About the RoleAs our first dedicated Governance, Risk & Compliance Manager, you'll own the GRC framework end to end. This is the person who turns security from a checkbox into a competitive advantage building the continuous compliance posture that shortens enterprise sales cycles, unlocks larger contracts, and prepares us for stricter regulatory oversight and future liquidity events.
You'll operate as a senior individual contributor with broad ownership: designing controls, running audits inhouse, standing up vendor risk governance, and giving leadership real visibility into risk. You know how to build scrappy but compliant processes at a startup and how to mature them toward enterprise standards and you know the difference.
What You'll Do- Own the GRC framework. Design, implement, and continuously test a unified controls framework, including IT General Controls (ITGCs), across a growing regulatory landscape.
- Run audits inhouse. Maintain and mature our SOC 2 Type II and ISO 27001 certifications, driving toward automated, continuous evidence collection instead of manual scramble before audit cycles.
- Build the SOX roadmap. Design and test internal controls over financial reporting (ICFR) and ITGCs aligned to AICPA / PCAOB standards, delivering a gap analysis and remediation roadmap that keeps us futureready.
- Stand up vendor & third party risk. Replace manual, adhoc vendor reviews with an automated, enterprise grade third party risk program built for a complex SaaS ecosystem.
- Operationalize a risk register. Run formal, continuous internal risk assessments, map them to a corporate risk register, and review it quarterly with leadership to prioritize security spend.
- Enable the business. Build and maintain a centralized Trust Center that cuts the time sales and engineering spend answering security questionnaires.
- Shift compliance left. Partner with engineering to embed compliance into the development lifecycle so new features ship without breaking existing controls.
- Optimize the policy program. Maintain a policy suite that satisfies legal and security requirements while minimizing overhead on the teams that support our growth.
Who You AreRequired Qualifications- 5-8+ years in Information Security, IT Audit, or GRC.
- Hands-on has experience designing, implementing, and defending controls for SOC 2 Type II, ISO 27001, SOX, and/or PCI DSS.
- Strong working knowledge of SarbanesOxley compliance, including evidence preparation to AICPA or PCAOB standards.
- A track record spanning both fast-paced Series B/C startups and a mature enterprise or Big 4 audit environment: you've built processes from scratch and you've seen what "good" looks like at scale.
- Comfortably operates as a hands-on owner, not just a program overseer.
Preferred Qualifications- Experience with APIdriven / continuous GRC tooling (e.g., Vanta, Drata, or similar).
- Exposure to cloud or GPU infrastructure security.
- Relevant certifications (CISA, CISSP, CRISC, ISO 27001 Lead Auditor/Implementer).
- Experience embedding compliance into CI/CD pipelines.
What We Offer- 100% paid Medical, Dental, and Vision insurance for Employees
- Company Health Savings Account Contributions
- 100% paid Short Term and Long Term Disability Insurance for Employees
- Life and Voluntary Supplemental Insurance Options
- Other Insurance Options, such as Pet & Legal Insurance
- Various Supplementary Health Benefits, such as discounted Virtual Healthcare Appointments and Serious Illness Support
- Flexible Spending Account
- Employee Assistance Program