Back to Jobs
Deepgram
Legal & HR 4d ago

Compliance and Documentation Lead

Deepgram
United StatesUnited States
Full-time
Not Disclosed
Senior-Level

Job Description

Key Skills Required

Master these to land this role

Security ComplianceTechnical Compliance DocumentationAI GovernanceGRCPrivacy Operations

Want to know if you're a match for this job?

Calculate My Match Score

The Opportunity

Deepgram is looking for a Compliance and Documentation Lead to own the written and evidentiary backbone of our compliance program — privacy and security both — and the documents that auditors, enterprise customers, and our own engineers rely on to know what we actually do.

This is one seat covering both halves deliberately. You will own our privacy program's operational work — assessments, data flow maps, deletion and rights workflows, subprocessor reviews — and our security compliance obligations under SOC 2, ISO 27001, and PCI DSS, along with the security questionnaires, policies, and public posture documents that sit on top of them. The reason to combine them is leverage: the same underlying facts about how Deepgram handles data answer a DPIA, a SOC 2 control, and a Fortune 500 questionnaire. Establishing them once and reusing them is the job.

Context matters here, because the claims you will be writing are unusually specific. Deepgram processes audio — often some of the most sensitive data our customers hold — across several deployment models: hosted with model-improvement opted in, hosted with model-improvement opted out (effectively zero data retention), single-tenant Deepgram Dedicated deployments with regional data residency, and fully self-hosted deployments running in the customer's own environment. Getting a statement right means knowing which of those it applies to.

Writing is the core skill in this role, and we mean writing that survives a skeptical reader — an auditor, an enterprise security reviewer, a customer DPO, an engineer who knows the system better than you do. Where a claim needs technical verification, you define what has to be proven and partner with Security Engineering to prove it; you are not expected to do that engineering work yourself.

This role reports to the Director of Information Security and works closely with Security Engineering, Legal, Research, and Solutions/Sales Engineering.

We are open on level. This is a senior individual-contributor role, and we will calibrate title, scope, and compensation to demonstrated experience.

Responsibilities

Privacy program

  • Own customer and prospect privacy risk assessments, DPIAs, and transfer impact assessments end to end. Be the technical voice in customer privacy reviews and vendor due diligence calls.
  • Build and maintain accurate data flow maps and records of processing across hosted, dedicated, and self-hosted deployments — and own the process that keeps them accurate as the product changes.
  • Own the operating model for our privacy controls: retention and deletion enforcement, DSAR and deletion workflows, consent and opt-out handling, de-identification and redaction. You specify, instrument, test, and audit; Engineering builds.
  • Own the subprocessor and vendor privacy review process, and the artifacts behind our DPAs.
  • Translate GDPR, UK GDPR, CCPA/CPRA and other US state privacy laws, and emerging AI regulation (EU AI Act, state AI and automated decision-making rules) into concrete requirements engineering and GTM teams can act on, rather than memos.
  • Partner with Legal on DPAs, SCCs, transfer mechanisms, and the residency commitments we make for dedicated deployments.

Security compliance and audit

  • Own audit evidence end to end for SOC 2, ISO 27001, and PCI DSS — what evidence is required, who produces it, where it lives, and whether it would actually satisfy a reviewer. Be the auditor's primary point of contact through fieldwork.
  • Own control mapping across frameworks. Build and maintain the crosswalk so one control and one piece of evidence satisfies SOC 2, ISO 27001, PCI DSS, privacy obligations, and customer questionnaires — rather than running the same work four times.
  • Own security questionnaires and the security sections of RFPs. Maintain the answer library, keep it current as the product changes, and know which answers to fight for and which to concede.
  • Partner with Security Engineering so evidence is generated once, by automation, and reused — and flag where a manual evidence pull should become an automated one.

Documentation and enablement

  • Author and own the lifecycle of our internal policies and standards: drafting, review and approval cycles, annual review, exceptions and carve-outs, and retiring what no longer reflects reality.
  • Own our public-facing posture documents — Trust Center content, the AI Safety statement, Model Cards (with Research), the Privacy Policy (with Legal), and the deployment-model and self-hosted documentation customers rely on during review.
  • Own the documentation system itself: where documents live, how they are versioned and reviewed, and how a customer-facing claim traces back to an internal source of truth. Nothing we say publicly should be unattributable.
  • Design and run operational auditing and remediation workflows, so drift between what we claim and what we do is caught by process rather than by a customer.
  • Run compliance and privacy training and enablement, including clear guidance to Sales Engineering on what they may and may not commit to on a customer call.

How would you rate this job post?

See what other professionals think about this role.

banner

Deepgram is a cutting-edge technology company that specializes in providing AI-powered speech recognition solutions. With a strong focus on innovation and accuracy, Deepgram's platform is designed to help businesses and organizations unlock the full potential of their audio and video data. By leveraging the latest advancements in deep learning and natural language processing, Deepgram's technology is capable of transcribing spoken language with unprecedented speed and precision, enabling applications such as voice-controlled interfaces, speech analytics, and real-time captioning. Whether it's improving customer service, enhancing user experience, or driving business insights, Deepgram's solutions are poised to revolutionize the way we interact with and extract value from audio and video content. As a leader in the speech recognition space, Deepgram is committed to pushing the boundaries of what is possible with AI and speech technology, and its innovative approach has earned it a reputation as a trailblazer in the industry. With a strong team of experts and a passion for innovation, Deepgram is well-positioned to continue making significant contributions to the field of speech recognition and beyond.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More