Compliance and Documentation Lead
Deepgram
Tailor my CV for this job, freeView job and applyYour CV rewritten for this role, from your real experience. Sign in with Google, nothing to install.
Got this interview? Our apps help you get the job.
Skills named in this job
Read from the description itself, not inferred.
This role on the market
50 open documentation roles across 25 companies are on ApplySarthi right now, most of them in Bengaluru (4), Chennai (2), Hyderabad (1).
- Documentation & Training CoordinatorAbbott
- Design Systems Documentation LeadServiceNow
- Stagiaire documentation par IA H/FHitachi
- Project Coordinator - Project Quality Audits & Documentation ReviewJll
- Medical Scribe & Clinical Documentation Virtual AssistantJobgether
What documentation roles keep asking for: REST APIs (14%) — counted across their open postings here.
Deepgram has 101 open roles listed here.
- EMEA Account Executive (German speaking)
- Privacy Operations Lead
- Infrastructure Partner Director
- Security Engineer
- Senior Partner Manager, AWS
Counted across 14 company job boards, updated as roles open and close.
Preparing for this interview
Interviews for documentation roles keep coming back to REST APIs. Practise those questions before you sit with Deepgram.
Questions you are likely to be asked
- Why do you want to join Deepgram?
- What is your experience with SQL? Tell me one thing you learned the hard way.
- What is a weakness you are working on, and how?
- Tell me about yourself, and why this role is the right next step.
- Tell me about a problem you solved at work that you are proud of.
Prep Sarthi gives you a free mock interview: an AI interviewer asks you questions like these out loud, from your own CV and this job, and shows your score and your weakest answer.
Practise the Compliance and Documentation Lead at Deepgram interview free →Company Overview Deepgram is the leading platform underpinning the emerging trillion-dollar Voice AI economy, providing real-time APIs for speech-to-text (STT), text-to-speech (TTS), and building production-grade voice agents at scale. More than 200,000 developers and 1,300+ organizations build voice offerings that are ‘Powered by Deepgram’, including Twilio, Cloudflare, Sierra, Decagon, Vapi, Daily, Cresta, Granola, and Jack in the Box. Deepgram’s voice-native foundation models are accessed through cloud APIs or as self-hosted and on-premises software, with unmatched accuracy, low latency, and cost efficiency. Backed by a recent Series C led by leading global investors and strategic partners, Deepgram has processed over 50,000 years of audio and transcribed more than 1 trillion words. There is no organization in the world that understands voice better than Deepgram. Company Operating Rhythm At Deepgram, we expect an AI-first mindset—AI use and comfort aren’t optional, they’re core to how we operate, innovate, and measure performance. Every team member who works at Deepgram is expected to actively use and experiment with advanced AI tools, and even build your own into your everyday work. We measure how effectively AI is applied to deliver results, and consistent, creative use of the latest AI capabilities is key to success here. Candidates should be comfortable adopting new models and modes quickly, integrating AI into their workflows, and continuously pushing the boundaries of what these technologies can do. Additionally, we move at the pace of AI. Change is rapid, and you can expect your day-to-day work to evolve just as quickly. This may not be the right role if you’re not excited to experiment, adapt, think on your feet, and learn constantly, or if you’re seeking something highly prescriptive with a traditional 9-to-5. The Opportunity Deepgram is looking for a Compliance and Documentation Lead to own the written and evidentiary backbone of our compliance program — privacy and security both — and the documents that auditors, enterprise customers, and our own engineers rely on to know what we actually do. This is one seat covering both halves deliberately. You will own our privacy program's operational work — assessments, data flow maps, deletion and rights workflows, subprocessor reviews — and our security compliance obligations under SOC 2, ISO 27001, and PCI DSS, along with the security questionnaires, policies, and public posture documents that sit on top of them. The reason to combine them is leverage: the same underlying facts about how Deepgram handles data answer a DPIA, a SOC 2 control, and a Fortune 500 questionnaire. Establishing them once and reusing them is the job. Context matters here, because the claims you will be writing are unusually specific. Deepgram processes audio — often some of the most sensitive data our customers hold — across several deployment models: hosted with model-improvement opted in, hosted with model-improvement opted out (effectively zero data retention), single-tenant Deepgram Dedicated deployments with regional data residency, and fully self-hosted deployments running in the customer's own environment. Getting a statement right means knowing which of those it applies to. Writing is the core skill in this role, and we mean writing that survives a skeptical reader — an auditor, an enterprise security reviewer, a customer DPO, an engineer who knows the system better than you do. Where a claim needs technical verification, you define what has to be proven and partner with Security Engineering to prove it; you are not expected to do that engineering work yourself. This role reports to the Director of Information Security and works closely with Security Engineering, Legal, Research, and Solutions/Sales Engineering. We are open on level. This is a senior individual-contributor role, and we will calibrate title, scope, and compensation to demonstrated experience. About Deepgram Deepgram builds foundational voice AI — speech-to-text, text-to-speech, and voice agent infrastructure — used by enterprises and developers to build production voice applications at scale. Our models are trained and served on our own infrastructure, and we offer hosted, dedicated single-tenant, and self-hosted deployment options so customers can meet their own data residency and retention requirements. Learn more at deepgram.com . Responsibilities Privacy program Own customer and prospect privacy risk assessments, DPIAs, and transfer impact assessments end to end. Be the technical voice in customer privacy reviews and vendor due diligence calls. Build and maintain accurate data flow maps and records of processing across hosted, dedicated, and self-hosted deployments — and own the process that keeps them accurate as the product changes. Own the operating model for our privacy controls: retention and deletion enforcement, DSAR and deletion workflows, consent and opt-out handling, de-identification and redaction. You specify, instrument, test, and audit; Engineering builds. Own the subprocessor and vendor privacy review process, and the artifacts behind our DPAs. Translate GDPR, UK GDPR, CCPA/CPRA and other US state privacy laws, and emerging AI regulation (EU AI Act, state AI and automated decision-making rules) into concrete requirements engineering and GTM teams can act on, rather than memos. Partner with Legal on DPAs, SCCs, transfer mechanisms, and the residency commitments we make for dedicated deployments. Security compliance and audit Own audit evidence end to end for SOC 2, ISO 27001, and PCI DSS — what evidence is required, who produces it, where it lives, and whether it would actually satisfy a reviewer. Be the auditor's primary point of contact through fieldwork. Own control mapping across frameworks. Build and maintain the crosswalk so one control and one piece of evidence satisfies SOC 2, ISO 27001, PCI DSS, privacy obligations, and customer questionnaires — rather than running the same work four times. Own security questionnaires and the security sections of RFPs. Maintain the answer library, keep it current as the product changes, and know which answers to fight for and which to concede. Partner with Security Engineering so evidence is generated once, by automation, and reused — and flag where a manual evidence pull should become an automated one. Documentation and enablement Author and own the lifecycle of our internal policies and standards: drafting, review and approval cycles, annual review, exceptions and carve-outs, and retiring what no longer reflects reality. Own our public-facing posture documents — Trust Center content, the AI Safety statement, Model Cards (with Research), the Privacy Policy (with Legal), and the deployment-model and self-hosted documentation customers rely on during review. Own the documentation system itself: where documents live, how they are versioned and reviewed, and how a customer-facing claim traces back to an internal source of truth. Nothing we say publicly should be unattributable. Design and run operational auditing and remediation workflows, so drift between what we claim and what we do is caught by process rather than by a customer. Run compliance and privacy training and enablement, including clear guidance to Sales Engineering on what they may and may not commit to on a customer call. Skills Needed Substantial experience in privacy operations, GRC, security compliance, or technical compliance documentation — enough that you have carried assessments or an audit cycle end to end and owned the outcome. Exceptional writer. This is the central requirement, not a soft skill. You can turn a messy technical reality into a document a skeptical auditor, customer, or engineer will accept. Demonstrated ownership of compliance operational systems at scale: data maps, DSAR workflows, evidence collection, answer libraries, policy sets, or the tooling behind them. Hands-on involvement in at least one formal audit — SOC 2, ISO 27001, or PCI DSS — as the person producing and defending evidence, not only as a reader of the report. Practical, applied experience with GDPR and CCPA/CPRA, and a current view of where AI regulation is heading. Technically fluent and unintimidated: you can read an architecture diagram, follow a data flow through cloud infrastructure, understand what a log line or a retention setting actually implies, and ask the question that exposes a gap — without needing someone to translate for you. Able to hold your own with a Fortune 500 privacy team, security reviewer, or DPO without escalating every question. Startup-friendly judgment. You know which questionnaire answers are worth fighting for and which to concede, and when a policy needs a carve-out rather than a mandate. Controls and policies that ignore how the company actually ships get routed around, and we would rather you name the trade-off than write the ideal version. Bias toward building systems and templates rather than becoming the person every request has to route through. Comfortable with ambiguity and with making a defensible call when the law or the standard is unsettled. Nice to Have Certification such as CIPM, CIPT, CIPP/E, CISA, or ISO 27001 Lead Implementer/Auditor. Experience with compliance automation platforms (Vanta, Drata, or similar) and trust center tooling. Familiarity with AI governance frameworks — NIST AI RMF, ISO/IEC 42001, EU AI Act — and with model documentation practice. Experience with ML/AI data pipelines and training-data governance. Compliance work in a hybrid model — multi-tenant SaaS alongside self-hosted or on-premise deployments. Comfort with SQL, light scripting, or AI and agentic tooling to pull and assemble your own evidence rather than filing a ticket for it. Exposure to HIPAA or FedRAMP. Notice : We're aware of individuals impersonating Deepgram recruiters. All legitimate Deepgram recruiting communication comes from an @ deepgram.com email address. If you've received a message claiming to be Deepgram, please forward it to careers@deepgram.com.
Match this job to your CV
ApplySarthi scores your CV against this role, shows the skills you are missing, and writes a tailored version for the application.
Check my match →Similar open roles
- Pre-Sales Solutions Engineer (EST or PST)Deepgram
- Strategic Account Executive (Chicago & Texas)Deepgram
- Research Staff, Voice AI FoundationsDeepgram
- Sales Development RepresentativeDeepgram
- Solutions Architect (EST or PST hours)Deepgram
- Senior Data Scientist, AudioDeepgram
- Corporate Account ExecutiveDeepgram
- Research Staff, Data ScienceDeepgram
Need answers during your interview? Try Live Sarthi.
Live Sarthi, an Interview Sarthi app, shows answer suggestions during the call.
- Hidden from supported screen sharingThe overlay stays out of supported Windows screen captures.
- Answers start in about 1.5 secondsResponse time varies with your connection and model.
- From your own CVYour projects and your experience, not a generic script.
- 30 minutes freeThen ₹99 for a 2-day pass with unlimited calls — you pay for the days you are interviewing, not a subscription.
A Windows app, from the same team as ApplySarthi.
Listed on ashby · posted 2026-10-01. ApplySarthi collects openings and links to application pages; the role is advertised by Deepgram, not by us.