Job Description
📋 Description Report to Head of InfoSec & Compliance; mature GRC programs with cross-functional teams. Manage the GRC control evidence library; investigate flags and collect evidence. Manage vendor risk program; intake, security/risk assessments, reviews, monitoring. Review security artifacts: SOC 2 Type II, pen tests, CAIQ, SIG, ISO, audits. Assist with implementing security/risk frameworks; add GDPR/ISO/SOC 2 controls. Assist with security questionnaires and client audits; manage knowledge base. 🎯 Requirements 4+ years in GRC/InfoSec with experience scaling programs. Hands-on GRC program at scale in high-growth SaaS/tech. Experience with GRC platforms: compliance, risk registers, policy lifecycle, evidence collection. Deep expertise in SOC 2 Type II and ISO 27001; HIPAA knowledge preferred. Experience conducting product/enterprise risk assessments with quant methods. AI-forward; automate processes; certifications: CISM/CRISC/CISA/CCSP preferred. 🎁 Benefits Compensation and equity: salary and stock options. Health plans: 100% coverage for medical, dental, vision. Time off: Unlimited PTO and 11 holidays. Health: Unlimited sick leave. Parental leave: Paid leave for new parents. Remote-friendly: $1,000 home office stipend.