San FranciscoFull TimeOperations
Remotely
grcsaasai governancepci dssiso 27001ccpahipaasoc 2 type ii
Job Description
📋 Description
- Drive compliance certifications including SOC 2 Type II, ISO 27001, PCI DSS, HIPAA, and CCPA
- Automate or execute compliance evidence collection, ensuring all controls are properly documented
- Maintain and improve security documentation including policies, procedures, and customer-facing
- Support customer security assessments by preparing materials for security reviews and helping
- Manage security and compliance topics in RFPs end-to-end, coordinating responses across
- Coordinate with contractors and vendors to maintain response quality and meet timelines during peak
🎯 Requirements
- 3-5 years of GRC experience in high-growth SaaS or tech companies with direct responsibility for
- Proven track record contributing to SOC 2, ISO 27001, or similar enterprise compliance
- Experience in data privacy regulations including CCPA, GDPR, and emerging AI governance frameworks
- Strong project management skills with ability to coordinate cross-functional teams under tight
- Excellent written and verbal communication skills to translate complex security concepts for
- Working knowledge of technical security controls and ability to collaborate effectively with
🎁 Benefits
- Compensation: $190K – $275K + Offers Equity
- Medical, Dental, and Vision benefits for you and your family
- Life Insurance and Disability Benefits
- Retirement Plan (e.g., 401K, pension)
- Parental Leave
- Fertility and family building benefits through Carrot