Compliance Manager
Quick Summary
vendor security questionnaires, risk tiering, onboarding reviews, and tracking remedi
Reflection is a research lab making intelligence open and accessible for everyone to use, customize, and build on. We build open models that let anyone control their intelligence and help shape the future of AI. Our mission: make intelligence open and accessible to all.
Reflection AI's Compliance and AI Governance function spans six pillars: AI Governance, Data Governance, Trade Compliance, Privacy Operationalization, Government Contracting Compliance, and Corporate Compliance. The team builds the policies, controls, and operating rhythms that let the company move fast while staying defensible with regulators, customers, and partners.
We're looking for a senior generalist who can flex across multiple pillars rather than own a single lane. You'll take ambiguous, cross-cutting problems (a new regulation, a customer due-diligence request, an internal process gap) and turn them into working programs: policies, SOPs, training, and monitoring. This role is a force multiplier for the pillar leads and a direct partner to the Head of Compliance and AI Governance.
Responsibilities
~1 min read- →
Stand up and maintain compliance processes and SOPs across pillars (e.g., insider risk, background checks, external reporting process, vendor/compliance tooling)
- →
Support our security framework compliance posture (SOC 2, ISO 27001, NIST 800-53/800-171, CMMC) by maintaining evidence, coordinating with control owners, and prepping for audits and assessments
- →
Own or support day-to-day TPRM operations: vendor security questionnaires, risk tiering, onboarding reviews, and tracking remediation of vendor findings
- →
Respond to inbound customer and partner security/compliance questionnaires, pulling in subject-matter owners as needed
- →
Partner with pillar leads (AI Governance, Data Governance, Trade Compliance, Privacy, Gov Contracting) to fill gaps, cover surge work, and keep cross-pillar initiatives moving
- →
Draft and maintain policies, process documentation, and training materials for internal and external audiences
- →
Track regulatory developments (AI, data, privacy) and translate them into concrete internal workstreams
- →
Prepare materials for leadership and cross-functional updates (steering committees, exec reporting, knowledge-share sessions)
- →
Identify process gaps and build the scaffolding (trackers, templates, intake forms) to close them
4-7 years in compliance, risk, legal operations, or a related GRC function, ideally in tech or a regulated industry
Direct experience with at least one security framework (SOC 2, ISO 27001, NIST) and with TPRM/vendor risk processes (questionnaires, risk tiering, onboarding review)
Demonstrated ability to own a problem end to end with minimal supervision, across unfamiliar subject matter
Strong written communication; comfortable turning ambiguous asks into clear policies and SOPs
Experience working cross-functionally with Legal, Security, Privacy, People, and Engineering stakeholders
Comfortable context-switching across multiple active workstreams
Exposure to AI governance, data privacy (GDPR/CCPA), export controls (ITAR/EAR), or federal contracting compliance (CMMC, FAR/DFARS)
Experience with GRC or compliance tooling (e.g., Vanta or similar platforms)
Experience responding to customer-facing security questionnaires or supporting enterprise sales/procurement cycles
Prior experience in a high-growth or startup environment where the compliance function is still being built
What We Offer
~2 min readWe believe that to make intelligence open and accessible to all, you need to start at the foundation. Joining Reflection means building from the ground up as part of a talent-dense team. You will help define our future as a company, and help define the future of open foundational models.
We want you to do the most impactful work of your career with the confidence that you and the people you care about most are supported.
Location & Eligibility
Listing Details
- Posted
- October 9, 2026
- First seen
- October 9, 2026
- Last seen
- October 10, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 57%
- Scored at
- October 10, 2026
Signal breakdown
Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.