SECTION I · THE BRIEF
Brief #99344Updated 06 OCT 2026UNITED STATESBamboohrSOFTWARE COMPANIES
Employbl Company Profile

Senior Manager, Compliance & Audit

We humanize AI by infusing empathy into your SaaS platforms, increasing engagement and revenue. By combining years of research on human interactions and growing proprietary datasets, mpathic is empathy-as-a-service.

Location
United States
Company size
10–50
Posted
Today
Via
Bamboohr
Section II · Full ProfileFree with an account
  • 01Comp band & equity packageLocked
  • 02Seniority & experience requirementsLocked
  • 03Interview process & rubricLocked
  • 04Hiring manager & team contextLocked
  • 05Growth trajectory in this roleLocked
  • 06Offer & decision timelineLocked

Free account · no card · 2 minutes

Senior Manager, Compliance & Audit

Mpathic.ai· United StatesView company profile


Job title
Senior Manager, Compliance & Audit
Job location
United States
Job description

About mpathic

mpathic is building the future of trustworthy AI. Grounded in behavioral science and human-centered design, we provide the infrastructure for building AI systems that are safe, aligned, and emotionally intelligent.

Building on our work in areas like RL gyms, red teaming, benchmarking, and human data, we are creating the foundation for training, probing, and measuring advanced AI systems reliably, auditably, and at scale.

Position Overview

mpathic is seeking a Senior Manager, Compliance & Audit to own and scale the compliance and audit programs that support our technology, customers, and continued growth.

This is a hands-on role for someone who can move comfortably between regulatory requirements, technical systems, external auditors, and internal teams. You’ll lead our audit and certification lifecycle across SOC 1, SOC 2 Type II, ISO/IEC 27001, ISO/IEC 42001, and FDA 21 CFR Part 11, while building a unified compliance program that minimizes duplicate work and makes compliance part of how we operate—not simply something we prepare for at audit time.

You’ll partner closely with engineering, security, product, delivery, and operations to translate requirements into practical controls, automate evidence wherever possible, and ensure our systems and processes can stand up to scrutiny from auditors, customers, and regulated-industry partners.

About You

  • Proven Experience: 7+ years in IT compliance, GRC, audit, or computerized systems validation, including direct ownership of external audits from scoping through final report or certification.
  • FDA 21 CFR Part 11 Depth: Hands-on experience applying Part 11 and GxP data integrity requirements to software or SaaS systems, including audit trails, electronic signatures, access controls, record retention, and ALCOA+ principles. Familiarity with FDA Computer Software Assurance (CSA) guidance, GAMP 5, and EU Annex 11 is a strong plus.
  • Validation Experience: Experience writing or leading validation deliverables such as validation plans, requirements traceability, risk-based test evidence (IQ/OQ/PQ or CSA-style), and validation summary reports, as well as supporting customer or sponsor audits of validated systems.
  • Multi-Framework Audit Experience: Experience leading or supporting SOC 1 and SOC 2 Type II examinations and ISO/IEC 27001 certification or surveillance audits. Experience with ISO/IEC 42001 or other AI governance frameworks, including NIST AI RMF or the EU AI Act, is a strong plus.
  • Technical Fluency: Comfortable reviewing cloud configurations across AWS, GCP, or Azure; IAM policies; CI/CD and change management records; logging; and infrastructure as code well enough to evaluate whether a control is actually operating—not simply whether documentation exists.
  • Internal Audit Skills: Able to plan and execute internal audits, sample and evaluate evidence, write clear findings, and drive corrective and preventive actions (CAPAs) through closure.
  • Auditor Credibility: Comfortable representing mpathic with external auditors, certification bodies, customers, and sponsor quality teams—and able to challenge findings constructively when the evidence supports a different conclusion.
  • Clear Communication: Able to write policies, findings, and customer responses that engineers can act on and executives can confidently approve.
  • Practical Mindset: You understand that strong compliance programs should enable teams to move quickly and responsibly rather than create unnecessary process.
  • Credentials: Certifications such as CISA, ISO/IEC 27001 Lead Auditor or Lead Implementer, ISO/IEC 42001 Lead Auditor, ASQ CQA, or CISSP are a plus.

Core Responsibilities

  • Audit Ownership: Plan and run the annual audit and certification cycle for SOC 1, SOC 2, ISO/IEC 27001, ISO/IEC 42001, and Part 11 readiness, including auditor selection, scoping, evidence collection, fieldwork, management responses, and final report or certificate delivery.
  • FDA Part 11 Program: Own Part 11 compliance for systems that create, modify, or store regulated records. Maintain the system inventory and GxP impact assessments, lead risk-based validation, and ensure validation documentation remains current through releases and system changes.
  • Unified Control Framework: Maintain a unified control set mapped across applicable frameworks so evidence can satisfy multiple requirements and teams aren't duplicating work for every audit.
  • Internal Audit: Run a risk-based internal audit program, including ISO-required internal audits and management reviews, and track nonconformities and CAPAs through closure.
  • Engineering & Delivery Partnership: Build controls into how mpathic develops and delivers its products and services, including change management, code review, access reviews, release validation, and data handling across customer work. Partner with engineering to automate evidence collection wherever possible.
  • Enforcement & Remediation: Monitor control health, identify and escalate gaps early, and drive remediation with control owners across engineering, delivery, operations, HR, and other teams.
  • AI Management System: Maintain mpathic’s ISO/IEC 42001 AI management system in partnership with ML, engineering, and product teams, including AI risk and impact assessments and documentation of model lifecycle controls.
  • Customer Security & Compliance Reviews: Own responses to security questionnaires, customer and sponsor quality audits, and compliance-related portions of RFPs and contracts. Maintain and continuously improve our trust center.
  • GRC Tooling: Own our GRC platform and its integrations, ensuring control mappings, automated evidence collection, and policy workflows remain accurate and useful.
  • Policies & Training: Maintain the policies and SOPs required by our certifications and regulatory commitments, and deliver compliance training, including Part 11 and GxP training for employees working with regulated systems.
  • Regulatory Monitoring: Track changes to FDA guidance, AI governance requirements, and applicable data privacy laws, translating relevant changes into practical recommendations for mpathic’s compliance program.

What Success Looks Like

You’ll build a compliance program that is rigorous enough to meet the expectations of auditors, regulated customers, and enterprise partners while remaining practical for a fast-moving technology company.

Audits and certifications will become increasingly predictable, evidence will be reusable and automated wherever possible, and teams will understand what controls they own and why they matter. You’ll also help ensure mpathic stays ahead of emerging expectations around AI governance and regulated technology as our platform and customer base grow.

Compensation

The base salary range for this role is $140,000–$180,000, depending on experience, skills, and qualifications.

View job listing ↗
The Saturday Briefing

Get the Saturday tech briefing

New company profiles, funding moves, and who’s hiring across the market — every Saturday morning.

Mpathic.ai headquarters

Nokesville, VA

Company size

10–50 employees

Founded

2021

Total raised

$28,270,778

View company profile ↗

Funding rounds