As Senior Manager of Customer Trust & Assurance, you'll own ServiceTitan's entire product certification portfolio (ISO 27001, SOC 1/2, PCI-DSS, ISO 42001) while building a customer trust program that accelerates enterprise sales and enables market expansion. This isn't traditional compliance. You'll architect AI-driven workflows, partner with Product and Sales to turn certifications into revenue enablers, and build scalable trust infrastructure. You'll be at the center of people, process, and technology making compliance strategic, technically sophisticated, and genuinely valuable. What you'll do: Customer Trust Program Build ServiceTitan's Customer Trust Program to differentiate us in the market and accelerate enterprise deals. Own trust infrastructure including security documentation, trust center, and customer-facing compliance portal. Partner with Sales and Customer Success to translate security controls into customer value. Create tiered security review processes and standard responses for questionnaires and RFPs. Establish trust metrics that demonstrate impact on sales velocity and customer confidence. Product Certification Program Own end-to-end management of ISO 27001, SOC 1/2, and PCI-DSS across multiple entities. Lead expansion into ISO 42001 for AI and emerging frameworks. Implement a 'Test Once, Comply Many' strategy to streamline operations. Drive continuous audit-readiness by ensuring controls are operationally effective, focusing on measurable security improvements and proactive risk mitigation. AI-Powered Compliance Operations Architect AI-driven workflows using next-gen GRC platforms (i.e. Anecdotes, Drata, Vanta) and AI tooling to automate evidence collection, control testing, and risk assessment. Drive reduction in manual work through intelligent automation. Build horizontal AI capabilities for cross-functional collaboration and vertical capabilities for deeper compliance insights and predictive analytics. Transform compliance from manual documentation to data-driven risk management. Auditor and Vendor Management Own strategic relationships with external auditors, serving as primary technical contact. Advocate for risk-based audit approaches that focus resources on highest-impact areas. Hold GRC vendors accountable for ROI and influence their product roadmaps to meet ServiceTitan's needs. Control Framework Architecture Design and maintain unified control framework across all certifications. Map controls to create a single source of truth in our GRC system of record. Establish clear ownership across Engineering, IT, Security, and business teams. Implement continuous monitoring to detect gaps and failures in real-time. Translate complex requirements into practical, sustainable controls that teams can actually implement. Product and Sales Enablement Collaborate deeply with Product and Engineering to map and maintain an accurate understanding of product architecture, data flows, and collection points. Architectural Scoping: Lead the technical definition of certification boundaries (e.g., PCI-DSS scoping) by analyzing how data moves through ServiceTitan’s ecosystem. Ensure certifications reflect current infrastructure rather than legacy snapshots. Strategic Roadmapping: Partner with Product Managers to translate customer security requirements and emerging regulations (like ISO 42001 for AI) into actionable roadmap priorities. Commercial Impact: Work with Sales to identify certifications that unlock new markets or accelerate deal cycles. Provide high-fidelity sales enablement materials and expert support for complex security RFPs. Advisory: Act as a bridge between compliance mandates and technical execution, ensuring Engineering understands the why behind control requirements to prevent 'compliance debt' in the product lifecycle. Cross-Functional Leadership Bridge Security, Engineering, IT, Finance, Legal, Product, and Sales to embed compliance into operations. Communicate certification status and risks to leadership through clear dashboards. Drive stakeholder engagement by connecting compliance to business outcomes. Build culture where compliance is competitive advantage, not burden. Compliance as Code Transform compliance from manual gathering to automated, continuous assurance. Build integrations between GRC platforms and source systems (Okta, Azure, AWS, GitHub, Jira). Implement controls through infrastructure-as-code, policy-as-code, and automated testing. Make audit-readiness continuous, not annual. Risk-Based Decision Making Apply risk-based thinking to focus resources on highest-impact areas. Scope audits based on risk, avoiding over-testing of low-risk controls. Assess and communicate residual risk when balancing compliance with business velocity. Help leadership make informed decisions about risk acceptance and resource allocation.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level
Education Level
No Education Listed