Hippo Insurance Logo

Hippo Insurance

Security Compliance Manager

Posted 13 Days Ago
Be an Early Applicant
Easy Apply
In-Office or Remote
11 Locations
180K-260K Annually
Senior level
Easy Apply
In-Office or Remote
11 Locations
180K-260K Annually
Senior level
The Security Compliance Manager leads and evolves the governance, risk, and compliance program by managing audits, controls, and regulatory compliance efforts.
The summary above was generated by AI

Title: Security Compliance Manager

Location: Austin, TX / Dallas, TX / San Francisco Bay Area, CA / Bedminster, NJ (hybrid)

Reports To: Sr. Manager, Cybersecurity

About Hippo

Hippo exists to protect the joy of homeownership. We believe that insurance should protect the things you treasure through an intuitive, modern experience. We provide tailored insurance coverage and preventative maintenance plans that keep you protected throughout your homeowner journey. We’ll also help you find coverage for everything life brings—from auto to flood—reimagining how you care for your home.

About the Role

The Security Compliance Manager owns and evolves Hippo’s governance, risk, and compliance (GRC) program, ensuring the company maintains strong, defensible security controls and meets regulatory and audit requirements. This role leads the design, execution, and maturity of IT general controls (ITGC), SOX compliance, SOC 2 readiness and audits, and alignment with industry frameworks such as ISO 27001 and NIST.

Partnering closely with Security Engineering, IT, Finance, Legal, and Internal and External Audit, the Security Compliance Manager delivers rigorous risk assessments, effective control testing, and clear assurance reporting. The role plays a critical part in ensuring regulatory compliance, including NYCRR 500, while continuously improving compliance efficiency through standardization and automation.

About You

You are a seasoned security compliance and risk professional with a strong command of audit, controls, and regulatory frameworks. You are comfortable owning complex compliance programs end-to-end and translating regulatory requirements into practical, scalable controls.

You thrive in cross-functional environments, communicate clearly with both technical and non-technical stakeholders, and bring a structured, detail-oriented approach to risk management. You balance rigor with pragmatism, helping the organization meet compliance obligations while enabling the business to move efficiently and confidently.

What You'll Do:

  • Own and mature the end-to-end GRC program, including ITGC, SOX, SOC 2, ISO 27001 alignment, and NYCRR 500 compliance.

  • Design, execute, and test IT general controls across access management, change management, operations, backup and disaster recovery, and vendor/SaaS environments.

  • Lead SOX activities including scoping, walkthroughs, design and operating effectiveness testing, deficiency evaluation, and remediation tracking.

  • Manage SOC 2 readiness and annual Type 1 and Type 2 audits, including control mapping, evidence collection, and exception management.

  • Align security policies, standards, and procedures with ISO 27001 Annex A, NIST CSF, COBIT, and CIS Controls, ensuring regulatory applicability.

  • Conduct enterprise and IT risk assessments, document risk treatment plans, and track remediation through closure.

  • Establish continuous control testing and assurance practices, including testing scripts, sampling methodologies, and evidence standards.

  • Develop and report on key risk and performance indicators (KRIs/KPIs) such as control pass rates, audit findings, evidence SLAs, and vendor risk trends.

  • Serve as the primary point of contact for Internal Audit and external auditors, producing executive- and board-ready compliance reporting.

  • Lead third-party and vendor risk assessments, including SIG/CAIQ reviews, contract control requirements, and ongoing monitoring.

  • Map and validate cloud controls (AWS, Azure, GCP) against SOX, SOC 2, ISO 27001, and NYCRR 500 expectations.

  • Maintain security policies, control catalogs, control narratives, and RACI documentation.

  • Drive security awareness, control owner training, and process maturity, including identifying opportunities for automation and continuous monitoring.

Must Haves:

  • 6+ years of experience in security compliance, IT audit, or IT risk management.

  • Hands-on ownership of ITGC, SOX, SOC 2, and policy frameworks such as ISO 27001.

  • Strong expertise in risk assessments, control testing, assurance practices, and audit methodologies.

  • Practical knowledge of enterprise and cloud control domains, including IAM, SDLC/change management, vulnerability management, logging and monitoring, incident response, and BC/DR.

  • Experience interpreting and applying regulatory requirements such as NYCRR 500 or similar industry regulations.

  • Proven ability to lead cross-functional initiatives with Security, IT, Finance, Legal, and Audit teams.

  • Excellent written and verbal communication skills, with experience delivering executive-level reporting.

Nice to Have:

  • Security or audit certifications (CISA, CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor, CIA, CPA).

  • Experience with GRC and compliance tooling (e.g., OneTrust, Drata, Vanta, Secureframe, Jira, Confluence).

  • Financial services or insurance industry experience, including GLBA, NAIC, and customer security questionnaires (SIG, CAIQ).

Benefits and Perks:

Hippo treats its team members with the same level of dedication and care as we do our customers, which is why we’re fortunate to provide all of our Hippos with: 

  • Healthy Hippos Benefits - Multiple medical plans to choose from and 100% employer covered dental & vision plans for our team members and their families. We also offer a 401(k)-retirement plan, short & long-term disability, employer-paid life insurance, Flexible Spending Accounts (FSA) for health and dependent care, and an Employee Assistance Program (EAP) 
  • Equity - This position is eligible for equity compensation  
  • Training and Career Growth - Training and internal career growth opportunities 
  • Flexible Time Off - You know when and how you should recharge 
  • Little Hippos Program - We offer 12 weeks of parental leave for primary and secondary caregivers 
  • Hippo Habitat - Snacks and drinks available and catered lunches for onsite employees

Hippo is an equal opportunity employer, and we are committed to building a team culture that celebrates diversity and inclusion. Hippo’s applicants are considered solely based on their qualifications, without regard to an applicant’s disability or need for accommodation. Any Hippo applicant who requires reasonable accommodations during the application process should contact the Hippo’s People Team to make the need for an accommodation known. 

Hippo CCPA

Top Skills

Confluence)
Drata
Grc Tools (Onetrust
Iso 27001
Itgc
JIRA
Nist
Secureframe
Soc 2
Sox
Vanta
HQ

Hippo Insurance San Jose, California, USA Office

We are located in downtown Palo Alto, just two blocks from University Avenue, one of the liveliest streets in Silicon Valley.

Similar Jobs

3 Hours Ago
Remote or Hybrid
Toronto, ON, CAN
Senior level
Senior level
Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
The Sr Solution Consultant will support sales efforts by providing technical expertise, developing product solutions, and leading customer engagements to meet sales targets.
Top Skills: Ai-Powered ToolsCloud Software SolutionsServicenow
9 Hours Ago
Remote
Canada
179K-242K Annually
Senior level
179K-242K Annually
Senior level
Artificial Intelligence • Cloud • Consumer Web • Productivity • Software • App development • Data Privacy
The Staff Product Designer will lead design initiatives for Teams & Collaboration, focusing on simplifying experiences and creating value. Responsibilities include defining problems, executing design projects, shaping strategy, and collaborating with cross-functional teams.
Top Skills: Ai-Powered Tools
10 Hours Ago
In-Office or Remote
8 Locations
168K-297K Annually
Senior level
168K-297K Annually
Senior level
Blockchain • eCommerce • Fintech • Payments • Software • Financial Services • Cryptocurrency
As a Product Manager for Automation, you'll drive AI product development, identify automation opportunities, and collaborate with teams to optimize workflows and enhance decision-making across various business areas.
Top Skills: A/B TestingAIData PipelinesMachine Learning SystemsMl

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account