidenced answers to security questionnaires that hold up under scrutiny, and you're honest about what the company doesn't do
Hands-on third-party risk experience: you've built or run a vendor review process and kept a subprocessor list accurate under contractual notice obligations
Strong evidence discipline and judgement: you capture evidence as work happens and know what to answer yourself versus escalate to Engineering, Security or Legal
Based in, or ready to relocate to, Prague, Berlin, Lisbon, Porto or Valencia, with the right to work in the EU (no visa sponsorship)
Responsibilities:
You'll join a fast-growing, well-funded AI start-up backed by one of Europe's top venture capital firms. They're building an AI operations platform for large enterprises, currently focused on retail and consumer goods. Their AI agents log into customers' core systems, such as SAP and supplier portals, and act inside them. That makes every enterprise deal a security review, and the company already holds SOC 2 Type II, ISO 27001 and ISO 42001, with GDPR and NIS2 commitments.
What you'll do
You'll own the compliance function and make the company 'reviewable': every customer, auditor or regulator gets an accurate, evidenced answer the first time they ask.
Own the Q&A library: the single source of truth for every due-diligence answer, mapped to the relevant frameworks, with owners, evidence and review dates
Run customer security reviews from intake to delivery, and keep the public trust centre and NDA-gated document portal up to date
Run the audit and certification calendar: SOC 2 renewal, ISO surveillance audits, NIS2 assessment, pen tests and customer audit requests, including evidence, auditor liaison and remediation
Keep the security and AI management systems operating between audits: risk register, policies, access reviews and internal audits
Own third-party and subprocessor risk: vendor reviews, data processing agreements, AI-provider commitments, and customer notifications when suppliers change
The team
You'll report to the Head of Engineering and work daily with the Security Lead. You'll be the first and, for now, the only person in this function, so you'll have real ownership from day one. The engineering team has around 20 people, about half at the home base in Prague and the rest in small hubs across Europe. The culture is built on ownership, direct feedback and using AI wherever it helps.
Technologies:
AI
AI Agents
REST
SAP
Security
GCP
More:
Rockstar Recruiting is hiring on behalf of a fast-growing, well-funded AI start-up, backed by one of Europe's top venture capital firms, that is building an AI operations platform for large enterprises, with customers among Europe's biggest retailers. This is a Compliance Manager role for someone who has run security certifications end to end and wants to own the function: customer security reviews, SOC 2 and ISO audits, vendor and subprocessor risk, and the answers and evidence behind them. You'll be the first person in this function, reporting to the Head of Engineering.
The team works from small hubs across Europe rather than fully remote, so the role is open to candidates based in, or ready to relocate to, Prague, Berlin, Lisbon, Porto or Valencia, with the right to work in the EU. Please get in touch with Tijana of Rockstar Recruiting to discuss further details: [email protected]
last updated 40 week of 2026
Quality
- + Salary range stated weight 35%
- x Remote policy stated weight 20%
- x Location stated weight 15%
- + Organisation stated weight 15%
- + Publication date stated weight 15%
Not enough history yet to judge honesty signals.
Timeline
-
*
#1159129 2026-10-03 18:27 UTCPublished