# GRC Lead

**Company:** [Juicebox](https://hotfix.jobs/companies/juicebox)
**Location:** San Francisco, CA
**Role:** Security Engineering
**Salary:** $150k – $250k/yr
**Experience:** 3+ years
**Skills:** GRC, SOC 2, ISO 27001, Ai Governance, Risk Management, Security Compliance, Security Questionnaires, Customer Trust, Security Audits, Security Policies, Endpoint Protection, Data Loss Prevention
**Posted:** 2026-09-04

> Build and own Juicebox’s governance, risk, compliance, and customer trust function, leading audits, enterprise security reviews, policies, and AI governance initiatives. Requires 3+ years in GRC or security compliance and experience with SOC 2, ISO 27001, and customer security questionnaires.

## Job Description

## Responsibilities
- Own and evolve Juicebox’s governance, risk, compliance, and customer trust programs.
- Lead SOC 2 Type 2 audits and drive adoption of additional frameworks such as ISO 27001 and emerging AI governance standards.
- Manage customer-facing security and compliance requests, including security questionnaires, trust documentation, and customer due diligence.
- Develop and maintain security, governance, and corporate policies, creating new policies as business needs evolve.
- Evaluate and improve security tooling and controls, partnering with Engineering and external security partners to identify gaps and strengthen the security posture.
- Advise Legal, Product, Engineering, Customer Success, and Go-to-Market teams on security and compliance matters.
- Position security and trust as competitive advantages supporting enterprise sales and customer adoption.

## Requirements
- 3+ years of experience in GRC, customer trust, security compliance, or a related field.
- Experience owning or supporting compliance frameworks such as SOC 2, ISO 27001, or similar programs.
- Experience responding to customer security questionnaires and supporting enterprise security reviews.
- Strong written communication skills and ability to translate technical concepts for business and customer audiences.
- Hands-on mindset and ability to independently drive projects from concept to execution.
- Experience working cross-functionally with Legal, Security, Engineering, and Go-to-Market teams.

## Nice to Have
- Experience building or scaling a GRC, compliance, or customer trust function at a startup.
- Familiarity with AI governance, AI risk management, or emerging AI compliance frameworks.
- Experience supporting international compliance initiatives, including UK or European requirements.
- Experience evaluating security tooling such as device management, endpoint protection, or data loss prevention solutions.

## Compensation and Benefits
- Top-of-market compensation with meaningful equity.
- 100% employer-paid medical coverage for employees; 90% employer contribution for dependents.
- Dental and vision coverage: 90% employer covered for employees and 85% for dependents.
- $2,000 annual wellness stipend.
- Daily meals provided.
- $300/month commuting stipend.

## Similar jobs

- [Security & Trust Lead](https://hotfix.jobs/jobs/2c665c46-9fc0-42d0-bc34-777fa50c8e6b) - Alex - San Francisco, CA - $150k – $180k/yr
- [Fraud Intelligence Lead](https://hotfix.jobs/jobs/35d29683-b36d-4c65-a143-3bc124a869ab) - Plaid - New York, NY - $149k – $233k/yr
- [Senior Security Software Engineer, Security Operations](https://hotfix.jobs/jobs/3afac001-b1e8-426c-8a65-56ae5e375464) - Pinterest - Remote - $156k – $320k/yr
- [Senior Security Engineer, Incident Response](https://hotfix.jobs/jobs/c68462e8-6fd9-48ef-99a9-0516fb5468d8) - Twilio - Remote - $142k – $208k/yr
- [Senior Security Engineer](https://hotfix.jobs/jobs/bf99bce1-bf10-4938-81d3-d24f8455171f) - Pindrop - Remote - $140k – $165k/yr

**Apply:** https://hotfix.jobs/jobs/1b5215fb-00e5-49a2-a7f2-6817a14b255f
**Canonical:** https://hotfix.jobs/jobs/1b5215fb-00e5-49a2-a7f2-6817a14b255f