Compliance Program Manager - SOC 2 and ISO Security
Job Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
You care about building trust without clogging up engineering workflows, and you know how to translate complex compliance frameworks into practical controls that developers actually use. If you want to shape the SOC 2 and ISO security posture at JetBrains while working directly with customers, this is for you.
What you’ll do
As JetBrains expands its cloud and SaaS offerings, maintaining customer trust and robust security compliance is critical. We are investing in the security posture and compliance program for JetBrains Cloud Platform (JCP), a new JetBrains offering, moving beyond checklist-driven security to build practical, real-world controls.
In this role, you will take ownership of our compliance program from design to execution, focusing on SOC 2 and ISO standards. You’ll sit at the intersection of product security, platform engineering, legal, and customer-facing teams. Rather than imposing rigid bureaucracy, you’ll help design workflows that protect user data while keeping development teams fast and autonomous. You’ll also serve as a key technical voice on compliance matters, speaking directly with customers to explain our security architecture and build trust.
Day to day, you will:
- Design, implement, and mature the compliance program for JCP, focusing initially on SOC 2 (Type 1 and Type 2) and ISO standards (such as ISO 27001, 27017, 27018, and 42001).
- Translate complex framework requirements into clear, practical controls that fit how JetBrains builds products.
- Partner with product security, platform engineering, legal, and people teams to embed security and compliance requirements into day-to-day work (policies, procedures, onboarding, training, SDLC, vendor management, etc.).
- Coordinate evidence collection, control testing, and remediation for internal reviews and external audits.
- Maintain and improve core compliance documentation, including policies, standards, control catalogs, risk registers, and playbooks.
- Respond to customer security questionnaires, participate in due diligence calls, and collaborate with account teams to handle non-standard compliance requests.
- Monitor changes in relevant standards and regulations and help keep our program aligned with them.
What you’ll bring
- A practical mindset that values clear systems and real outcomes over rigid checklists.
- A clear, structured communication style that makes technical security concepts accessible to any audience.
- A detail-oriented approach with the curiosity to navigate both policy text and technical architecture.
- Calmness and confidence when guiding customers through security due diligence.
What you’ll need
- Established hands-on experience building and maturing compliance programs around SOC 2 and ISO security standards.
- Experience managing security compliance in SaaS or cloud environments (such as AWS, GCP, or Azure).
- Practical experience across core security and compliance domains, including access management, logging, secure development, vendor risk, and business continuity.
- A track record of collaborating effectively with technical teams (engineering, SRE, product security, etc.) and turning framework language into concrete, realistic requirements.
- Direct experience answering customer security questionnaires and leading customer-facing compliance discussions.
- Strong English communication skills, both written and spoken.
It would be great if you also have:
- Experience with other frameworks and regulations relevant to SaaS, such as FedRAMP, ISMAP, or others.
- Experience working inside or closely with product security, cloud security, or risk management teams.
- Familiarity with security and compliance tooling (such as GRC platforms, ticketing systems, policy and evidence repositories, asset and identity management tools).
- Prior experience in a fast-growing or multi-product environment where processes and ownership boundaries are evolving.
What success looks like
Success in this role means establishing a clear, reliable compliance foundation for JetBrains Cloud Platform that strengthens customer trust and respects engineering autonomy. You’ll know you’re succeeding when compliance controls feel like a natural part of product development, external audits run smoothly without last-minute scrambles, and customer security calls build lasting confidence in our platform.
How would you rate this job post?
See what other professionals think about this role.
Similar Opportunities
More Openings at Jetbrains
Explore Top Companies in this Space
Laravel
Software Development / Developer Tools / Cloud SaaS
Percona
Database Monitoring Tools / Software Development / Enterprise Software
IntegrityM
Business Consulting / Compliance / Fraud Detection / Government Services
Ignition
SaaS / Financial Technology / Professional Services / Automation
Jetbrains
View Company ProfileJetBrains is a global technology company that specializes in the development of software development tools and technologies. With a strong mission to make developers' work easier, JetBrains focuses on creating innovative products that address the needs of software developers, data scientists, and other professionals. The company's culture emphasizes collaboration, innovation, and continuous learning, which are reflected in its diverse and dynamic work environment. JetBrains' tech stack is characterized by a wide range of products and tools, including IntelliJ IDEA, WebStorm, PyCharm, and Rider, that cater to different programming languages and development frameworks. Its flagship product, IntelliJ IDEA, is a comprehensive integrated development environment (IDE) that offers advanced code completion, debugging, and project management capabilities. Other notable products include Kotlin, a modern programming language designed to be more concise, safe, and interoperable with Java, and Space, a comprehensive platform for software development teams that integrates version control, project management, and communication tools. The company is committed to staying at the forefront of technology advancements, investing heavily in research and development, and partnering with leading technology companies, startups, and academic institutions to drive innovation and growth.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.







