1 день назад
Governance, Risk, and Compliance Manager (AI Compliance)
190 000 - 275 000$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Governance, Risk, and Compliance Manager (AI Compliance) (Privacy/GRC): Operating and improving Decagon's privacy and enterprise compliance programs for conversational AI agents with an accent on ISO standards, GDPR, CCPA/CPRA, HIPAA, data governance, and customer security engagements. Focus on managing DSARs, DPAs, data inventories, transfer assessments, audit readiness, and translating complex security requirements for customers and cross-functional teams.
Location: San Francisco; in-office company
Salary: $190K–$275K base salary plus equity
Company
Conversational AI platform helping enterprise brands deliver customer experiences through AI agents across voice, chat, email, SMS, and other channels.
What you will do
- Operate and improve the privacy program against ISO 27701, ISO 27018, HIPAA, GDPR, CCPA/CPRA, and US state privacy laws.
- Manage data inventories, DSAR intake and fulfillment, DPAs, cross-border transfer mechanisms, retention schedules, subprocessors, breach notification readiness, and privacy training.
- Partner with legal on data residency, subprocessor flow-downs, data retention, DPIAs, and transfer impact assessments.
- Support customer security engagements, compliance audits, enterprise security communications, and security documentation.
- Coordinate cross-functional compliance initiatives and help close enterprise customer deals.
Requirements
- 5+ years of GRC experience in high-growth SaaS or technology companies with direct responsibility for privacy compliance programs.
- Experience contributing to SOC 2, ISO 27001, or similar enterprise compliance certifications.
- Experience with CCPA, GDPR, and emerging AI governance frameworks.
- Strong project management, written communication, and verbal communication skills.
- Working knowledge of technical security controls and the ability to collaborate with engineering teams.
- Ability to work in-office in San Francisco.
Nice to have
- Experience with AI/ML compliance frameworks and conversational AI security risks.
- Healthcare or financial services experience, including HIPAA or PCI requirements.
- Experience building GRC programs while scaling from startup to enterprise.
- Experience with Vanta, Drata, or SecureFrame.
- Understanding of Google Cloud Platform security and compliance features.
Culture & Benefits
- In-office environment focused on excellence and velocity.
- Medical, dental, vision, life insurance, and disability benefits.
- Retirement plan, parental leave, and fertility and family-building benefits.
- Monthly wellness and lifestyle stipend.
- Daily office lunches and snacks.
- Take-what-you-need vacation policy, subject to local requirements.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →