Skip to content
SigmaSigmaSan Francisco, CA

Governance, Risk & Compliance Manager

Build and lead Sigma's Trust & Assurance function as Director, owning end-to-end GRC (SOC 2/ISO audits, policies, vendor risk), maturing it into enterprise risk management. Requires 8+ years GRC/risk experience including people management and personally running a SOC 2 program.

225k – 265k/yr
On-site8+ YOEOther

About the role

What You'll Do

Compliance & Controls

  • Own our SOC 2 (and/or ISO 27001) program — including PCI DSS and other relevant standards as applicable — covering control implementation, evidence collection, audit management, and remediation tracking
  • Maintain and evolve our internal policy library and employee attestation process
  • Monitor regulatory requirements relevant to our business (data privacy, industry-specific regulations) and work with the Legal team to assess impact and translate requirements into practical controls
  • Conduct internal audits and assessments to validate control effectiveness
  • Manage security awareness training programs enterprise-wide

Vendor & Third-Party Risk

  • Run vendor risk assessments and maintain a vendor risk inventory, including contract reviews and ongoing monitoring
  • Manage subprocessor tracking and disclosures
  • Partner with Legal on risk-related contract terms for vendors

Customer Trust

  • Own the security questionnaire response process (VSAs, SIGs, and custom questionnaires) and our customer-facing trust documentation
  • Maintain ready-to-use compliance artifacts and trust center content to support efficient deal cycles
  • Act as a trusted resource for Sales, Sales Engineering, and Solutions teams on security-related deal questions

Business Continuity & Incident Response

  • Maintain our business continuity/disaster recovery plan, including regular testing
  • Together with the Security team, own the incident response plan, including running periodic tabletop exercises
  • Lead post-incident reviews and track remediation

Growth into Enterprise Risk

  • Mature and maintain an enterprise risk register
  • Create risk treatment plans and track remediation activities across the organization
  • Run quarterly risk reviews
  • Scan for emerging risks (regulatory, market, operational) and flag material developments to the GC

Insurance

  • Manage the company's insurance program (cyber, E&O, D&O) including renewals and coverage review
  • Serve as primary point of contact with brokers and carriers

Team Leadership

  • Manage and develop a team of 3+ direct reports covering compliance analysts, vendor risk, and/or a GRC coordinator
  • Set goals, run performance reviews, and build career paths for direct reports

What We're Looking For

  • 8+ years of experience in GRC, compliance, audit, or risk management, ideally in a SaaS or technology company, including at least 2–3 years directly managing people
  • Has personally owned a SOC 2 or ISO 27001 program through at least one full audit cycle, including managing the auditor relationship end-to-end — not just executing tasks within someone else's program
  • Track record of building a function or program from the ground up, not just maintaining an established one
  • Experience with vendor/third-party risk assessment processes
  • Experience implementing risk management frameworks (COSO, ISO 31000, NIST RMF, or similar)
  • Ability to translate technical/security concepts into risk language for executives and business language for engineers, with excellent communication skills to influence stakeholders at all levels
  • Strong project management skills; comfortable juggling audits, questionnaires, and quarterly reporting simultaneously
  • Bonus: experience with GRC tooling (Vanta, Drata, Secureframe, ServiceNow GRC, Archer, LogicGate, or similar)
  • Bonus: hands-on experience with cloud environments (GCP, AWS, Azure) from a compliance and security perspective
  • Bonus: familiarity with security frameworks such as NIST CSF, CIS Controls, or OWASP
  • Bonus: relevant certifications (CISA, CRISC, CISSP, CGRC, CRM, CISM, CGEIT, or CIPP)

What Success Looks Like in Year One

  • SOC 2 Type II achieved/maintained with no material findings
  • Vendor risk assessment process in place and adopted before contract signing
  • Enterprise risk register matured and reviewed quarterly
  • Incident response plan tested via tabletop exercise
  • Insurance program reviewed for adequacy with no coverage gaps
  • Security questionnaire turnaround time meets sales cycle needs

Compensation

The base salary range for this position is $225k to $265k annually. This role is eligible for stock options, as well as a comprehensive benefits package.

Skills

GRCSOC 2ISO 27001vendor risk managementrisk management frameworkspci dssnistcisspcisaAWSGCPAzure

Similar roles

Thinking Machines Lab

Governance, Risk and Compliance Lead

Thinking Machines LabSan Francisco, CA

Lead end-to-end certifications (SOC 2, ISO 27001, FedRAMP) and day-to-day GRC processes for an AI company. Drive compliance roadmap, manage audits/risk, answer technical questions from engineering teams, and build automation/tools while growing the function.

225k – 350k/yrOn-site7+ YOEOther
Fluidstack

Design Management Lead

FluidstackAustin, TX

Lead design management for Fluidstack's multi-gigawatt AI data center builds. Set and enforce aggressive design schedules across multiple firms, run high-velocity review processes for constructability/cost/reference conformance, and close the design-field loop on RFIs to enable months-not-years delivery at 50GW+ scale.

222k – 307k/yrOn-site7+ YOEOther
Cohere

Lead, Global External Affairs

CohereWashington, DC

Lead Global External Affairs at Cohere by building and executing strategy for partnerships with think tanks, academics, NGOs, and coalitions to validate and amplify the company's responsible enterprise AI policy narrative. Requires 10+ years in external affairs/public policy with a deep global network and AI policy expertise.

220k – 330k/yrRemote10+ YOEOther
Fluidstack

Site Manager, Datacenter Operations

FluidstackBuffalo, NY +1

Lead 24/7 operations of critical data center infrastructure for AI compute sites, including electrical, mechanical, cooling, safety, hardware/network repair, incident response, and team leadership while sites are still under construction. Requires deep experience running contractual-availability facilities, technical infrastructure knowledge, and building high-performing teams.

234k – 340k/yrOn-site7+ YOEOther
OpenAI

Visual Storytelling & AI Innovation Lead, Office of the CFO

OpenAISan Francisco, CA

Hands-on IC partnering with the CFO's Chief of Staff to create executive presentations, board materials, and AI transformation stories that showcase Finance's AI adoption and support broader company messaging.

216k – 310k/yrHybridOther