GRC Lead
Build and own Juicebox’s governance, risk, compliance, and customer trust function, leading audits, enterprise security reviews, policies, and AI governance initiatives. Requires 3+ years in GRC or security compliance and experience with SOC 2, ISO 27001, and customer security questionnaires.
About the job
Responsibilities
- Own and evolve Juicebox’s governance, risk, compliance, and customer trust programs.
- Lead SOC 2 Type 2 audits and drive adoption of additional frameworks such as ISO 27001 and emerging AI governance standards.
- Manage customer-facing security and compliance requests, including security questionnaires, trust documentation, and customer due diligence.
- Develop and maintain security, governance, and corporate policies, creating new policies as business needs evolve.
- Evaluate and improve security tooling and controls, partnering with Engineering and external security partners to identify gaps and strengthen the security posture.
- Advise Legal, Product, Engineering, Customer Success, and Go-to-Market teams on security and compliance matters.
- Position security and trust as competitive advantages supporting enterprise sales and customer adoption.
Requirements
- 3+ years of experience in GRC, customer trust, security compliance, or a related field.
- Experience owning or supporting compliance frameworks such as SOC 2, ISO 27001, or similar programs.
- Experience responding to customer security questionnaires and supporting enterprise security reviews.
- Strong written communication skills and ability to translate technical concepts for business and customer audiences.
- Hands-on mindset and ability to independently drive projects from concept to execution.
- Experience working cross-functionally with Legal, Security, Engineering, and Go-to-Market teams.
Nice to Have
- Experience building or scaling a GRC, compliance, or customer trust function at a startup.
- Familiarity with AI governance, AI risk management, or emerging AI compliance frameworks.
- Experience supporting international compliance initiatives, including UK or European requirements.
- Experience evaluating security tooling such as device management, endpoint protection, or data loss prevention solutions.
Compensation and Benefits
- Top-of-market compensation with meaningful equity.
- 100% employer-paid medical coverage for employees; 90% employer contribution for dependents.
- Dental and vision coverage: 90% employer covered for employees and 85% for dependents.
- $2,000 annual wellness stipend.
- Daily meals provided.
- $300/month commuting stipend.
Skills
GRC, SOC 2, ISO 27001, Ai Governance, Risk Management, Security Compliance, Security Questionnaires, Customer Trust, Security Audits, Security Policies, Endpoint Protection, Data Loss Prevention
Similar jobs
Security Engineering jobsOwn Alex’s information security, compliance, AI governance, and enterprise trust program as its first dedicated Security & Trust hire. The role combines security reviews and customer-facing assurance with audits, regulatory readiness, risk management, and technical control development.
Leads a high-leverage fraud intelligence team while personally investigating complex attacks across identities, devices, accounts, and payments. The role combines people leadership, incident response, threat intelligence, and partnerships with product and ML teams to improve fraud detection and prevention.
Provides technical leadership for Security Operations by building cloud security platforms, automated controls, vulnerability-management workflows, and developer-facing security capabilities. Requires senior-level production systems experience, AWS security architecture, Terraform, and strong cross-functional technical ownership.
Lead technical response to security incidents across Twilio's global cloud infrastructure, including triage, containment, remediation, documentation, and post-incident improvements. Requires 5+ years incident response experience, expertise with SIEM/SOAR, cloud platforms, and AI-driven security tools.
Senior Security Engineer on the Red Team performing offensive security, adversarial testing, and red team operations against GenAI/LLM systems, deepfake defenses, cloud infrastructure, and SaaS products. Requires 3+ years of hands-on pen testing/red team experience plus demonstrable GenAI attack experience.