CloudZero

GRC Manager

CloudZero$100K — $130K *
Enterprise Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of governance, risk, and/or compliance experience, preferably in SaaS or cloud tech.
  • Experience building or maturing a GRC program, with SOC 2 audit involvement.
  • Familiar with risk management frameworks like COSO, ISO 31000, or NIST RMF.
  • Understanding of GDPR, CCPA, and how they apply to operational practices.
  • Strong communication skills to simplify risk and compliance topics for diverse audiences.

Responsibilities

  • Design and implement a comprehensive GRC framework compatible with business growth.
  • Oversee audit and certification programs, coordinating with internal teams and auditors.
  • Develop and maintain security and privacy policies, ensuring practical application.
  • Conduct regular enterprise risk assessments and establish a living risk register.
  • Manage business continuity and disaster recovery plans with operational readiness testing.
  • Create and streamline third-party risk management processes, including vendor evaluations.
  • Facilitate the security questionnaire process and implement automation for efficiency.

Benefits

  • Hybrid work model with in-office presence 2-3 days a week.
  • Opportunity to own high-impact governance, risk, and compliance programs.
  • Collaboration with cross-functional teams including Legal, Engineering, and Sales.
  • Involvement in building AI Governance & Strategic Risk initiatives.
  • Respect for work-life balance through flexible working arrangements.
Full Job Description
About the Role

As the GRC Manager at CloudZero, you'll own and scale our governance, risk, and compliance programs across the organization.

Reporting to the Sr. Director of IT & Security within the Office of the CTO organization, you'll partner closely with Legal, Engineering, Product, Sales, and G&A to build a GRC function that protects CloudZero's interests, earns customer trust, and gives the business the confidence to move quickly.

This is a high-impact, highly cross-functional role. You'll be as comfortable presenting a risk register to leadership as you are helping a sales team close a deal with the right compliance documentation. This is a hybrid role with an expectation of in-office presence 2-3 days per week.

What You'll Do
Design and Operate the GRC Framework
  • Design and operate a comprehensive GRC framework spanning governance structures, enterprise risk management, and compliance programs that grows alongside CloudZero's business
  • Own audit and certification programs including SOC 2 and other relevant standards, coordinating across internal teams and third-party auditors to drive successful outcomes
  • Own the development, maintenance, and ongoing improvement of CloudZero's security and privacy policies and procedures, ensuring they're current, practical, and embedded into how teams actually operate
  • Lead regular enterprise risk assessments, maintain a living risk register, and create an environment where risk-informed decision-making happens at every level of the organization


Governance, Risk & Business Continuity
  • Serve as a key stakeholder in building CloudZero's AI Governance & Strategic Risk strategy
  • Take full ownership of business continuity and disaster recovery programs, including program design, documentation, regular testing cycles, and tabletop exercises - ensuring operational preparedness when it matters most
  • Build and manage third-party risk management processes, including vendor due diligence, contract reviews, and ongoing monitoring throughout the vendor lifecycle
  • Track regulatory developments alongside the Legal team, ensuring CloudZero meets its obligations under GDPR, CCPA, and other applicable requirements
  • Manage the company's security awareness training program and run internal audits to validate that controls are working as intended


Sales and Revenue Enablement
  • Own the security questionnaire and assessment process - including VSAs, SIGs, and custom customer requests - with a primary focus on building and scaling tooling and automation that makes high-quality responses fast and repeatable
  • Review and redline security and data privacy language in customer and prospect contracts, working closely with Legal to protect CloudZero's interests while keeping deals on track
  • Build and maintain a library of pre-approved security responses, compliance artifacts, and contract language so the team isn't starting from scratch on every deal
  • Actively identify and implement tooling to automate questionnaire responses and security review workflows, reducing manual effort and accelerating deal cycles without sacrificing quality
  • Maintain and continuously improve CloudZero's trust center, ensuring prospective customers have ready access to up-to-date security and compliance documentation
  • Partner with Sales Engineering and Solutions teams to address security and compliance requirements early in the sales cycle, removing friction before it becomes a blocker


What You Bring
Governance, Risk & Compliance
  • 5+ years of experience in governance, risk, and/or compliance roles, ideally within a SaaS or cloud technology company
  • Proven experience building or significantly maturing a GRC program, with direct, hands-on involvement in SOC 2 or similar certification audits
  • Working knowledge of established risk management frameworks such as COSO, ISO 31000, or NIST RMF
  • Solid understanding of GDPR, CCPA, and how data privacy obligations translate into practical controls and policies


Communication & Leadership
  • Strong communicator who can make risk and compliance topics accessible and actionable for technical teams, business partners, and senior leadership alike
  • Ability to drive initiatives from scoping through completion while keeping multiple workstreams moving in a fast-paced environment
  • A business-enabling mindset - you treat compliance as something that creates competitive advantage, not just something that checks boxes


Bonus If You Have...
  • Prior experience at a SaaS technology startup
  • Hands-on technical experience with GCP, AWS, or Azure from a security and compliance lens
  • Experience working with Vanta or Drata for continuous compliance monitoring and automation
  • Experience with security questionnaire automation tools such as Loopio, Iris, or similar solutions
  • Professional certifications such as CRISC, CISA, CISM, CISSP, or CIPP
  • Familiarity with security frameworks including NIST CSF, CIS Controls, or OWASP
  • Proven ability to partner cross-functionally across departments to drive compliance goals and outcomes
  • Curiosity and enthusiasm for leveraging AI tools (such as Claude, Claude Code, or similar) to work smarter, automate repetitive tasks, and continuously find new ways to drive efficiency across the GRC function


About CloudZero

CloudZero is a cloud cost intelligence platform that helps companies optimize their cloud spending. The company's platform provides real-time visibility into cloud costs and usage, allowing companies to identify areas where they can reduce costs and improve efficiency. CloudZero's software integrates with a variety of cloud providers, including Amazon Web Services, Microsoft Azure, and Google Cloud Platform. The company was founded in 2016 and is headquartered in Cambridge, Massachusetts.
Learn more about CloudZero
Size
50 employees
Industry
Net Income
-$3 million
Founded
2016
5 Year Trend
+80%
Revenue
$2 million

Similar Jobs

More Jobs at CloudZero

  • CloudZero
    GRC Manager
    $100K — $130K *
    Boston, MA 02115 (Suffolk County)
    Enterprise Technology
    In-Person
  • CloudZero
    GRC Manager
    $120K — $150K *
    San Francisco, CA 94112 (San Francisco County)
    Enterprise Technology
    In-Person
  • CloudZero
    Senior CloudOps Engineer
    $120K — $160K *
    San Francisco, CA 94112 (San Francisco County)
    Information Technology
    In-Person
  • CloudZero
    Senior CloudOps Engineer
    $120K — $150K *
    Boston, MA 02115 (Suffolk County)
    Information Technology
    In-Person

More Enterprise Technology Jobs

Find similar GRC Manager jobs: