Security & Compliance Program Specialist

AI overview

Support compliance through audits, risk assessments, and training, while collaborating cross-functionally to uphold security standards in a rapidly growing tech environment.
About the Role
Were looking for a Security & Compliance Program Specialist to help strengthen Stadium’s security and privacy posture as we scale.
In this role, you’ll partner with our Security & Compliance Lead to maintain and improve our SOC 2 Type II, GDPR, and data protection programs. You’ll be hands-on with risk assessments, policy updates, vendor reviews, access management, and audit prep — ensuring our teams stay aligned with top-tier security standards.
This is a great opportunity for someone who’s passionate about compliance, detail-oriented, and eager to make a tangible impact in a fast-growing tech environment.
 
What You’ll Do
  • Support and coordinate annual SOC 2 Type II audits, pen tests, and data protection reviews.
  • Maintain compliance documentation and ensure control evidence is complete and accurate.
  • Assist in responding to vendor risk questionnaires and client security assessments.
  • Manage and track access reviews, onboarding/offboarding compliance, and user privilege reports.
  • Support data privacy activities including DPA reviews, GDPR readiness, and incident documentation.
  • Coordinate security awareness training across the organization.
  • Collaborate with Engineering, IT, HR, and Legal to embed compliance in daily operations.
  •  
What You’ll Bring
  • 2–4 years of experience in security compliance, data protection, or IT risk management.
  • Familiarity with SOC 2, ISO 27001, GDPR, or PCI DSS frameworks.
  • Strong organizational and documentation skills — you thrive in structure and detail.
  • Ability to translate complex requirements into practical, actionable steps.
  • Experience working cross-functionally and communicating with both technical and non-technical teams.
  • Bonus points for experience with compliance automation tools (e.g. Vanta, Scrut.io ) or certifications like CIPP/E, Security+, or ISO 27001 Lead Implementer.

We are SpreeCommerce core team and leading the SpreeCommerce opensource efforts. We are an app development agency in USA, build next generation web and mobile applications.

View all jobs
Get hired quicker

Be the first to apply. Receive an email whenever similar jobs are posted.

Ace your job interview

Understand the required skills and qualifications, anticipate the questions you may be asked, and study well-prepared answers using our sample responses.

Specialist Q&A's
Report this job
Apply for this job