Back to jobs

Security and Compliance Manager

South Jordan, UT

Security and Compliance Manager

About Us

Canopy is a fast-growing SaaS company in South Jordan, Utah building simple, efficient software for accounting firms. We are looking to revolutionize the accounting space with modern, user-friendly software for a neglected industry. Our goal is to help our clients unlock the firm they’ve always wanted with our Practice Management Suite. We place strong emphasis on delighting our customers, spotting and solving problems, and being good people along the way.  Click here to see why our clients love Canopy. Interested in learning more about Canopy & the industry? Check out our blog here where you can find great information on our product features, industry news, practice management, and more!

The Opportunity

Canopy is expanding our security and compliance program, and we're looking for a Security Compliance Manager to own and elevate our compliance initiatives as we scale. This is a high-impact role where you'll take ownership of our SOC 2 program and its expansion, build and maintain our Trust Center, and establish the policies and frameworks that enable secure, compliant growth.

You'll be our first dedicated compliance hire, working closely with our Security and DevOps teams to transition compliance ownership from an ad-hoc, team-distributed model to a structured, scalable program. This role is perfect for someone who loves building systems from the ground up, can balance strategic thinking with hands-on execution, and thrives in a collaborative, fast-moving environment.

This can be a hybrid position in South Jordan, Utah (M, W, F in-office) or fully remote based from Utah.

What You’ll Do

Compliance Program Ownership (30%)

  • Lead the expansion of our SOC 2 audit scope to include all Trust Services Criteria (Security, Availability, Confidentiality, Processing Integrity, and Privacy)
  • Own and manage our compliance roadmap, ensuring we're continuously audit-ready
  • Coordinate and manage SOC 2 audits, including evidence gathering, auditor communication, and remediation tracking
  • Implement and maintain our Trust Center, making our security posture transparent and accessible to customers
  • Serve as the primary point of contact for customer security questionnaires and assessments

Policy & Documentation Management (25%)

  • Create, refine, and maintain comprehensive security and compliance policies, such as:
    • Acceptable Use Policy
    • Software Approval Policy
    • AI Use Policy
    • Incident Response Plan
    • Data Retention, Access, and Classification policies
    • Email Communication Policy
    • Business Continuity Plans
  • Ensure policies are practical, enforceable, and aligned with industry frameworks and regulatory requirements
  • Develop clear, accessible documentation that empowers teams to understand and follow security best practices
  • Partner with Legal, HR, and other departments to ensure policies are comprehensive and cross-functional

Risk & Vendor Management (20%)

  • Own and maintain our risk register, conducting regular risk assessments and tracking mitigation efforts
  • Lead third-party vendor security reviews and risk assessments
  • Maintain detailed knowledge of what data exists in every third-party tool and who has access
  • Track and manage vendor compliance documentation (SOC 2 reports, security attestations, etc.)
  • Work with Procurement and Engineering to ensure vendors meet our security standards

Technical Control Implementation (15%)

  • Implement security controls across our infrastructure and applications in collaboration with Security Engineers
  • Work with the team to automate evidence collection and compliance monitoring using tools like Drata and Datadog
  • Conduct internal reviews of audit controls to ensure they remain effective and up-to-date
  • Identify gaps in our security posture and design solutions to address them
  • Evaluate and implement new compliance and security tooling as needed

Cross-Functional Collaboration (10%)

  • Partner with Engineering, Product, HR, Legal, and Sales to ensure compliance requirements are understood and met
  • Ensure control owners across the organization complete their compliance tasks on schedule
  • Provide training and guidance to teams on security and compliance best practices
  • Serve as a trusted advisor to leadership on compliance strategy and risk posture

What We're Looking For

Required Qualifications

  • 6+ years of experience in security compliance, with at least 2 years owning or leading SOC 2 audits
  • Deep understanding of SOC 2 Trust Services Criteria and how to implement effective controls
  • Proven experience building or scaling compliance programs at a SaaS or technology company
  • Excellent policy writing skills with the ability to translate complex requirements into clear, actionable documentation
  • Strong technical foundation with the ability to implement security controls and work effectively with engineering teams
  • Experience managing GRC platforms (Drata, Vanta, or similar)
  • Outstanding project management skills and ability to coordinate across multiple stakeholders
  • Self-starter mentality with the ability to own initiatives from strategy through execution
  • Strong ability to translate technical concepts for non-technical audiences

Preferred Qualifications

  • Experience expanding SOC 2 scope beyond Security (Availability, Confidentiality, Processing Integrity, Privacy)
  • Familiarity with additional compliance frameworks (ISO 27001, PCI-DSS, GDPR, CCPA, HIPAA)
  • Experience implementing and managing Trust Centers
  • Knowledge of AWS/cloud security best practices (we use EKS, RDS, and AWS services)
  • Technical skills in scripting or automation (Python, Bash, etc.) for evidence collection and control monitoring
  • Experience with SIEM tools (Datadog), CI/CD platforms (GitHub), and infrastructure monitoring
  • Relevant certifications (CISSP, CISM, CISA, or similar)
  • Experience in a high-growth startup or scale-up environment
  • Background working cross-functionally with Legal, HR, or Sales on compliance initiatives

We know many women do not apply for a job if they don't perfectly fit the description. We want you to apply anyway.

Why You Want to Work Here:

🌴 Flexible Paid Time Off - you’re actually encouraged to use it, plus 10 company holidays! 

❤️‍🩹 Health Benefits - including Medical, Dental, and Vision and an HSA Match. 

💰 401(k) - we match 100% up to 3% of your contribution. Eligibility is immediate with 100% vesting.

🧠 Mental Health -  all employees have access to Impact Suite & to our Employee Assistance Program (EAP).

👶 Paid New Parent Leave & Birthing Parent Leave - so you’re able to care for your little ones.

➕ Supplemental Benefits - including 100% company paid Basic Life & AD&D insurance and long & short-term disability coverage.

🌟 Nectar - our peer-to-peer recognition program to help our employees recognize the amazing work being done by other Canopians!

🥳 Company Events - including monthly company-wide meetings, summer parties, and more.

💡 ERG Committees - to plan initiatives around continuing education, community outreach, recruiting, onboarding, and more.

☕ Fully-stocked kitchen - Keto? Vegan? Flexitarian? Mandalorian? We’ve got you covered. 

Our Values:

We approach our work every day with a few things in mind:

🔑 Own - we own this place! We focus on outcomes, holding ourselves & each other accountable.

🏆 Win - we win by delighting our customers with the very best products and services.

👍 Do Good - we work hard to be good people!

💡 Embrace Curiosity & Candor - we approach everything with curiosity & we understand that candor is kindness and give the gift of feedback.

To learn more about us & our values, click here.

Interviewing @ Canopy:

Application processes can be a little stressful. Here are the stages of a typical interview process at Canopy:

  • Once your application is received, we will review it and get back to you if we feel like it’s a mutual fit! 
  • 20-minute phone call with the People Team.
  • 45-60-minute video or in-person interview with the Hiring Manager.
  • 1-3 rounds of interviews, depending on the role.
  • Final Interview.

Interview processes can vary depending on the role. The People Team will give you a role-specific overview of the process during your first phone call. 

Remember: This is your interview too! We know candidates are evaluating us just as much as we are them. We encourage you to bring questions to each of your interviews—our hiring teams will always make sure to save time for questions at the end! 

Canopy is an equal-opportunity employer. Canopy provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, gender, national origin, sexual orientation, gender identity or expression, age, disability, genetic information, marital status, or veteran status.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Canopy’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.