Sierra Club

Security GRC Manager: Customer Trust Enablement

Sierra Club$130K — $180K *
Finance & Insurance
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years of progressive experience in compliance, security operations, or customer trust.
  • 3+ years of experience building or scaling customer-facing security programs.
  • Strong technical acumen with ability to convey complex concepts simply.
  • Hands-on experience with regulated industries including financial services, healthcare, and insurance.
  • Familiarity with regulatory frameworks like HIPAA, GDPR, and SOC 2.

Responsibilities

  • Own the Customer Trust roadmap, evolving it based on company growth and customer needs.
  • Drive automation strategy to improve response times and scalability of security questionnaires.
  • Develop systematic customer intelligence loops for regulatory drivers across industries and regions.
  • Define metrics and reporting frameworks to measure customer trust impacts on deals.
  • Establish operating rhythms and escalations for the Customer Trust team.
  • Create enablement programs to facilitate self-service for sales teams.
  • Lead security audits and meetings with highly regulated customers.

Benefits

  • Flexible (unlimited) paid time off
  • Comprehensive medical, dental, and vision coverage for employees and dependents
  • Life insurance and disability benefits
  • Retirement plan options based on country of employment
  • Parental leave and family-building benefits through Carrot
  • Free lunch and snacks available in the office
  • Discretionary benefit stipend for personal use
  • Unique perks like free alphorn lessons.
Full Job Description
We're looking for a seasoned Customer Trust Enablement professional to join the Security Foundations and GRC team. This is a role for someone with 10+ years experience and has done this work at depth before: you'll turn Sierra's underlying security and compliance posture into assets that accelerate revenue, run the trust-building relationships with our customers' security teams, and stand up the automation that lets us scale enterprise growth without scaling headcount one questionnaire at a time. A defining part of this role is winning the trust of our most regulated customers: banks, financial institutions, healthcare providers, insurers, and others operating under frameworks like HIPAA, HITRUST, GLBA, and state insurance and privacy regimes. As Sierra expands globally, that scope is increasingly international: you'll navigate cross-border data protection and AI regimes (GDPR, UK GDPR, the EU AI Act, and regional data-residency requirements) and work with customers and regulators across North America, EMEA, and APAC. To do this well, you'll develop a genuine understanding of what each industry and region is actually accountable for and why, and bring empathy to the obligations your customers carry into every conversation. You'll lead customer security meetings and audits, go toe-to-toe with their risk and security teams on the hard technical questions, and use automation and AI to handle that depth at scale rather than one painstaking review at a time. That same understanding flows inward: you'll weigh the tradeoffs between customer expectations, deal velocity, and what Sierra can credibly commit to, and translate the patterns you see across regulated buyers into the internal roadmaps that Product, Engineering, and Security GRC build against. This is a high-leverage, cross-functional role for someone who can set strategy and roll up their sleeves. What You'll Do Program Strategy & Execution (Roadmap Ownership) - Own the Customer Trust roadmap end-to-end, evolving priorities based on company growth, customer needs, and the competitive landscape. - Drive automation platform strategy: evaluate, implement, and scale AI questionnaire and trust platforms to dramatically improve response times and automation rates. - Build systematic customer intelligence loops that translate the regulatory drivers and recurring concerns across industries and regions healthcare, insurance, financial services, and global markets into prioritized inputs for the Product, Engineering, and Security GRC roadmaps. - Define metrics, SLAs, and escalation frameworks for the function, and report on cycle time, coverage, and deal impact to leadership. - Establish team operating rhythms, metrics reporting, and escalation frameworks. - Create GTM enablement programs that drive self-service adoption across sales teams, so AEs and Solutions can confidently field first-pass security questions. Customer & Revenue Enablement - Develop trust artifacts including security landing pages, whitepapers, industry-specific FAQs, data-flow and architecture overviews, and sales enablement materials. - Lead responses to enterprise security questionnaires and RFP security sections (SIG, CAIQ, custom frameworks), and serve as the named security point of contact in strategic sales cycles. - Lead live customer security meetings and customer audits with highly regulated customers: banks, financial institutions, and healthcare organizations navigating deep technical and regulatory diligence. - Support complex security contract reviews requiring security expertise, and escalate appropriately. AI, Automation & Scale - Identify broken or manual processes, design scalable solutions, and implement the right tools to maximize efficiency without sacrificing quality. - Apply automation and AI including AI questionnaire and trust platforms to absorb the volume and depth of regulated-customer diligence, turning days of manual review into minutes. - Build and maintain a security knowledge base and questionnaire-automation workflows so common questions are answered once and reused across the sales org. - Curate Sierra's Trust Center so customers can self-serve answers under NDA. Who You'll Work With This role sits in the Security function. You'll work day-to-day with: - Sales, GTM and Agent Development integrating Customer Trust workflows into the CRM, streamlining due-diligence processes, and keeping security from becoming a bottleneck in the deal cycle. - Security developing trust artifacts, security content, and scalable response frameworks grounded in Sierra's actual security posture. - Legal collaborating on DPAs, BAAs, security exhibits, and the security and data-protection terms in customer agreements. - Product feeding customer security and compliance signals into roadmap prioritization. - Executive audiences and customer/prospects representing Sierra's security posture in strategic customer engagements and Field CISO activities, leading audits and security meetings with the risk teams at regulated banks and financial institutions, and translating technical security concepts for business stakeholders. What You'll Bring You may be a good fit if you: - Have 10+ years of progressive experience in compliance, security operations, or customer trust, with 3+ years building or scaling customer-facing security programs from early stage through high growth and seniority and judgment. - Have a proven track record managing enterprise security relationships at scale: you've personally led customer audits and security meetings, built trust with Fortune 500 CISOs, and know how to balance rigor with deal velocity. - Have hands-on experience selling into or supporting highly regulated buyers financial services, banks, healthcare, or insurance and can navigate the depth of their security and regulatory diligence with credibility. - Understand the regulatory landscape across customer industries and geographies well enough to know what each is genuinely accountable for, and bring empathy to those obligations, balancing customer needs, deal velocity, and what Sierra can credibly commit to, and turning that judgment into clear internal priorities. - Have experience supporting global customers and navigating international data protection and AI regimes (e.g., GDPR, UK GDPR, EU AI Act, cross-border transfer and data-residency requirements). - Have strong technical acumen you can explain complex security architectures, compliance frameworks (NIST 800-53, SOC 2, ISO 27001, PCI DSS, HIPAA), and multi-cloud implementations (AWS, GCP) in customer-friendly language. - Have experience implementing trust automation platforms or building scaled questionnaire-management processes. - Can identify broken processes, design scalable solutions, and implement the right tools to maximize efficiency without sacrificing quality. - Are comfortable presenting to C-level executives and translating technical security concepts for business audiences. - Have a proven track record of cross-functional influence without direct authority - you build partnerships that get things done. - Have experience partnering with Revenue Operations, Deal Desk, or Sales teams to integrate security into go-to-market motions. Strong candidates may also: - Have worked in AI/ML or high-growth SaaS companies navigating rapid compliance expansion. - Bring Field CISO or Customer Success Security experience supporting enterprise deals. - Have familiarity with emerging AI standards (ISO 42001, NIST AI RMF). - Possess relevant certifications (CISA, CRISC, CISM, CISSP, ISO 27001 Lead Auditor). - Have experience with AI safety or AI agent / model security considerations. What we offer We want our benefits to reflect our values and offer the following to full-time employees: - Flexible (unlimited) paid time off - Medical, dental, and vision benefits for you and your family - Life insurance and disability benefits - Retirement plan dependent on country of employment - Parental leave - Fertility and family building benefits through Carrot - Lunch, as well as delicious snacks and coffee to keep you energized - Discretionary benefit stipend giving people the ability to spend where it matters most - Free alphorn lessons

About Sierra Club

The Sierra Club is a nonprofit organization that promotes environmental conservation. It was founded in 1892 by John Muir and is one of the oldest and largest environmental organizations in the United States. The organization has over 3.8 million members and supporters and is dedicated to protecting the planet's natural resources and wildlife. The Sierra Club engages in a variety of activities, including lobbying for environmental legislation, organizing outdoor activities, and publishing a magazine. The organization is headquartered in Oakland, California.
Learn more about Sierra Club
Size
800 employees
Industry
Founded
1892

Similar Jobs

More Jobs at Sierra Club

More Finance & Insurance Jobs

Find similar Security GRC Manager: Customer Trust Enablement jobs: