Risk and Compliance Lead
Leads security GRC program, conducts enterprise risk assessments, manages compliance audits like SOC2/ISO 27001/TISAX, drives TPRM, and builds GRC infrastructure. Requires 6+ years in security compliance with hands-on audit and tooling experience.
About the job
Responsibilities
- Own and mature the security GRC program, including policy lifecycle management, risk register maintenance, and control framework alignment across the organization
- Conduct comprehensive enterprise and product-level risk assessments to identify, prioritize, and track risks against the company's risk appetite - translating findings into actionable remediation plans for stakeholders
- Lead, manage and support compliance efforts such as, but not limited to, SOC2, ISO 27001, ISO 9001, TISAX, and federal/defense requirements - owning audit readiness, evidence collection, and remediation tracking end to end
- Drive Third Party Risk Management (TPRM) program, including vendor assessments, contract security reviews, and ongoing monitoring of critical third parties
- Build and maintain the GRC program infrastructure - including risk tracking, compliance tooling, reporting cadences, and executive-level risk reporting
- Partner with Legal, Engineering, IT, and Operations to embed compliance and risk requirements into business processes, product development, and infrastructure decisions
- Develop and maintain security policies, standards, and procedures that are practical, enforceable, and aligned to regulatory and contractual obligations
- Support customer-facing security assurance activities including questionnaires, audits, and contractual security reviews
Requirements
- 6+ years of experience in security GRC, risk management, or compliance program ownership - with a track record of building or maturing programs, not just executing within them
- Hands on experience in running Enterprise Risk Assessments aligned with industry standard frameworks, risk register ownership, and translating technical risk into business-level impact
- Past experience of running Security Maturity Assessments against NIST 800-53, CCF, and more
- Deep hands-on experience managing SOC 2, ISO 27001, and TISAX audits - including scoping, control mapping, evidence coordination, and auditor management
- Experience running Third Party Risk Management programs including vendor tiering, security assessments, and ongoing monitoring
- Ability to interpret compliance frameworks in practical terms and drive cross-functional remediation without direct authority
- Strong communication skills - comfortable presenting risk posture and program status to executive leadership and board-level stakeholders
- Experience with GRC tooling such as Vanta, Drata, OneTrust, or similar platforms
Nice to Have
- Experience with Automotive security and safety compliance frameworks such as ISO 21434, ISO 26262
- Certifications such as CISSP
Compensation
- Base salary range: $160,000 - $190,000 USD annually
- Equity, comprehensive health/dental/vision/life/disability insurance, 401k with employer match, learning/wellness stipends, paid time off
Skills
GRC, SOC 2, ISO 27001, Tisax, Nist 800-53, Third Party Risk Management, Vanta, Drata, Onetrust, Risk Assessments, Iso 9001
Similar jobs
Security Engineering jobsProvides technical leadership for Security Operations by building cloud security platforms, automated controls, vulnerability-management workflows, and developer-facing security capabilities. Requires senior-level production systems experience, AWS security architecture, Terraform, and strong cross-functional technical ownership.
Leads application security initiatives across products, APIs, distributed systems, and AI-enabled applications. The role requires at least five years of security or software engineering experience, strong threat-modeling and architecture skills, and the ability to build security automation and drive remediation.
Leads the Product Security team responsible for security posture management, governed security rollouts, and software supply chain security across GitLab’s software factory. The role combines technical security leadership, organizational adoption, audit readiness, team building, and external thought leadership.
Build and own Juicebox’s governance, risk, compliance, and customer trust function, leading audits, enterprise security reviews, policies, and AI governance initiatives. Requires 3+ years in GRC or security compliance and experience with SOC 2, ISO 27001, and customer security questionnaires.
Build and operate scalable malware-analysis, threat-enrichment, and graph-intelligence systems that power security research and detection. The role requires 6+ years of security pipeline or threat-intelligence experience, strong Python or Go skills, and expertise in cloud and distributed systems.