Назад
Company hidden
3 дня назад

Director of GRC

180 000 - 250 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
director
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Director of GRC (SOC 2/ISO 27001): Building the governance, risk, and compliance function for a liquid market for GPU offtake with an accent on SOC 2 ownership, first-time ISO 27001 certification, and enterprise risk management. Focus on designing controls and policies, managing auditors and GRC tooling, and hiring the team that will operate the program.

Location: San Francisco, CA, United States

Salary: $180K–$250K annually, plus equity

Company

Building a liquid market for GPU offtake to reduce infrastructure and customer risk in large-scale AI compute deployments.

What you will do

  • Build and lead the GRC function, including hiring, managing, and developing a small team.
  • Own the SOC 2 Type 2 program and lead the first ISO 27001 certification from readiness through audit and continuous monitoring.
  • Establish enterprise risk management, including risk assessments, a risk register, treatment plans, and leadership reporting.
  • Design and operationalize policies and processes for access reviews, business continuity, security awareness, vendor management, change management, and incident response.
  • Own Vanta and select or integrate additional GRC tooling.
  • Lead vendor security reviews and third-party risk assessments while collaborating with engineering on controls and remediation.

Requirements

  • Senior, high-impact GRC or security compliance experience in a startup environment.
  • Hands-on experience taking a company through its first ISO 27001 certification, from readiness through audit.
  • Experience owning or running a SOC 2 program.
  • Proven experience hiring, managing, and developing a team.
  • Ability to work cross-functionally with engineering on controls, tooling, and technical remediation.
  • Relevant certifications such as CISA, CISM, CISSP, CRISC, or ISO 27001 Lead Implementer/Auditor are valued.

Nice to have

  • Experience operating Vanta or a similar compliance automation platform.
  • Privacy program experience covering GDPR or CCPA.

Culture & Benefits

  • Visa and work permit sponsorship available.
  • Equity alongside competitive compensation.
  • 401(k) matching up to 4%.
  • Medical, dental, and vision insurance for employees and dependents, with premiums fully covered.
  • Unlimited paid time off, 10+ observed holidays, and paid leave for biological, adoptive, and foster parents.
  • Daily lunch and an office book budget.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →