Find Jobs
Find Jobs Near You – Available Work in Your Location
Skip to job details
R
RightCapital
Compliance Manager
Career Insights for Compliance Manager
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on Connecticut data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Compliance Manager tracks employer compliance with laws and regulations, particularly for organizations in business and health care. Creates company policies, reviews departmental functions and protocol, follows developments in law and regulations affecting the industry
$177,282 / year median in Connecticut
+2% projected growth
Job Description
About the role RightCapital is seeking an experienced Compliance Manager to lead both advisor-facing regulatory compliance and platform security compliance across our SaaS wealth-tech offering. This role sits at a pivotal intersection: you'll need to operate confidently in the established SaaS platform world of SOC 2, privacy, vendor risk, and financial-services regulatory considerations, while also helping steer the emerging, AI-enabled future we are building toward. You will orchestrate our SOC 2 Type II audit, serve as the primary point of contact for customer trust and vendor risk activities, and an embedded advisor to Product, Marketing, Sales, and Customer Experience on regulatory and privacy matters. You'll partner with engineering and IT, who own the technical controls, by coordinating evidence, surfacing gaps, and pushing for new controls when business or regulatory needs demand them. As AI becomes an increasingly meaningful part of what we deliver, you'll also help shape RightCapital's approach to emerging AI assurance and governance frameworks, including ISO/IEC 42001, the NIST AI Risk Management Framework, and evolving regulatory guidance from the SEC, FINRA, and state regulators, to position the company ahead of customer and regulator expectations. The Team This role sits on our Operations team, reporting to the VP, Operations, as part of our combined Legal & Compliance function. Our mission is to enable RightCapital's growth through robust regulatory oversight, disciplined data stewardship, and a credible security and privacy posture. We protect the company, our advisor customers, and the end-clients whose data flows through our platform by anticipating regulatory change, validating that internal controls operate as designed, and serving as a trusted advisor to every team. The Impact You will set the bar for how RightCapital demonstrates trust to advisors, enterprise customers, regulators, and auditors by translating complex regulatory, privacy, and security requirements into practical guidance the business can act on, and ensuring our SOC reports and customer assurance posture keep pace with our growth. Responsibilities Regulatory & Advisor-Facing Compliance Understand how financial services regulations affect our advisor and RIA customer base and our platform, including FINRA, SEC, and Investment Adviser Act considerations as they intersect with the features and communications we deliver Partner with Product and Marketing teams as an embedded compliance consultant to review product enhancement proposals, feature releases, and public-facing statements for regulatory adherence and risk exposure Develop and maintain compliance guidelines and frameworks for Product and Marketing teams to ensure platform features, promotional materials, and customer communications meet necessary regulatory standards and industry requirements Develop and maintain a regulatory horizon-scanning process to monitor changes in FINRA, SEC, state privacy laws, and other relevant frameworks; translate impact into actionable guidance for the business Privacy & Data Stewardship Serve as a key operator and enforcer of RightCapital's privacy program, keeping day-to-day practices aligned with the privacy policy and applicable regulations, and driving the internal data inventory / data map, DSAR (data subject access request) intake and fulfillment, and privacy impact assessments for new features Enforce privacy requirements across teams, holding data-handling practices accountable to documented policy and escalating exceptions and risks as needed Engage with internal stakeholders including business units, information security, and product teams to assess transaction-specific risks, particularly related to data privacy regulations (CCPA and other applicable US state frameworks) Operationalize a 'data steward' approach to consumer-permissioned data flowing through the platform, ensuring downstream uses align with consents and contractual commitments Manage sub-processor disclosures and customer notifications required under DPAs SOC 2 Audit Orchestration Orchestrate the company's annual SOC 2 Type II audit, defining scope, building the audit calendar, managing the relationship with external auditors, coordinating PBC (prepared-by-client) requests, and driving the company across the finish line on time Coordinate evidence collection from control owners across engineering, IT, HR, product, operations, and management; track evidence freshness throughout the year so audits aren't a fire drill Maintain the SOC 2 control matrix and mapping to internal policies, and ensure each control has a documented owner Identify and flag missing, weak, or outdated controls to engineering, IT, HR, product, operations, management, and leadership, including controls that may be needed for future SOC scope changes, new customer commitments, or frameworks we may choose to explore over time. This role does not implement or operate technical controls; it ensures the right controls exist and that gaps are visible and assigned Plan and facilitate tabletop exercises required to support SOC 2 and related programs including business continuity (BCP), disaster recovery, and incident response simulations document outcomes and track remediation Track and report SOC audit status, control gaps, and remediation progress to leadership on a recurring cadence AI Governance & Emerging AI Frameworks Author and maintain customer-facing AI trust materials (Trust Center AI section, AI rider language, advisor FAQs) in partnership with Marketing and the Legal and governance team Serve as the company's internal SME on AI compliance questions from Product, Engineering, Sales, and customers Monitor and translate emerging AI regulation, including the Colorado AI Act, evolving US state laws, and