Governance, Risk, and Compliance Manager

TensorWave

$110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5-8+ years in Information Security, IT Audit, or GRC
  • Hands-on experience with SOC 2 Type II, ISO 27001, SOX, and/or PCI DSS
  • Strong knowledge of Sarbanes-Oxley compliance
  • Experience in both fast-paced startups and mature enterprises or Big 4 audit firms
  • Ability to operate as a hands-on owner rather than just managing programs

Responsibilities

  • Own the GRC framework by designing and implementing a controls framework
  • Run inhouse audits to maintain and mature SOC 2 Type II and ISO 27001 certifications
  • Build a roadmap for SOX compliance, aligning internal controls with AICPA/PCAOB standards
  • Establish an automated vendor and third-party risk management program
  • Operationalize a risk register through continuous internal assessments
  • Enable business teams by creating a centralized Trust Center for security questionnaire efficiencies
  • Embed compliance into the development lifecycle to streamline feature shipping

Benefits

  • Stock Options
  • 100% paid Medical, Dental, and Vision insurance for Employees
  • Company Health Savings Account Contributions
  • 100% paid Short Term and Long Term Disability Insurance for Employees
  • Life and Voluntary Supplemental Insurance Options
  • Flexible Spending Account
  • 401(k)
  • Flexible PTO
  • Paid Holidays
  • Parental Leave
  • Employee Assistance Program
Full Job Description
About the Role

As our first dedicated Governance, Risk & Compliance Manager, you'll own the GRC framework end to end. This is the person who turns security from a checkbox into a competitive advantage building the continuous compliance posture that shortens enterprise sales cycles, unlocks larger contracts, and prepares us for stricter regulatory oversight and future liquidity events.

You'll operate as a senior individual contributor with broad ownership: designing controls, running audits inhouse, standing up vendor risk governance, and giving leadership real visibility into risk. You know how to build scrappy but compliant processes at a startup and how to mature them toward enterprise standards and you know the difference.

What You'll Do
  • Own the GRC framework. Design, implement, and continuously test a unified controls framework, including IT General Controls (ITGCs), across a growing regulatory landscape.
  • Run audits inhouse. Maintain and mature our SOC 2 Type II and ISO 27001 certifications, driving toward automated, continuous evidence collection instead of manual scramble before audit cycles.
  • Build the SOX roadmap. Design and test internal controls over financial reporting (ICFR) and ITGCs aligned to AICPA / PCAOB standards, delivering a gap analysis and remediation roadmap that keeps us futureready.
  • Stand up vendor & third party risk. Replace manual, adhoc vendor reviews with an automated, enterprise grade third party risk program built for a complex SaaS ecosystem.
  • Operationalize a risk register. Run formal, continuous internal risk assessments, map them to a corporate risk register, and review it quarterly with leadership to prioritize security spend.
  • Enable the business. Build and maintain a centralized Trust Center that cuts the time sales and engineering spend answering security questionnaires.
  • Shift compliance left. Partner with engineering to embed compliance into the development lifecycle so new features ship without breaking existing controls.
  • Optimize the policy program. Maintain a policy suite that satisfies legal and security requirements while minimizing overhead on the teams that support our growth.


Who You Are

Required Qualifications
  • 5-8+ years in Information Security, IT Audit, or GRC.
  • Hands-on has experience designing, implementing, and defending controls for SOC 2 Type II, ISO 27001, SOX, and/or PCI DSS.
  • Strong working knowledge of SarbanesOxley compliance, including evidence preparation to AICPA or PCAOB standards.
  • A track record spanning both fast-paced Series B/C startups and a mature enterprise or Big 4 audit environment: you've built processes from scratch and you've seen what "good" looks like at scale.
  • Comfortably operates as a hands-on owner, not just a program overseer.

Preferred Qualifications
  • Experience with APIdriven / continuous GRC tooling (e.g., Vanta, Drata, or similar).
  • Exposure to cloud or GPU infrastructure security.
  • Relevant certifications (CISA, CISSP, CRISC, ISO 27001 Lead Auditor/Implementer).
  • Experience embedding compliance into CI/CD pipelines.


What We Offer
  • Stock Options
  • 100% paid Medical, Dental, and Vision insurance for Employees
  • Company Health Savings Account Contributions
  • 100% paid Short Term and Long Term Disability Insurance for Employees
  • Life and Voluntary Supplemental Insurance Options
  • Other Insurance Options, such as Pet & Legal Insurance
  • Various Supplementary Health Benefits, such as discounted Virtual Healthcare Appointments and Serious Illness Support
  • Flexible Spending Account
  • 401(k)
  • Employee Assistance Program
  • Flexible PTO
  • Paid Holidays
  • Parental Leave
  • Other In-Office Perks


Similar Jobs

More Jobs at TensorWave

More Information Technology Jobs

Find similar Governance, Risk, and Compliance Manager jobs: