Sigma Computing

Director, Trust & Assurance

Sigma Computing$225K — $265K *
Enterprise Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 4+ years in governance, risk management, or compliance roles, preferably in technology companies
  • Experience building or maturing a GRC program from the ground up
  • Proven track record with certification audits (SOC 2, ISO 27001, HIPAA)
  • Knowledge of risk management frameworks (COSO, ISO 31000, NIST RMF)
  • Familiarity with data privacy regulations (GDPR, CCPA)

Responsibilities

  • Design and implement governance frameworks and control oversight
  • Develop a comprehensive Enterprise Risk Management (ERM) program
  • Conduct enterprise-wide risk assessments and maintain a risk register
  • Manage audit and certification programs for relevant standards
  • Support sales teams with compliance documentation and security inquiries

Benefits

  • Equity
  • Generous health benefits
  • Flexible time off policy
  • Paid bonding time for new parents
  • Traditional and Roth 401k
  • Commuter and FSA benefits
  • Lunch Program
  • Dog friendly office
Full Job Description
Director, Trust & Assurance

Reports to: General Counsel

Location: San Francisco office or New York office

Type: Full-time

About the Role

Sigma is looking for a Director of Trust & Assurance to build and run our compliance and enterprise risk function, and to lead the team behind it. You will own our GRC program end-to-end (SOC 2/ISO audits, policies, vendor risk) while positioning the team and the function to grow into an enterprise risk function as the company matures. This is a builder-and-leader role for someone who has run a similar successful program.

You will take ownership of compliance, contractual, vendor, and enterprise/business risk, reporting directly to the General Counsel, with a team reporting to you.

You will also work closely with Security, HR, Sales, and other members of leadership.

What You'll Do

Compliance & Controls
  • Own our SOC 2 (and/or ISO 27001) program - including PCI DSS and other relevant standards as applicable - covering control implementation, evidence collection, audit management, and remediation tracking
  • Maintain and evolve our internal policy library and employee attestation process
  • Monitor regulatory requirements relevant to our business (data privacy, industry-specific regulations) and work with the Legal team to assess impact and translate requirements into practical controls
  • Conduct internal audits and assessments to validate control effectiveness
  • Manage security awareness training programs enterprise-wide

Vendor & Third-Party Risk
  • Run vendor risk assessments and maintain a vendor risk inventory, including contract reviews and ongoing monitoring
  • Manage subprocessor tracking and disclosures
  • Partner with Legal on risk-related contract terms for vendors

Customer Trust
  • Own the security questionnaire response process (VSAs, SIGs, and custom questionnaires) and our customer-facing trust documentation
  • Maintain ready-to-use compliance artifacts and trust center content to support efficient deal cycles
  • Act as a trusted resource for Sales, Sales Engineering, and Solutions teams on security-related deal questions

Business Continuity & Incident Response
  • Maintain our business continuity/disaster recovery plan, including regular testing
  • Together with the Security team, own the incident response plan, including running periodic tabletop exercises
  • Lead post-incident reviews and track remediation

Growth into Enterprise Risk
  • Mature and maintain a enterprise risk register
  • Create risk treatment plans and track remediation activities across the organization
  • Run quarterly risk reviews
  • Scan for emerging risks (regulatory, market, operational) and flag material developments to the GC

Insurance
  • Manage the company's insurance program (cyber, E&O, D&O) including renewals and coverage review
  • Serve as primary point of contact with brokers and carriers

Team Leadership
  • Manage and develop a team of 3+ direct reports covering compliance analysts, vendor risk, and/or a GRC coordinator
  • Set goals, run performance reviews, and build career paths for direct reports

What We're Looking For
  • 8+ years of experience in GRC, compliance, audit, or risk management, ideally in a SaaS or technology company, including at least 2-3 years directly managing people
  • Has personally owned a SOC 2 or ISO 27001 program through at least one full audit cycle, including managing the auditor relationship end-to-end - not just executing tasks within someone else's program
  • Track record of building a function or program from the ground up, not just maintaining an established one
  • Experience with vendor/third-party risk assessment processes
  • Experience implementing risk management frameworks (COSO, ISO 31000, NIST RMF, or similar)
  • Ability to translate technical/security concepts into risk language for executives and business language for engineers, with excellent communication skills to influence stakeholders at all levels
  • Strong project management skills; comfortable juggling audits, questionnaires, and quarterly reporting simultaneously
  • Bonus: experience with GRC tooling (Vanta, Drata, Secureframe, ServiceNow GRC, Archer, LogicGate, or similar)
  • Bonus: hands-on experience with cloud environments (GCP, AWS, Azure) from a compliance and security perspective
  • Bonus: familiarity with security frameworks such as NIST CSF, CIS Controls, or OWASP
  • Bonus: relevant certifications (CISA, CRISC, CISSP, CGRC, CRM, CISM, CGEIT, or CIPP)

What Success Looks Like in Year One
  • SOC 2 Type II achieved/maintained with no material findings
  • Vendor risk assessment process in place and adopted before contract signing
  • Enterprise risk register matured and reviewed quarterly
  • Incident response plan tested via tabletop exercise
  • Insurance program reviewed for adequacy with no coverage gaps
  • Security questionnaire turnaround time meets sales cycle needs

Additional Job details

The base salary range for this position is $225k to $265k annually.

Compensation may vary outside of this range depending on a number of factors, including a candidate's qualifications, skills, competencies and experience. Base pay is one part of the Total Package that is provided to compensate and recognize employees for their work at Sigma Computing. This role is eligible for stock options, as well as a comprehensive benefits package.

Benefits For Our Full-Time Employees:
  • Equity
  • Generous health benefits
  • Flexible time off policy. Take the time off you need!
  • Paid bonding time for all new parents
  • Traditional and Roth 401k
  • Commuter and FSA benefits
  • Lunch Program
  • Dog friendly office


Note: We have an in-office work environment in all our offices in SF, NYC, London and Sydney.

Sigma's use of AI

This hiring process utilizes artificial intelligence tools to assist in candidate screening and assessment. Our AI tools are designed to complement, not replace, human decision-making.

About Sigma Computing

Sigma Computing is a cloud-based analytics and business intelligence platform that allows users to analyze data from various sources without the need for coding or SQL. The platform is designed to be user-friendly and accessible to non-technical users, while still providing powerful analytics capabilities. Sigma Computing's customers include Blue Apron, Snowflake, and Upwork. The company was founded in 2014 and is headquartered in Palo Alto, California.
Learn more about Sigma Computing
Size
100 employees
Industry
Founded
2014

Similar Jobs

More Jobs at Sigma Computing

  • Sigma Computing
    Director, Trust & Assurance
    $225K — $265K *
    San Francisco, CA 94112 (San Francisco County)
    Enterprise Technology
    In-Person
  • Sigma Computing
    Head of Pipeline Strategy
    $180K — $200K *
    San Francisco, CA 94112 (San Francisco County)
    Enterprise Technology
    In-Person
  • Sigma Computing
    Head of Pipeline Strategy
    $180K — $200K *
    New York, NY 10025 (New York County)
    Business Services
    In-Person
  • Sigma Computing
    Data Engineer
    $140K — $180K *
    San Francisco, CA 94112 (San Francisco County)
    Information Technology
    In-Person
  • Sigma Computing
    Business Value Marketing Manager
    $126K — $148K *
    San Francisco, CA 94112 (San Francisco County)
    Business Services
    In-Person

More Enterprise Technology Jobs

Find similar Director, Trust & Assurance jobs: