--- title: 'Head of IT/Compliance at Footprint' canonical: 'https://feeny.ai/job/head-of-it-compliance-footprint-new-york-4k4h9yfphx0n' type: 'job' last_seen: '2026-09-06' --- # Head of IT/Compliance at Footprint - **Company:** Footprint - **Location:** New York, NY - **Employment:** full-time - **Work type:** hybrid - **Posted:** 2026-08-26 - **Last confirmed live:** 2026-09-06 - **Apply:** https://jobs.ashbyhq.com/footprint/056f8070-5a76-4c8a-b246-593ed934bb71 ## Job description Footprint is the agentic platform that learns your compliance program and runs it end to end. Compliance teams at banks and fintechs are drowning in financial crimes investigations. Transaction volumes are surging, regulators keep raising the bar, and the work still runs on manual review queues stitched together from legacy vendors. Percy, our agentic system, learns each team's procedures and makes the same calls their analysts would: clearing false positives, escalating real risk, writing the case narrative, and documenting every decision for audit. It cuts review workloads by 70%+. The harder problem is underneath. Every investigation is grounded in the data sources compliance teams already trust, and every case commits to an organizational memory that compounds — so a pattern one analyst caught in March surfaces automatically in October, across KYC, EDD, sanctions, and monitoring. Whether the team is five analysts or 500, they share one brain. Every memory carries provenance. Agents propose; humans approve. That's four years of identity infrastructure sitting under the agent, and it's the part nobody can bolt on later. We're backed by QED, Index, and Box Group, and trusted by FDIC- and OCC-regulated banks plus fintechs like Bilt, Nuvei, and MoonPay. We 5x'd revenue last year. The team is small, senior, and ships fast. ## THE ROLE For four years, Footprint's security and compliance work has been the CTO's responsibility. SOC 2 Type 2, PCI DSS Level 1, GDPR, and ISO 27001 all got stood up and kept live. The internal systems underneath them got built the same way: SSO, device management, access control, and dozens of vendor relationships. We are hiring this first dedicated IT and Compliance role early for two reasons. First, Footprint helps companies be compliant, so we hold ourselves to the highest standards here. Our customers are banks and fintechs who trust us with some of the most sensitive data there is, and proving we deserve that trust - security questionnaires, report requests, audits - is core to how we sell, not a cost center. Second, we believe our compliance program should push the frontier on what a secure organization touching this kind of data should be. You're inheriting a real program with all four frameworks live and passing. We're in good health; we need you to take us to the next level. The mandate is to take a compliance program that passes its audits and build one that's ahead of them: vendor management, data lifecycle, endpoint coverage, and the system of record itself all become yours to systematize, and to keep pace with everything we're building next, including agentic systems. You'll own these decisions and have the trust and ownership to change how we approach this today. You'll report directly to Alex Grinman, our CTO. ## WHAT YOU'LL OWN - The compliance programs. SOC 2 Type 2, PCI DSS Level 1, GDPR, and ISO 27001, with Vanta as the system of record. You own the control state, the evidence, and the audits with our external auditors. You also own the judgment underneath them: which findings we fix now, which risks we accept and document, and where an auditor's ask deserves an argument - Identity and access. SSO, directory management, and the authentication and authorization policies behind them. Onboarding and offboarding run end to end through you, including the revocation path that has to be airtight the day someone leaves. You set the access standard for every internal service and tool we use - The device fleet. Endpoint protection and device security across every workforce machine. You own the coverage standard, the tooling choices, and the enforcement model, and you defend them to the engineers who live inside them - Technology vendors and spend. Dozens of tools, each carrying a security review, a SOC 2, ISO, or PCI risk report in Vanta, and a spend line. The vendor process is yours to design and own: the security and IT review on anything new we adopt, and the renew-or-cut calls on infrastructure spend - Security and cloud operations. You own the relationship with our pentesters and scanning vendors, and their results as audit evidence. Workforce and vendor-stack alerts run through you to resolution. Cloud operations, and the documentation of how our infrastructure fits together. Disaster recovery and the data-lifecycle program, retention through deletion, are yours to own and to test on a schedule you set - Compliance as something Sales can use. You own the customer-facing edge of the program: the report package Sales hands a prospect directly, and the hard answer on a security questionnaire when one comes back ## STACK Vanta · SSO and directory management · MDM and endpoint security · AWS · external auditors, pentesters, and continuous scanning Deep experience with most of this, and the judgment to pick up the rest, is what matters. ## MUST-HAVE - You've owned at least one compliance program end to end: scoped it, ran the audit with the auditor, and closed the findings yourself - You've been the person accountable for control state in Vanta, Drata, or an equivalent platform - You've run a workforce device fleet on a modern MDM and endpoint security stack - You've owned SSO and directory management, including the offboarding path - You've been the entire IT and compliance function at a company, with no specialist team behind you - You've made a documented risk-acceptance call under real resource constraints and can walk through the reasoning - You can explain a technical control to someone non-technical without jargon. You'll do it in the first conversation ## NICE-TO-HAVE - PCI DSS Level 1 program ownership. It's the scarcest piece of this scope and the hardest of our four frameworks to learn on the job - An engineering background of any depth. You'll set access and device policy that engineers live inside every day, and it helps to have been on their side of it - Fintech, payments, or another regulated environment. We're a company built on detecting and stopping financial crime, so knowing what a regulator actually asks for counts for a lot here - You've built a compliance function from zero at a company under 200 people. That's the exact shape of this job - Security and cryptography standards. To us, caring about this is an indicator that you're thoughtful about security ## SUCCESS LOOKS LIKE 90 Days - Endpoint coverage and control state across all four frameworks run to a standard you set, and you own the evidence for both - Vendor management runs as a process you own, with reviews, risk reports, and spend all in one place - Sales pulls a current compliance report from a package you maintain - The 2026 GDPR and SOC 2 audits are underway with you running them, and Alex has stopped being the person IT and compliance decisions route through 1 Year - Every compliance program runs on a calendar you own, with audit dates set a year out - The data-lifecycle program and disaster recovery both run on a schedule you own and test - Infrastructure and network documentation is maintained on a cadence you own - New frameworks get adopted on a schedule we set - You report vendor spend, control state, and time-to-close on vulnerability alerts as standing numbers ## WHY JOIN FOOTPRINT - Massive impact, fast: You'll work on projects that shape company direction, not analysis that gets shelved. - Own meaningful work: From day one, you'll have direct ownership over strategic initiatives that drive the business forward. - Real growth opportunity: Promotion timelines depend on performance: the harder you work, the quicker you'll get promoted. - Winning team and culture: We're a fast-moving, no-BS team that likes to win (and have fun doing it). ## BENEFITS - 💰 Generous compensation and equity packages - 🍽 Free lunch and dinner (after 7pm) - 💪 Monthly wellness stipend - 🏖 Unlimited PTO - 🏥 Fully covered health, dental, and vision insurance - 🚀 The chance to help shape the future of internet identity and financial crime prevention ## About Footprint ## Company Overview - **One-liner**: Footprint is an AI-native platform for risk operations that helps companies verify identities, block fraud, ensure compliance, and drive revenue through a unified identity and privacy platform. - **Entity Type**: Private (Series A) - **Headquarters**: New York, United States - **Founded**: 2022 - **Founders**: Eli Wachs (CEO), Alex Grinman (CTO) ## Core Business - Primary industry: Identity Infrastructure, Fraud Detection, KYC/KYB Compliance, Cybersecurity - Target customers: B2B, Enterprise (banking, payments, gaming, real estate, supply chain) - Mission or purpose statement: "Bringing interoperability and real security to the internet, by giving companies the tools to verify, authenticate, and secure identity with no friction, low cost, and unparalleled accuracy, and consumers the ability to live in a secure world that trusts and rewards them for being digital citizens." ## Products & Services - **AI-Native Risk Platform**: A generative onboarding UI that converts more users, assesses risk in milliseconds, and investigates financial crime with AI agents—automatically. Includes KYC, KYB (Know Your Business), and more, eliminating manual review and the need for BPOs. - **One-Click KYC / Identity Vault**: A unified identity and privacy platform enabling one-click KYC powered by a strong cryptographic data vault, giving consumers control over their data. ## Market Standing - **Valuation/Market Cap**: Not disclosed - **Key Metric**: Total Funding of $20.0M - **Notable Investors/Partners**: QED Investors (led Series A), Index Ventures, and 15+ other investors across seed and Series A rounds. Team members hail from Stripe, Robinhood, Brex, and Fast. - **Growth Signals**: 18 employees (+37.5% YoY growth), annual revenue of $510K (early stage), monthly web traffic of 188K visits (+173.5% YoY), top customers across banking, payments, gaming, real estate, and supply chain. Raised a $13M Series A in May 2024. ## Competitive Advantages - **AI-Native Approach**: Uses generative AI for onboarding and AI agents for fraud investigation, differentiating from legacy KYC/fraud tools. - **Privacy-First Architecture**: Cryptographic data vault puts users in control of their data, building trust and regulatory compliance. - **Strong Team DNA**: Early employees from Stripe, Robinhood, Brex, and Fast bring deep fintech and identity experience. - **Product Breadth**: Covers KYC, KYB, fraud detection, and identity verification in a single platform, reducing vendor complexity. ## Strategic Focus - Scaling the AI-native risk platform to more enterprise customers across banking, payments, gaming, and real estate. - Deepening the identity layer of the internet with a focus on interoperability and real security. - Continuing to invest in AI agents to automate manual review and financial crime investigation. - Growing the team globally with a remote-first culture. ## Why Work Here - **Culture**: Values include "Make mistakes and learn," "Lead with empathy," "No shortcuts to progress," and "Reputation is built over years, but destroyed in a day." The team is passionate, diverse, and hails from multiple countries. - **Remote/Hybrid**: Fully remote across the globe, with quarterly offsites that are described as "tasteful yet enjoyable." - **Notable Perks**: Generous benefits, a strong emphasis on work-life balance ("Work hard, be happy"), and a culture that celebrates mistakes as learning opportunities. Team members get "a ton of responsibility" and are empowered to have a big impact. - **Engineering Culture**: Small, high-agency engineering team (5 people) working on hard problems in cryptography, AI, and identity. Tech stack includes React, Figma, C, and more. ## Sources 1. [onefootprint.com](https://onefootprint.com/) 2. [onefootprint.com/company](https://onefootprint.com/company) 3. [jobs.ashbyhq.com/footprint](https://jobs.ashbyhq.com/footprint) 4. [linkedin.com/company/onefootprint](https://www.linkedin.com/company/onefootprint) 5. [theorg.com/org/onefootprint](https://theorg.com/org/onefootprint) ## Other roles at Footprint - [Founding Strategy & Ops](https://feeny.ai/job/founding-strategy-ops-footprint-new-york-4qtp2b9ygrcn) — New York, NY - [Director of Sales](https://feeny.ai/job/director-of-sales-footprint-new-york-8xmh2wt2m8my) — New York, NY - [Member of Technical Staff (Security)](https://feeny.ai/job/member-of-technical-staff-security-footprint-new-york-vzw195dh6f15) — New York, NY - [Account Executive](https://feeny.ai/job/account-executive-footprint-new-york-j2t8719qwvjk) — New York, NY - [Head of Partnerships](https://feeny.ai/job/head-of-partnerships-footprint-new-york-22c27tgg9hxk) — New York, NY - [Forward Deployed Engineer](https://feeny.ai/job/forward-deployed-engineer-footprint-new-york-z2hpe0ks8eze) — New York, NY - [Member of Technical Staff (Infrastructure)](https://feeny.ai/job/member-of-technical-staff-infrastructure-footprint-new-york-sdjgkzvcnb0p) — New York, NY - [Member of Technical Staff (Frontend)](https://feeny.ai/job/member-of-technical-staff-frontend-footprint-new-york-v48amzg2stxe) — New York, NY - [Member of Technical Staff (Backend)](https://feeny.ai/job/member-of-technical-staff-backend-footprint-new-york-yhqhnzv3tz9h) — New York, NY - [Events & Field Marketing Manager](https://feeny.ai/job/events-field-marketing-manager-footprint-new-york-55d7t8a6v1dy) — New York, NY