Director of GRC

SF Compute

$150K — $180K *
Enterprise Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years in high-impact GRC or security compliance roles at tech startups.
  • Hands-on experience achieving ISO 27001 certification from start to finish.
  • Proven track record in managing SOC 2 programs.
  • Demonstrated leadership success in hiring and developing teams.
  • Ability to collaborate effectively with technical teams on compliance issues.

Responsibilities

  • Hire, manage, and develop the GRC team, setting priorities and operating cadence.
  • Lead the full lifecycle of SOC 2 Type 2 and ISO 27001 certification processes.
  • Establish and maintain enterprise risk management practices and reporting.
  • Design and implement compliance policies and procedures as the company matures.
  • Own and optimize compliance automation platforms including Vanta.
  • Conduct vendor security reviews and manage third-party risk assessments.

Benefits

  • Generous equity grant offered to all team members.
  • Competitive salary with equity in the company.
  • Visa sponsorships available for eligible candidates.
  • Retirement matching for 401(k) plans up to 4%.
  • 100% coverage for medical, dental, and vision insurance for employees and dependents.
  • Unlimited paid time off plus over 10 observed holidays.
  • Paid parental leave for biological, adoptive, and foster parents.
  • Daily lunch expenses covered for employees.
  • Unlimited budget for office books.
Full Job Description
As Director of GRC, you'll own governance, risk, and compliance at SFCompute and build the team that runs it - starting with you as the first hire. We've completed our first SOC 2 audit and are pursuing ISO 27001 next. These two - maintaining SOC 2 and obtaining ISO 27001 - are the committed mandate.

Reporting to engineering leadership, you'll set the function's strategy and operating cadence, hire and manage a small GRC team, and personally build and drive the program of work from day one - designing controls, running the tooling, and managing auditors yourself until the team is in place to take it on. Much of what your team will run doesn't exist yet - the mandate is to design new functions and processes, not inherit them.

This is a build role. You should have prior startup experience in a high-impact, senior capacity, and you should have personally taken a company through an ISO 27001 certification for the first time - not just maintained one that was already in place.

About You
  • Prior experience in a senior, high-impact GRC or security compliance role at a startup - you've built programs under resource constraints, not just operated within an already-mature function.
  • Hands-on experience driving a company through its first ISO 27001 certification, from readiness through audit - standing up the program, not inheriting one already in place.
  • Experience owning or running a SOC 2 program.
  • Proven people leadership - you've hired, managed, and developed a team before.
  • Comfortable working cross-functionally with engineering on controls, tooling, and technical remediation.
Responsibilities
  • Team Leadership: Hire, manage, and develop the GRC team from day one - set its structure, priorities, and operating cadence, and own its results.
  • Compliance Program Ownership: Own our SOC 2 Type 2 program and lead ISO 27001 certification end to end - readiness, gap remediation, control implementation, auditor management, and continuous monitoring.
  • Risk Management: Stand up enterprise risk management - risk assessments, the risk register, treatment plans, and reporting to leadership.
  • Policy & Process Design: Author and operationalize the policies and functions a maturing company needs: access reviews, business continuity, security awareness, and vendor management. Collaborate with departments to ensure change management and incident response policies are sensible and meet compliance obligations.
  • GRC Tooling: Own our compliance automation platform, Vanta, and drive selection and integration of GRC-related tooling.
  • Third-Party Risk: Own vendor security reviews and third-party risk assessments.

Nice to Haves
  • Hold relevant certifications such as CISA, CISM, CISSP, CRISC, or ISO 27001 Lead Implementer/Auditor.
  • Have operated compliance automation platforms (Vanta or similar).
  • Have privacy program experience (GDPR/CCPA).
Benefits

Generous equity grant

Team members are offered a competitive salary along with equity in the company

Visa Sponsorships

Yes, we sponsor visas and work permits

Retirement matching

We match 401(k) plans up to 4%

Medical, dental & vision

We offer competitive medical, dental, vision insurance for employees and dependents and cover 100% of premiums

Time off

We offer unlimited paid time off as well as 10+ observed holidays

Parental leave

We offer biological, adoptive, and foster parents paid time off to spend quality time with family

Daily lunch

We cover lunch daily for employees

Unlimited office book budget

You can buy as many books for the office as you want

Similar Jobs

More Jobs at SF Compute

  • Director of GRC
    $150K — $180K *
    San Francisco, CA 94112 (San Francisco County)
    Enterprise Technology
    In-Person
  • Go-To-Market Generalist
    $110K — $130K *
    San Francisco, CA 94112 (San Francisco County)
    Enterprise Technology
    In-Person
  • People Operations Manager
    $110K — $130K *
    San Francisco, CA 94112 (San Francisco County)
    Business Services
    In-Person
  • General Counsel
    $200K — $250K *
    San Francisco, CA 94112 (San Francisco County)
    Legal & Accounting
    In-Person
  • Staff Design Engineer
    $130K — $180K *
    San Francisco, CA 94112 (San Francisco County)
    Consumer Technology
    In-Person

More Enterprise Technology Jobs

Find similar Director of GRC jobs: