All remote jobs
Open role
Remote opportunity atAda

Compliance and Security Lead

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

Published
25Listing views
2Application actions
26 Sep 2026Apply before
Opportunity details

About this role.

AI Summary

Ada is seeking a senior Compliance and Security Lead to own its security compliance program across audits, customer trust, vendor risk, vulnerability management, and control documentation. The role leads end-to-end SOC 2, PCI, and AIUC audit readiness, with a focus on automating evidence collection and continuous control monitoring through Drata. It is highly customer-facing, covering enterprise security discussions, RFP security responses, questionnaires, and SafeBase trust-center maintenance. The successful candidate will translate emerging agentic-AI governance requirements into actionable platform requirements while building durable, scalable compliance processes.

Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

Job Complexity

5/5
EasyHard

Pace & Pressure

5/5
RelaxedFast-paced

Autonomy Level

5/5
GuidedFull ownership

Communication Load

5/5
IndependentCollaborative
AI insightThis is a senior ownership role spanning complex audit frameworks, technical security operations, third-party risk, customer assurance, and evolving AI regulation. It requires independently transforming manual, seasonal compliance work into an always-ready program while managing high-stakes external and internal stakeholders.

Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianMarket rate
$155,000
US market range$135k–$185k
AI insightNo actual salary was disclosed, so these figures are estimated USD annual US-market compensation for a senior security compliance lead with ownership of SOC 2, PCI, vulnerability management, customer trust, and AI-governance responsibilities. Actual compensation may differ based on the employer’s Canada-based compensation structure, candidate location, experience, equity, and total-rewards package.

Core skills

Skills and capabilities most closely associated with this opportunity.

Sample interview questions
Describe how you have led a SOC 2 or PCI DSS audit from planning through final reporting.

I begin with a scoped control inventory and gap assessment, then assign control owners, define evidence requirements, and establish a cadence for readiness reviews. I use a centralized evidence tracker or compliance platform to validate operating effectiveness before auditor testing, resolve exceptions quickly, and maintain clear communication with both auditors and internal stakeholders.

How would you make Ada audit-ready throughout the year rather than only during the August-to-November audit season?

I would map each control to an accountable owner, evidence source, collection frequency, and validation method in Drata. I would automate integrations where possible, establish monthly control-health reviews and exception remediation SLAs, and use quarterly internal readiness assessments to identify gaps long before an external audit.

How would you prioritize a vulnerability backlog containing thousands of findings?

I would normalize the inventory, remove duplicates and false positives, and prioritize based on exploitability, asset criticality, exposure, data sensitivity, compensating controls, and business impact rather than CVSS alone. I would then assign owners and time-bound remediation SLAs, report trend metrics to leadership, and maintain an exception process for risks that cannot be remediated immediately.

How do you handle a difficult enterprise customer security questionnaire when information is incomplete or a requested control is not currently in place?

I provide accurate, evidence-based responses and avoid overstating the organization’s posture. Where a control is incomplete, I explain the current safeguard, identify the accountable owner and remediation plan where appropriate, and coordinate quickly with engineering, legal, and privacy teams so the customer receives a clear and timely answer.

How would you translate emerging agentic-AI requirements such as AIUC into engineering work?

I would first map the framework requirements to Ada’s product architecture, data flows, model and agent lifecycle, monitoring, and governance processes. I would convert gaps into prioritized control requirements with measurable acceptance criteria, partner with platform owners on implementation, and preserve evidence so compliance can be demonstrated to auditors and customers.

This analysis is generated from the job description. Salary estimates, role characteristics and sample answers are guidance, not employer-provided facts.

About Us

Ada is an AI customer service company whose mission is to make customer service extraordinary for everyone. We’re driven to raise a new standard of quality customer service at scale, enabling enterprise companies to deliver experiences that people love–instant, proactive, personalized, and effortless.

Ada is an AI transformation platform and partner—combining strategic expertise with powerful AI agent management technology to accelerate businesses’ AI maturity to keep them ahead of the curve. With Ada, 83% of customer conversations—and counting—are effortlessly resolved through automation, giving teams more time back, companies more resources to focus on growth, and customers more life to focus on what matters most to them.

Established in 2016, Ada is a Canadian company that has powered over 5.5 billion interactions for leading brands like Square, YETI, IPSY, and Monday.com, saving millions of hours of human effort. Backed with over $250M in funding from tier-one investors including Accel, Bessemer, FirstMark, Spark, and Version One Ventures, Ada is a pioneer in the management and application of AI in customer service.

At Ada, we see growth as a reflection of each individual owner’s personal growth. That’s why our values are rooted in driving progress and continuous improvement. If you’re ambitious and eager to grow, Ada could be the place for you.

Learn more at www.ada.cx.

Security at Ada

Ada’s AI Agent resolves customer service conversations for enterprises — which means our customers trust us with their customers’ data and their brand. Security and compliance are how we earn and keep that trust. The Security team partners across engineering, legal, and go-to-market to make sure Ada’s controls are real, evidenced, and easy for customers to verify.

Our Role

As Compliance & Security Lead, you own Ada’s security compliance program end to end: audits, customer trust, vendor risk, vulnerability management, and the control framework that ties it all together. Our audit season runs August through November — your mandate is to automate evidence collection and process to the point where the team is audit-ready year-round, not scrambling seasonally. You are the internal source of truth on compliance status and the external face of Ada’s security posture: you will own security conversations with enterprise prospects and customers. As agentic AI regulation takes shape (starting with AIUC), you translate framework movement into concrete requirements for the platform team.

About You

  • Deep audit experience across SOC 1, SOC 2, PCI DSS, NIST frameworks, AICPA standards, and PII/privacy requirements. You have run audits end to end: evidence collection, control mapping, and auditor coordination.
  • Experience working directly with major audit firms such as Deloitte or EY; you know what a gold-standard audit engagement looks like from the inside.
  • You have inherited manual compliance programs and driven them toward automation tooling, process, and repeatability (Drata or similar compliance automation platforms).
  • Vulnerability management at scale: you have taken a large vulnerability backlog (thousands of findings) and driven it down through prioritization, ownership, and process.
  • Customer-facing confidence: you own the room in security posture conversations with enterprise prospects, and you are equally comfortable saying “let me get back to you” and then actually getting back to them.
  • An engineering background is preferred but not required; you must understand modern infrastructure, Kubernetes, Terraform, CI/CD! well enough to hold your own with engineers and auditors alike.
  • Experienced owner of RFP security sections, customer security questionnaires, and trust centers (SafeBase or similar).
  • Strong writer: policies, control documentation, and data handling standards that people actually follow.
  • Proactive owner who builds programs that outlast you: process, documentation, and tooling over heroics.
  • You track regulatory and framework movement interest in agentic AI governance (AIUC and emerging frameworks) is a strong plus.

Outcomes

  • Own Ada’s security audits end to end: the upcoming AIUC audit, PCI, and SOC 2. Evidence collection, control mapping, and auditor coordination, run through Drata.
  • Automate evidence collection and control monitoring so that audit season (August–November) no longer requires heroics the team is audit-ready year-round.
  • Own the security and compliance sections of customer RFPs and security questionnaires. Maintain the SafeBase trust center so deals stop stalling on security review.
  • Own vulnerability management as a program: drive the backlog down with clear prioritization, ownership, and SLAs for critical findings.
  • Run vendor security and privacy reviews as a standing process with clear SLAs, not one-off scrambles.
  • Maintain the control framework and its documentation: policies, data handling, retention, and the evidence that controls actually operate.
  • Be the point of contact for customer security, privacy, and legal teams, and the internal source of truth on compliance status.
  • Track regulatory and framework movement relevant to agentic AI, starting with AIUC, and translate it into concrete internal requirements for the platform team.
  • Take ownership of the compliance work currently spread across the team, and make it sustainable.
  • First 90 days: take full ownership of the AIUC audit, produce a current-state gap assessment against our target frameworks, and turn the RFP security response into a repeatable process.

#LI-NS1

Benefits & Perks

At Ada, you’ll not only build extraordinary products but also thrive in an environment designed for your success. We prioritize your well-being, growth, and work-life balance. Here’s what we offer:

Benefits

  • Unlimited Vacation: Recharge when you need to.
  • Comprehensive Benefits: Extended health coverage, dental, vision, travel, and life insurance.
  • Wellness Account: Empowering you to invest in your overall well-being and lifestyle.
  • Employee & Family Assistance Plan: Resources to support you and your loved ones.

Perks

  • Flexible Work Schedule: Balance your work and personal life.
  • Remote-First, In-Person Friendly: Options to work from home or at our local hub.
  • Learning & Development Budget: Invest in your long-term growth goals and skills.
  • Work from Home Budget: Equipping you with the tools and support for a seamless remote work experience.
  • Access to Cutting-Edge AI Tools: Work with the best AI tech stack in the industry.
  • Hands-On with LLMs: Enhance your expertise in leveraging large language models.
  • A Thriving Industry: Join the forefront of innovation in AI, shaping the future of technology.

The above Benefits and Perks only apply to full-time, permanent employees.

As part of our recruitment process, we may use AI enabled tools to support certain aspects of hiring, such as interview note-taking. All hiring decisions are made by our team.

Thank you for your interest in joining us at Ada. Due to the high volume of applications, we will only contact candidates whose qualifications match closely to the requirements of the position. We appreciate the time you have invested in learning more about us.

Apply now >

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Did you apply?Let us know, and we’ll help you track your application.
Application method

Continue on the employer website

Protect your personal information and never pay to secure an interview or job offer. View safety guidance.

Log in to save
One quick step before you apply

Create your free account, then apply.

Build a more organized job search on Jobicy and continue to the employer's application when you're ready.

  • Never lose a promising opportunitySave roles and return to them from your dashboard.
  • See your entire search at a glanceTrack applications, stages and next steps in one place.
  • Get matched with relevant remote jobsChoose the alerts and digests that work for you.
or continue without an account
Applying is free. The employer's application opens in a new tab.
Add alert
Jobs Talent AI Tools Salaries
Menu