Migaru AI builds an AI-native CRM that automatically reads a sales team's email, calendar, and calls to keep account, contact, and deal records current — including, as part of the sales process, responding to customer requests for SOC 2 reports and security questionnaires. As Migaru works with customer and prospect data pulled from connected mailboxes, calendars, call transcripts, and Slack, we're hiring a Compliance Manager to own our SOC 2 program and privacy posture as the company scales.
What you'll do
- Own and maintain our SOC 2 compliance program, including control design, evidence collection, and coordination of Type I/Type II audits with external auditors
- Serve as the internal point of contact for customer security questionnaires and requests for SOC 2 reports, working closely with sales and customer-facing teams
- Build and maintain privacy policies, data processing practices, and documentation covering how customer and end-user data (email, calendar, call, and Slack content) is collected, stored, and used
- Monitor regulatory developments in privacy law (e.g., GDPR, CCPA) and assess their impact on the company's data handling practices
- Partner with engineering and product teams to ensure security and privacy controls are implemented and operating effectively
- Track remediation of audit findings and maintain a continuous compliance posture across frameworks
What we're looking for
- 4+ years of experience in compliance, information security, or privacy roles, with direct ownership of a SOC 2 program
- Working knowledge of privacy regulations such as GDPR and CCPA, and experience translating requirements into practical policies
- Experience managing external audits and responding to customer security and privacy questionnaires
- Strong written communication skills; comfortable explaining compliance requirements to engineers, salespeople, and customers alike
- Familiarity with cloud infrastructure and SaaS security practices sufficient to evaluate technical controls
Nice to have
- A relevant certification such as CIPP, CISA, or CISSP
- Experience at an early-stage SaaS company building a compliance function from the ground up
- Experience with trust and compliance automation tooling (e.g., Vanta, Drata, Secureframe)
