Individual contributor role driving compliance, customer trust, vendor reviews, and security training workstreams to support audit readiness (FedRAMP, SOC 2, ISO) and earn stakeholder trust. Requires 5+ years GRC experience, strong knowledge of compliance frameworks, documentation, and cross-functional execution with minimal oversight.
Salary not listed
On-site5+ YOEOther
About the role
Compliance
Support audit readiness across core frameworks such as FedRAMP, SOC 2, and ISO 27001/27017/27018 by organizing evidence, maintaining documentation quality, and partnering with control owners to close gaps.
Manage compliance operations including evidence requests, policy and procedure updates, control narrative maintenance, and recurring review cycles.
Partner cross-functionally with Security Engineering, DevOps, IT, Legal, People, Procurement, and other stakeholders to gather inputs, validate implementation details, and produce audit-ready outputs.
Maintain strong execution against defined compliance SLAs, milestones, and recurring obligations, escalating risks early.
Translate technical, operational, and regulatory topics into clear written deliverables for internal and external audiences.
Support internal risk and governance processes, including security impact analyses, change-related compliance reviews, and other structured review workflows.
Contribute to the operation of the Public Sector Clearance Program, guiding cohorts, maintaining status, tracking issues, and communicating updates.
Customer Trust
Manage customer security questionnaires, trust inquiries, and diligence requests with minimal supervision, including researching answers, validating claims, gathering evidence, and producing accurate responses.
Maintain and improve customer-facing trust content across repositories, trust portals, knowledge resources, and standard response libraries.
Partner with Security Engineering, DevOps, Legal, GTM, Product, IT, and other stakeholders to collect inputs and ensure responses reflect current implementation.
Maintain execution against trust-related SLAs including turnaround time and response quality.
Identify gaps in trust materials and proactively drive updates.
Support trust enablement initiatives including trust center improvements, evidence library maintenance, and process improvements.
Use workflow data to identify recurring concerns and recommend changes to content, process, or tooling.
Vendor Reviews
Own end-to-end delivery of moderately complex vendor review workstreams including intake, scoping, stakeholder coordination, and completion with limited oversight.
Conduct security and compliance reviews of third parties by analyzing documentation such as security questionnaires, architecture details, attestations, policies, and contracts.
Evaluate vendor security posture against requirements for confidentiality, integrity, availability, privacy, access control, incident response, change management, and regulatory obligations.
Partner with Procurement, Legal, Security Engineering, IT, and business owners to validate use cases and ensure risks are understood.
Document identified gaps, assumptions, compensating controls, and recommended next steps.
Maintain execution against vendor review SLAs and recurring obligations, escalating higher-risk issues.
Security Training
Own end-to-end delivery of moderately complex security training program workstreams including planning, content coordination, rollout tracking, and continuous improvement with limited oversight.
Support the design, maintenance, and execution of security and compliance training, with focus on role-based, environment-specific, and regulatory obligations.
Maintain training content to align with policies, practices, and requirements such as FedRAMP, CJIS, export control.
Partner with GRCT, Legal, HR, Security, IT, and stakeholders to validate training materials.
Coordinate recurring training cycles, onboarding assignments, acknowledgements, re-certifications, and evidence collection for audit readiness.
Track status, identify gaps, and drive follow-through against program deadlines and obligations.
Requirements
5+ years of experience working as an individual contributor with a Governance, Risk, Compliance and Trust team.
Strong working knowledge of customer trust, compliance operations, risk, and the evidence and control narratives needed to support questionnaires, reviews, and audits.
Experience supporting FedRAMP, SOC 2, ISO 27001/27017/27018, or similar compliance frameworks.
Ability to independently drive moderately complex workstreams, navigate ambiguity, communicate clearly with stakeholders, and improve processes.
High attention to detail, disciplined execution, and commitment to quality, integrity, and cross-functional partnership.
Lead expansion of Ataraxis's clinical AI platform into new cancer types beyond breast cancer, from scientific groundwork to model launch. Requires scientific fluency in oncology, relentless drive, network-building with clinical leaders, and comfort with modern AI tools.
115k – 255k/yr
On-siteOther
Compliance Operations
PoeticSan Francisco, CA +1
Build and own the compliance program end-to-end for SOC 2, HIPAA, PCI DSS, ISO 27001 and other frameworks. Lead audits, build automations, partner with engineering on technical controls, manage vendor risk and customer security reviews as the first dedicated hire.
180k – 225k/yr
On-site5+ YOEOther
Process Modeling Engineer
Mariana MineralsSan Francisco, CA +1
Develop, validate, and optimize steady-state and dynamic process models for critical minerals refining using tools like ASPEN, SysCAD, and OLI. Translate lab/pilot data into scalable designs, supporting R&D, operations, and techno-economic analysis for next-generation mineral facilities.
100k – 160k/yr
On-siteOther
Executive Business Partner
LyftWashington, DC
Executive Business Partner supporting four Senior Directors on Lyft's Policy Leadership team. Manage complex calendars, project-manage initiatives, prepare materials, coordinate events, and build strong stakeholder relationships in a hybrid DC-based role.
66k – 83k/yr
Hybrid3+ YOEOther
AI Operations Manager, Emma
ClutchUnited States
Own the full post-sale journey for Clutch's AI collections agent Emma and future agents, from implementation and conversation design with credit unions to ongoing performance monitoring, optimization, and executive reviews. Build the function's playbooks, infrastructure, and eventually the team while feeding field insights back into product, sales, and pricing.