Jobs and Careers
BL

Compliance & Risk Manager

Blossom
Remote - United States, United StatesRemotefull_timeVerifiedPosted 2 Jul 2026
💰 $105,000/yr($95,000/yr$105,000/yr)

About the role

FLSA Classification: Exempt

Reports To: Chief Financial Officer (CFO)


Job Summary:

The Compliance & Risk Manager is responsible for managing and executing Blossom’s compliance and risk management programs. Reporting to the CFO, this role oversees day-to-day compliance operations across all regulatory, security, and audit functions—including SOC 2 Type II, PCI DSS, and all compliance obligations associated with Blossom’s hardware and software products while maintaining a risk management framework that identifies, tracks, and mitigates operational, financial, regulatory, and strategic risks. This role collaborates closely with Engineering, Product, Legal, HR, and Operations to support a culture of compliance and risk awareness across the organization. This role works in close partnership with the IT and Infrastructure function, which retains ownership of technical security controls, HSM/key management, and PCI Security; the Compliance & Risk Manager owns program management, audit coordination, the enterprise risk framework, and policy.


Supervisory Responsibilities:

  • Support the recruitment and onboarding of compliance and risk staff; provide day-to-day guidance and oversight to any direct reports within the function.


Duties/ Responsibilities:

Audit & Certification Management

  • Own the end-to-end SOC 2 Type II audit lifecycle: scope definition, control design, evidence collection, auditor coordination, and remediation tracking.

  • Lead PCI DSS compliance efforts across applicable business units, including scope management, gap assessments, and coordination with Qualified Security Assessors (QSAs).

  • Manage relationships with external auditors, assessors, and certification bodies; serve as primary point of contact during audit engagements.

  • Maintain a comprehensive controls inventory; ensure all controls are documented, tested, and operating effectively.

  • Track and manage audit findings and remediation plans through to closure in collaboration with control owners.

Enterprise Risk Management

  • Manage and maintain the enterprise risk management (ERM) framework, ensuring risks across operational, regulatory, financial, strategic, and technology domains are identified, assessed, prioritized, and tracked.

  • Maintain and update the company-wide risk register; coordinate with risk owners to ensure mitigation and remediation plans are tracked to resolution.

    • Conduct periodic enterprise risk assessments; summarize findings and risk trends for CFO review.

    • Collaborate with Product, Engineering, Finance, HR, and Operations to identify and flag risks associated with new initiatives, product launches, and process changes.

    • Support operational risk programs including business continuity planning (BCP), disaster recovery readiness, and incident response protocols in coordination with IT and Engineering.

    • Administer the third-party and vendor risk assessment process, evaluating vendors for security, financial stability, regulatory alignment, and contractual risk.

    • Monitor the evolving risk landscape—including emerging cyber threats, regulatory changes, and market developments—and flag potential impact to leadership.

    • Support the CFO in maintaining the company’s risk appetite and tolerance thresholds; help ensure business decisions align with established risk parameters.

    • Respond to credit union client risk and security due diligence requests, including vendor questionnaires and risk assessments.

    • Maintain required risk documentation including the risk register, risk appetite statements, and reporting artifacts in a manner that supports executive review and external audit.

Regulatory & Policy Compliance

  • Monitor and interpret federal, state, and credit union-specific regulatory requirements applicable to Blossom’s software and hardware products (e.g., NCUA guidance, FFIEC frameworks, GLBA, applicable state laws).

  • Maintain and update company-wide compliance policies, standards, and procedures; ensure alignment with regulatory requirements and industry best practices.

  • Conduct regular internal audits and control testing to evaluate compliance with applicable laws, regulations, and internal policies.

Hardware & Software Product Compliance

  • Ensure Blossom’s hardware and software products comply with applicable regulatory standards, including security and interoperability requirements for financial technology

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Blossom

View company profile →