Job Description
📋 Description Own and continuously mature the company risk register; design a risk management workflow that uses Lead external audit management (SOC 2 Type II); automate evidence collection pipelines in Vanta so Engineer the Trust and Assurance program for scale: build automated intake and triage workflows for Build a vendor and supply chain risk program that goes beyond static spreadsheets. Design automated Redesign and maintain security and privacy policies; use AI to draft, version, and track policy Own common controls monitoring in Vanta. Configure and tune integrations, checks, and alerting so 🎯 Requirements 3+ years of experience in GRC, information security compliance, or risk management. Working knowledge of SOC 2 (Trust Services Criteria), with hands-on experience supporting or Familiarity with additional frameworks is a strong plus: CIS Controls v8, NIST CSF, NIST AI RMF Experience conducting rapid third-party/vendor risk assessments and managing a supply chain risk Strong organizational skills with the ability to manage multiple concurrent workstreams and Excellent written communication, capable of drafting clear, audience-appropriate policy documents 🎁 Benefits Compensation range: $130,000-$170,000