About the job
Join the Future of Finance with Light!
At Light, we are on a mission to revolutionize the outdated ERP systems of the past with a cutting-edge software solution that feels dynamic and intuitive. Our Smart Financial Platform empowers global enterprises with automated accounting, real-time reporting, and the ability to manage financial flows at an unprecedented speed.
We pride ourselves on our collaborative culture, rapid delivery, and meticulous attention to detail. In just a short period, Light has evolved from a concept to the essential operating core for prominent companies such as Lovable, Legora, and Keyshot. Our users don't just utilize Light—they revel in the experience.
As a pioneering team, we are defining a new software category, bringing together engineers passionate about debits and credits, designers focused on reconciliation states, and operators treating finance as a product. If you are eager to modernize how money flows in the world—one innovative workflow at a time—you are in the right place.
Supported by top-tier investors and guided by industry leaders, we are creating category-defining products with the autonomy to execute ambitious plans and take ownership of our results.
Join us in making Light the global standard for next-gen finance.
Your Role: Global Compliance Manager
As the Global Compliance Manager, you will take charge of compliance execution at Light. Reporting to the Head of Finance & Core Operations, you will manage our SOC 1, SOC 2, and PCI compliance programs from start to finish, ensuring we remain audit-ready and that our controls function effectively in practice.
This is a hands-on, operational role where you will coordinate audits, collaborate with DevSecOps and engineering teams on control implementation, track evidence and remediation efforts, and assist with customer and partner due diligence processes. Your mission is to make compliance straightforward, predictable, and scalable.
Our Working Environment
Utilizing AWS infrastructure (EKS, RDS PostgreSQL, Lambda, ECR, S3, SES, Bedrock for AI/LLM)
Kotlin backend with Gradle, Next.js frontend with TypeScript
Employing GitHub Actions for CI/CD, Terraform for infrastructure management, Kubernetes using Tanka/Jsonnet
Monitoring with Datadog and CloudWatch
A distributed team of 25 engineers scaling to 50+
Your Responsibilities
Manage compliance programs for SOC 1, SOC 2 (Type I & II), and PCI DSS
Plan and oversee audits, including managing timelines and auditor relationships
Lead evidence collection, review, and submission processes
Track audit findings and ensure timely remediation in collaboration with engineering
Facilitate customer and partner due diligence processes

