# Governance, Risk & Compliance Manager

**Company:** [Sigma](https://hotfix.jobs/companies/sigma)
**Location:** San Francisco, CA
**Role:** Other
**Salary:** $225k – $265k/yr
**Experience:** 8+ years
**Skills:** GRC, SOC 2, ISO 27001, vendor risk management, risk management frameworks, pci dss, nist, cissp, cisa, AWS, GCP, Azure
**Posted:** 2026-07-28

> Build and lead Sigma's Trust & Assurance function as Director, owning end-to-end GRC (SOC 2/ISO audits, policies, vendor risk), maturing it into enterprise risk management. Requires 8+ years GRC/risk experience including people management and personally running a SOC 2 program.

## Job Description

## What You'll Do

### Compliance & Controls
- Own our SOC 2 (and/or ISO 27001) program — including PCI DSS and other relevant standards as applicable — covering control implementation, evidence collection, audit management, and remediation tracking
- Maintain and evolve our internal policy library and employee attestation process
- Monitor regulatory requirements relevant to our business (data privacy, industry-specific regulations) and work with the Legal team to assess impact and translate requirements into practical controls
- Conduct internal audits and assessments to validate control effectiveness
- Manage security awareness training programs enterprise-wide

### Vendor & Third-Party Risk
- Run vendor risk assessments and maintain a vendor risk inventory, including contract reviews and ongoing monitoring
- Manage subprocessor tracking and disclosures
- Partner with Legal on risk-related contract terms for vendors

### Customer Trust
- Own the security questionnaire response process (VSAs, SIGs, and custom questionnaires) and our customer-facing trust documentation
- Maintain ready-to-use compliance artifacts and trust center content to support efficient deal cycles
- Act as a trusted resource for Sales, Sales Engineering, and Solutions teams on security-related deal questions

### Business Continuity & Incident Response
- Maintain our business continuity/disaster recovery plan, including regular testing
- Together with the Security team, own the incident response plan, including running periodic tabletop exercises
- Lead post-incident reviews and track remediation

### Growth into Enterprise Risk
- Mature and maintain an enterprise risk register
- Create risk treatment plans and track remediation activities across the organization
- Run quarterly risk reviews
- Scan for emerging risks (regulatory, market, operational) and flag material developments to the GC

### Insurance
- Manage the company's insurance program (cyber, E&O, D&O) including renewals and coverage review
- Serve as primary point of contact with brokers and carriers

### Team Leadership
- Manage and develop a team of 3+ direct reports covering compliance analysts, vendor risk, and/or a GRC coordinator
- Set goals, run performance reviews, and build career paths for direct reports

## What We're Looking For
- 8+ years of experience in GRC, compliance, audit, or risk management, ideally in a SaaS or technology company, including at least 2–3 years directly managing people
- Has personally owned a SOC 2 or ISO 27001 program through at least one full audit cycle, including managing the auditor relationship end-to-end — not just executing tasks within someone else's program
- Track record of building a function or program from the ground up, not just maintaining an established one
- Experience with vendor/third-party risk assessment processes
- Experience implementing risk management frameworks (COSO, ISO 31000, NIST RMF, or similar)
- Ability to translate technical/security concepts into risk language for executives and business language for engineers, with excellent communication skills to influence stakeholders at all levels
- Strong project management skills; comfortable juggling audits, questionnaires, and quarterly reporting simultaneously
- Bonus: experience with GRC tooling (Vanta, Drata, Secureframe, ServiceNow GRC, Archer, LogicGate, or similar)
- Bonus: hands-on experience with cloud environments (GCP, AWS, Azure) from a compliance and security perspective
- Bonus: familiarity with security frameworks such as NIST CSF, CIS Controls, or OWASP
- Bonus: relevant certifications (CISA, CRISC, CISSP, CGRC, CRM, CISM, CGEIT, or CIPP)

## What Success Looks Like in Year One
- SOC 2 Type II achieved/maintained with no material findings
- Vendor risk assessment process in place and adopted before contract signing
- Enterprise risk register matured and reviewed quarterly
- Incident response plan tested via tabletop exercise
- Insurance program reviewed for adequacy with no coverage gaps
- Security questionnaire turnaround time meets sales cycle needs

## Compensation
The base salary range for this position is $225k to $265k annually. This role is eligible for stock options, as well as a comprehensive benefits package.

## Similar roles

- [Governance, Risk and Compliance Lead](https://hotfix.jobs/jobs/ad85eb1f-c888-4153-a518-692f11a24f0d) - Thinking Machines Lab - San Francisco, CA - $225k – $350k/yr
- [Design Management Lead](https://hotfix.jobs/jobs/5decbd85-9f45-4904-9d0c-e6471a01979b) - Fluidstack - Austin, TX - $222k – $307k/yr
- [Lead, Global External Affairs](https://hotfix.jobs/jobs/ac844653-08a5-485e-a75f-86fa5cf45878) - Cohere - Remote - $220k – $330k/yr
- [Site Manager, Datacenter Operations](https://hotfix.jobs/jobs/459ea64b-9c03-4f29-9f95-d6e770dc3378) - Fluidstack - Buffalo, NY - $234k – $340k/yr
- [Visual Storytelling & AI Innovation Lead, Office of the CFO](https://hotfix.jobs/jobs/6d70c88d-579a-42f4-8b26-7efc13dd7a7f) - OpenAI - San Francisco, CA - $216k – $310k/yr

**Apply:** https://hotfix.jobs/jobs/5e004b31-c093-4227-a691-62994ef91b0d
**Canonical:** https://hotfix.jobs/jobs/5e004b31-c093-4227-a691-62994ef91b0d