Vercel: Frontend cloud platform for building and hosting web applications.
3+ YOE3+ years supporting audit lifecycle in cloud environments; manage ISO/SOC/HIPAA/PCI compliance, collaborate with engineering, strong project management and communication; familiarity with cloud and GRC tools.
Fluidstack: Provides high-performance cloud GPU infrastructure for AI development.
Experienced in operating compliance controls and audits across SOC 2, ISO 27001, NIST 800-53 or FedRAMP; owning policy sets, evidence collection, and audit readiness on GRC platforms.
Hayward HoldingsNYSE: HAYW: Manufacturer of residential and commercial swimming pool equipment.
3+ YOEBachelor's degree in Accounting, Information Systems, Cybersecurity or related; 3+ years SOX-focused GRC/audit experience; hands-on Varonis and SailPoint experience; strong ITGC/ICFR and audit evidence knowledge.
DoorDashNASDAQ: DASH: On-demand delivery platform connecting consumers with local merchants.
6+ YOE6+ years in security compliance/GRC with 3+ years implementing HIPAA programs in technology or regulated environments; strong HIPAA Security Rule knowledge, multi-framework experience, technical fluency with cloud/IAM/CI/CD, and stakeholder communication skills.
Headway: A healthtech accelerating access to mental healthcare
5+ YOE5+ years in GRC/compliance/security risk; knowledge of HITRUST/SOC 2/PCI-DSS/HIPAA; experience with GRC platforms; strong communication; ability to build repeatable processes; interest in AI-enabled security workflows; healthcare/healthtech HIPAA understanding a plus
Compyl: A provider of a platform to help companies understand and manage risk, security, and compliance.
5+ YOE5+ years GRC experience with audits, risk assessments, and policy/control rollouts; familiarity with SOC 2/ISO 27001/HIPAA/PCI-DSS/NIST; strong consultative communication and judgment.
Kokosing: Provides heavy civil, industrial, and marine construction services.
5+ YOE5+ years GRC/cybersecurity experience; knowledge of CMMC and NIST 800-171; strong risk management, policy and vendor risk experience; ability to influence stakeholders and support audits and data governance.
TrustmarkNASDAQ: TRMK: Provides retail and commercial banking, wealth, and insurance services.
1+ YOEBachelor's in related field, minimum 1 year IT GRC/IT audit experience, familiarity with GLBA/FFIEC/SOX/NIST CSF, strong writing and stakeholder coordination, GRC and ITSM tool experience preferred.
AuditBoard, Archer, ServiceNow, Microsoft Office 365, Microsoft Excel, Microsoft SharePoint, Alteryx, Tableau, Power BI, Python
RobloxNYSE: RBLX: Platform for creating and playing user-generated 3D digital experiences.
4+ YOE4+ years GRC experience, risk assessment and policy development, ability to work with engineers, knowledge of compliance frameworks and security controls.
Factor Analysis of Information Risk (FAIR), Roblox Studio
Clear Capital: AI-driven real estate valuation and property data solutions.
3+ YOE5+ years GRC/risk/compliance experience with Bachelor’s (or 3+ years with Master’s) or equivalent; deep knowledge of NIST, ISO, SOC 2, GLBA/CCPA/GDPR; relevant certifications (CISSP, CISM, CISA, CRISC, AIGP); familiarity with Vanta, Drata, OneTrust, cloud and DevOps; strong analytics and communication.
NIST CSF, NIST RMF, ISO 27001, ISO 27002, ISO 42001, SOC 2, GLBA, CCPA, GDPR, Vanta, Drata, OneTrust, DevOps, cloud computing
Frazier & Deeter: Accounting and advisory firm providing tax and audit services.
2+ YOE2+ years GRC, risk, compliance, audit, or vendor risk experience; familiarity with SOC reports, ISO 27001, security questionnaires; strong documentation, evidence management, and stakeholder coordination; preferred CRISC/CISA/CGRC/Security+ or ISO 27001 auditor/TPrisk credentials.
TurnCare: Develops patient mobility monitoring and therapeutic support systems.
Bachelor's degree, experience in security operations or GRC, familiarity with HIPAA, SOC2, HITRUST, vendor due diligence, policy development, and audit readiness.
OneTrust, Microsoft 365, Microsoft SharePoint, JIRA, Windows, macOS
Creative Information Technology: Provides IT solutions and software for government and healthcare sectors.
1+ YOE1 year information security/IT/GRC experience preferred; bachelor\u0002s degree in related field preferred; experience with ServiceNow and Office 365; knowledge of NIST, risk scoring, HIPAA; certifications earn points.
SalesforceNYSE: CRM: Sells cloud-based customer relationship management and business software solutions.
2+ YOE2–4 years GRC/compliance/audit or information security experience; working knowledge of at least two of SOC 2, HIPAA, ISO 27001, or GxP; proficiency with GRC/audit tools and Microsoft Office or Google Workspace; strong communication skills.
SOC 2, HIPAA, ISO 27001, GxP, Microsoft Office Suite, Google Workspace, Drata, Vanta, OneTrust, ServiceNow GRC
Ivo: AI-powered contract review and intelligence platform for legal teams.
3+ YOE3–5 years GRC/InfoSec/IT audit experience; hands-on SOC 2 Type II, ISO 27001, CSA STAR, ISO/IEC 42001; experience with Vanta, audits, evidence management, risk assessments, policy maintenance, and strong communication skills.
Sub-Zero Group: Manufactures premium luxury kitchen refrigeration and cooking appliances.
0+ YOEAssociate's or bachelor's degree in a related field and 0–3 years of GRC, risk, compliance, auditing, or related experience; strong analytical, organizational, and communication skills.
NIST CSF, NIST AI RMF, ISO 27001, ISO 31000, ISO 22301, CCPA/CPRA, GDPR, PCI DSS