Governance, Risk, and Compliance Manager - Privacy
Own and operate Decagon’s privacy and GRC programs, including regulatory compliance, data governance, customer security engagements, audits, and cross-functional privacy initiatives. The role requires 5+ years of GRC experience, strong communication and project management skills, and familiarity with enterprise security controls.
About the job
Responsibilities
- Improve and maintain the privacy program against ISO 27701, ISO 27018, HIPAA, GDPR, CCPA/CPRA, and other U.S. state privacy laws.
- Own privacy program operations, including data inventory, DSAR intake and fulfillment, DPAs, cross-border transfer mechanisms, data retention schedules, subprocessor onboarding and public subprocessor listings, breach notification readiness, and privacy training.
- Partner with Legal on data residency, subprocessor flow-downs, retention by data class, DPIAs, and transfer impact assessments.
- Drive day-to-day privacy and compliance decisions.
Requirements
- 5+ years of GRC experience in high-growth SaaS or technology companies, with direct responsibility for privacy compliance programs.
- Experience contributing to SOC 2, ISO 27001, or similar enterprise compliance certifications.
- Experience with CCPA, GDPR, and emerging AI governance frameworks.
- Strong project management skills and ability to coordinate cross-functional teams under tight deadlines.
- Excellent written and verbal communication skills.
- Working knowledge of technical security controls and ability to collaborate with engineering teams.
Nice-to-haves
- Experience with AI/ML compliance frameworks and risks in conversational AI systems.
- Healthcare or financial services experience, including HIPAA or PCI requirements.
- Experience building GRC programs as companies scale from startup to enterprise.
- Experience with Vanta, Drata, or SecureFrame.
- Understanding of Google Cloud security and compliance features.
Compensation & Benefits
- $190K–$275K plus equity.
- Medical, dental, and vision benefits for employees and families.
- Life insurance and disability benefits.
- Retirement plan.
- Parental leave.
- Fertility and family-building benefits.
- Monthly wellness and lifestyle stipend.
- Daily office lunches and snacks.
- Flexible vacation policy.
Skills
Iso 27701, Iso 27018, HIPAA, GDPR, Ccpa/Cpra, SOC 2, ISO 27001, Ai Governance, Data Privacy, Dpias, Vanta, Drata, Secureframe, GCP
Similar jobs
Security Engineering jobsThe analyst develops and evaluates cyber product policies, enforcement guidance, controlled-access frameworks, and launch-review inputs for AI systems. The role requires strong policy writing, cybersecurity or platform-enforcement familiarity, technical security literacy, and cross-functional communication.
Manages Decagon’s governance, risk, and compliance program, including enterprise certifications, audit evidence, vendor risk, customer security assessments, and RFP responses. Requires 3–5 years of GRC experience, strong communication and project management skills, and familiarity with technical security controls and privacy regulations.
Leads and develops a security incident response team while driving automation, AI-assisted workflows, operational maturity, and response strategy. The role requires 5+ years of incident response experience, people leadership, technical depth, and calm management of high-severity incidents.
Build and lead a Security Quality Management System for agentic and human-led SOC investigations, establishing quality standards, sampling, validation, reporting, and corrective actions. The role requires 5+ years in quality, governance, operational excellence, or controls, plus security operations and people-management experience.
Develop and maintain secure platform software spanning authentication, authorization, communications, data access, and automated security testing. The role requires 5+ years of security-focused software development experience, strong coding skills, and expertise in cloud and container security.