Compliance Risk Manager positions focus on delivering results in their domain. This page aggregates open Compliance Risk Manager roles and what employers typically expect.
**FLSA Classification:** Exempt **Reports To:** Chief Financial Officer (CFO) **Job Summary:** The Compliance & Risk Manager is responsible for managing and executing Blossom’s compliance and risk management programs. Reporting to the CFO, this role oversees day-to-day compliance operations across all regulatory, security, and audit functions—including SOC 2 Type II, PCI DSS, and all compliance obligations associated with Blossom’s hardware and software products while maintaining a risk management framework that identifies, tracks, and mitigates operational, financial, regulatory, and strategic risks. This role collaborates closely with Engineering, Product, Legal, HR, and Operations to support a culture of compliance and risk awareness across the organization. This role works in close partnership with the IT and Infrastructure function, which retains ownership of technical security controls, HSM/key management, and PCI Security; the Compliance & Risk Manager owns program management, audit coordination, the enterprise risk framework, and policy. **Supervisory Responsibilities:** - Support the recruitment and onboarding of compliance and risk staff; provide day-to-day guidance and oversight to any direct reports within the function. **Duties/ Responsibilities:** **Audit & Certification Management** - Own the end-to-end SOC 2 Type II audit lifecycle: scope definition, control design, evidence collection, auditor coordination, and remediation tracking. - Lead PCI DSS compliance efforts across applicable business units, including scope management, gap assessments, and coordination with Qualified Security Assessors (QSAs). - Manage relationships with external auditors, assessors, and certification bodies; serve as primary point of contact during audit engagements. - Maintain a comprehensive controls inventory; ensure all controls are documented, tested, and operating effectively. - Track and manage audit findings and remediation plans through to closure in collaboration with control owners. **Enterprise Risk Management** - Manage and maintain the enterprise risk management (ERM) framework, ensuring risks across operational, regulatory, financial, strategic, and technology domains are identified, assessed, prioritized, and tracked. - Maintain and update the company-wide risk register; coordinate with risk owners to ensure mitigation and remediation plans are tracked to resolution. - Conduct periodic enterprise risk assessments; summarize findings and risk trends for CFO review. - Collaborate with Product, Engineering, Finance, HR, and Operations to identify and flag risks associated with new initiatives, product launches, and process changes. - Support operational risk programs including business continuity planning (BCP), disaster recovery readiness, and incident response protocols in coordination with IT and Engineering. - Administer the third-party and vendor risk assessment process, evaluating vendors for security, financial stability, regulatory alignment, and contractual risk. - Monitor the evolving risk landscape—including emerging cyber threats, regulatory changes, and market developments—and flag potential impact to leadership. - Support the CFO in maintaining the company’s risk appetite and tolerance thresholds; help ensure business decisions align with established risk parameters. - Respond to credit union client risk and security due diligence requests, including vendor questionnaires and risk assessments. - Maintain required risk documentation including the risk register, risk appetite statements, and reporting artifacts in a manner that supports executive review and external audit. **Regulatory & Policy Compliance** - Monitor and interpret federal, state, and credit union-specific regulatory requirements applicable to Blossom’s software and hardware products (e.g., NCUA guidance, FFIEC frameworks, GLBA, applicable state laws). - Maintain and update company-wide compliance policies, standards, and procedures; ensure al…