Skip to content
DecagonDecagon

Governance, Risk, and Compliance Manager

Manages Decagon’s governance, risk, and compliance program, including enterprise certifications, audit evidence, vendor risk, customer security assessments, and RFP responses. Requires 3–5 years of GRC experience, strong communication and project management skills, and familiarity with technical security controls and privacy regulations.

About the job

Responsibilities

  • Drive compliance certifications including SOC 2 Type II, ISO 27001, PCI DSS, HIPAA, and CCPA.
  • Automate or execute compliance evidence collection and ensure controls are documented and audit-ready.
  • Maintain and improve security documentation, including policies, procedures, and customer-facing security collateral.
  • Support customer security assessments by preparing review materials and addressing technical inquiries.
  • Manage security and compliance topics in RFPs end-to-end, coordinating responses across engineering, product, and legal teams.
  • Coordinate contractors and vendors to maintain response quality and meet timelines during peak sales periods.
  • Build and optimize repeatable processes to scale GRC operations.
  • Partner with sales engineering, Sales, and Customer Success to address customer security requirements and concerns.
  • Collaborate with Security, Engineering, and Product teams to translate compliance requirements into technical controls.
  • Establish vendor risk management programs to assess and monitor third-party security risks.

Requirements

  • 3–5 years of GRC experience in high-growth SaaS or technology companies, with direct responsibility for compliance programs.
  • Experience contributing to SOC 2, ISO 27001, or similar enterprise compliance certifications.
  • Experience with data privacy regulations including CCPA and GDPR, as well as emerging AI governance frameworks.
  • Strong project management skills and ability to coordinate cross-functional teams under tight deadlines.
  • Excellent written and verbal communication skills.
  • Working knowledge of technical security controls and ability to collaborate with engineering teams.

Nice-to-haves

  • Experience with AI/ML compliance frameworks and risks in conversational AI systems.
  • Healthcare or financial services experience, including HIPAA or PCI requirements.
  • Experience building GRC programs as a company scales from startup to enterprise.
  • Experience with Vanta, Drata, or SecureFrame.
  • Understanding of Google Cloud compliance and security features.

Compensation and Benefits

  • Compensation: $190K–$275K plus equity.
  • Medical, dental, and vision benefits for employees and families.
  • Life insurance and disability benefits.
  • Retirement plan.
  • Parental leave.
  • Fertility and family-building benefits.
  • Monthly wellness and lifestyle stipend.
  • Daily office lunches and snacks.
  • Take-what-you-need vacation policy.

Skills

SOC 2, ISO 27001, Pci Dss, HIPAA, CCPA, GDPR, Ai Governance, GRC, Vendor Risk Management, Vanta, Drata, Secureframe, GCP, Technical Security Controls, Rfp Management

Decagon

Decagon

San Francisco, CA

Governance, Risk, and Compliance Manager - Privacy
$190k+/yrOn-site5+ YOESecurity Engineering

Own and operate Decagon’s privacy and GRC programs, including regulatory compliance, data governance, customer security engagements, audits, and cross-functional privacy initiatives. The role requires 5+ years of GRC experience, strong communication and project management skills, and familiarity with enterprise security controls.

Anthropic

Anthropic

San Francisco, CA
Safeguards Policy Analyst, Cyber Harms
$190k+/yrHybridSecurity Engineering

The analyst develops and evaluates cyber product policies, enforcement guidance, controlled-access frameworks, and launch-review inputs for AI systems. The role requires strong policy writing, cybersecurity or platform-enforcement familiarity, technical security literacy, and cross-functional communication.

1Password

1Password

United States
Manager, Security Incident Response
$192k+/yrRemote5+ YOESecurity Engineering

Leads and develops a security incident response team while driving automation, AI-assisted workflows, operational maturity, and response strategy. The role requires 5+ years of incident response experience, people leadership, technical depth, and calm management of high-severity incidents.

Huntress

Huntress

United States

QMS Manager
$185k+/yrRemote5+ YOESecurity Engineering

Build and lead a Security Quality Management System for agentic and human-led SOC investigations, establishing quality standards, sampling, validation, reporting, and corrective actions. The role requires 5+ years in quality, governance, operational excellence, or controls, plus security operations and people-management experience.

Glean

Glean

United States

Platform Security Engineer
$185k+/yrRemote5+ YOESecurity Engineering

Develop and maintain secure platform software spanning authentication, authorization, communications, data access, and automated security testing. The role requires 5+ years of security-focused software development experience, strong coding skills, and expertise in cloud and container security.