Security & Compliance Manager

Madrid

About us

At Sapira, we're building PHARO: the cognitive engine for heavy enterprise operations. While most AI tools are built to chat, draft emails, or summarize data, we build AI that actually executes. We deploy networks of specialized, multi-agent systems that plug directly into legacy systems, autonomously reading unstructured documents, navigating complex deterministic decision trees, and executing end-to-end workflows without human intervention. We turn slow, manual back-office bottlenecks into highly scalable digital assembly lines.

We don't build software for Silicon Valley; we build operational infrastructure for the physical economy. Our focus is strictly on high-stakes, high-volume environments like supply chain, heavy manufacturing, and logistics. And we are not just building for the future — we are operating at scale today. PHARO is already powering the back-office operations of €1B+ revenue industrial titans.

We are guided by a set of values that are at the core of our actions and define our culture: Matter-of-Fact, Cutting Through the Theater, and Ahead of the Standard. These values are the foundation of our work, and we are committed to upholding them in everything we do.

You will

  • Act as a primary point of accountability for customer trust enablement, including participation in customer meetings, security reviews and AI governance.
  • Contribute to AI Governance including building guardrails to align with AI regulations (EU AI Act, ISO 42001, NIST AI RMF and local EU laws).
  • Partner closely with Legal and Privacy to interpret regulatory requirements and support complex, security-sensitive contractual discussions, escalating risks and tradeoffs appropriately.
  • Collaborate with Engineering and Product to ensure expectations are reflected in system design and operational effectiveness.
  • Translate regulatory and privacy expectations into scalable, region-aware technical controls across model governance, agent security and safety, and data handling.
  • Own and evolve customer-facing trust materials and narratives related to AI, privacy, and security.
  • Represent Sapira in customer audits and formal assessments, clearly explaining security posture, governance decisions, and risk management approaches.
  • Support resilience and response expectations as part of broader governance, with an emphasis on learning and continuous improvement.
  • Continuously improve trust by identifying opportunities to streamline workflows, increase automation, and improve signal quality, while maintaining a high bar for accuracy and quality.

Who you'll work with

You will act as a strategic partner to Platform, Security, Product, Agent Development, Legal, and GTM, ensuring security and compliance requirements are embedded into architecture decisions, product roadmaps, and go-to-market execution while supporting product velocity and technical complexity.

Requirements

  • 8+ years of experience in security compliance, privacy, or regulatory roles in SaaS, fintech, or AI companies.
  • Deep experience with EU regulatory frameworks, including GDPR, DORA, EU AI Act and emerging AI regulations, paired with strong awareness of US regulatory norms.
  • Demonstrated ability to operate globally — understanding where requirements must diverge and where alignment is possible.
  • Experience engaging directly with enterprise and regulated customers as a trusted representative of security, privacy, and compliance.
  • Ability to translate abstract or evolving regulatory requirements into defensible, real-world practices.
  • Comfort operating in ambiguity, making reasoned judgment calls, and clearly articulating rationale and tradeoffs.
  • Strong written and verbal communication skills, including close collaboration with Legal and external stakeholders.

Nice to have

  • Direct experience preparing for or operationalizing DORA, EU AI Act or ISO/IEC 42001.
  • Experience working in and/or supporting industrial, supply chain, manufacturing, or logistics environments.
  • Familiarity with AI governance frameworks such as NIST AI RMF or CSA AI controls.
  • Experience navigating cross-border data transfer, residency, and localization considerations in a multi-cloud environment.
  • Prior experience in customer-facing, sales-adjacent, or deal-support contexts.
  • Experience automating security and compliance workflows.

Our values

  • Matter-of-fact. Why show you what's possible when we can show you what's working? We go and deliver, with real evidence. We don't pitch the future of AI — we point at the workflows it's already running.
  • Cutting through the theater. Corporate life is full of "coordination theater" — meetings about meetings, tools about tools. Being sincere means calling out the theater. We don't just report on the landscape; we trade polite dashboards for honest friction.
  • Ahead of the standard. This is how companies will operate. We're continuously searching the edge of what is possible, and we bring our clients with us.

Apply for this role.

By submitting this form I confirm I have read and accepted Sapira's Privacy Policy.