Job Description
📋 Description Lead and scale Sigma's GRC, security, and compliance programs Own SOC 2 / ISO audits and vendor risk program Build and maintain policies, attestation processes, and controls Monitor regulatory requirements and translate into practical controls Conduct internal audits and validate control effectiveness Oversee security awareness training enterprise-wide Collaborate with Legal, Security, HR, and Sales to align risk posture 🎯 Requirements 8+ years in GRC, compliance, audit, or risk management Led SOC 2 or ISO 27001 program through a full audit cycle Proven track record building a function from scratch Experience with vendor/third-party risk assessments Experience implementing frameworks (COSO, ISO 31000, NIST RMF) Able to translate technical concepts into risk language for executives Strong project management; handling audits and quarterly reporting 🎁 Benefits Equity Generous health benefits Flexible time off Paid bonding time for new parents Traditional and Roth 401k Commuter and FSA benefits Dog-friendly office