Назад
Company hidden
2 дня назад

GRC Program Manager

120 000 - 180 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
GRC Program Manager (Security & Compliance): Running SOC 2 Type II, ISO 27001, ISO 42001, GDPR, and Microsoft SSPA compliance programs with an accent on audit ownership, evidence management, and vendor coordination. Focus on administering Drata, tracking remediation, managing auditor relationships, and coordinating security questionnaire, vendor review, bug bounty, training, and access-review processes.

Location: San Francisco, California; on-site

Salary: $120K–$180K annually

Company

hirify.global operates a documentation platform serving developers and companies at large scale.

What you will do

  • Own SOC 2 Type II, ISO 27001, ISO 42001, GDPR, and Microsoft SSPA programs end-to-end.
  • Manage audit calendars, evidence collection, remediation tracking, and auditor relationships.
  • Administer Drata, including monitors, evidence assignments, policies, and the trust center.
  • Manage the security and compliance vendor portfolio, including the vCISO engagement, renewals, and contracts.
  • Run security questionnaires, vendor security reviews, bug bounty coordination, training, and access-review cadences.
  • Maintain customer-facing compliance materials, including the trust center, DPAs, subprocessor list, and enterprise security requirements.

Requirements

  • 3+ years of experience in GRC, compliance program management, or security operations with direct audit ownership.
  • Hands-on administration experience with Drata, Vanta, or a similar compliance platform.
  • Experience owning vendor and auditor relationships.
  • Strong follow-through and meticulous remediation tracking.
  • Bias toward automation and delegating work to tests and vendors where appropriate.
  • Ability to coordinate technical work with Engineering directly and clearly.

Nice to have

  • ISO 42001 or AI governance experience.
  • GDPR operations experience, including DSARs, RoPA, or consent tooling.
  • Early-stage startup experience as a sole compliance owner.

Culture & Benefits

  • Competitive compensation and equity.
  • 20 days of paid time off annually.
  • 401(k) or RRSP.
  • $420 monthly wellness stipend.
  • Health, dental, and vision coverage, plus free transportation and meals at work.
  • Annual team offsite.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →