Brex: Corporate cards and spend management software for businesses.
5+ YOE5+ years in GRC or Security Engineering; strong automation; security frameworks SOC 2, PCI DSS, ISO 27001; Python and API integrations; cross-functional collaboration; cloud native; Terraform.
Phylo: An applied research lab building AI agents for biomedical discovery.
5+ YOE5+ years in security GRC or adjacent role; experience leading SOC 2, ISO 27001, HIPAA, FedRAMP or similar; cloud and application security knowledge; audit and enterprise customer review experience; strong cross-functional communication.
AdobeNASDAQ: ADBE: Provides software for digital media creation and marketing analytics
8+ YOE8–12+ years in strategy, business operations, risk management, or related fields; proven experience building metrics and executive reporting; able to engage and influence executives.
San Francisco or New York City or London or Sydney
$190k-$215k/yrOnsiteFull Time
Sigma Computing: Cloud-native analytics platform featuring a spreadsheet-style interface.
4+ YOE4+ years GRC experience in SaaS/tech, proven track record building GRC programs and leading SOC 2/ISO 27001/HIPAA audits, experience with ERM frameworks (COSO, ISO 31000, NIST RMF), data privacy (GDPR/CCPA), policy and control development, strong communication.
WindBorne Systems: Operates smart weather balloons to provide global atmospheric data.
3+ YOE3+ years in compliance audits and US government compliance; experience with CMMC, FedRAMP, NIST frameworks; security, cloud, and GRC tooling expertise; ability to obtain security clearance.
Drata, Vanta, eMASS, Tenable Security Center, Burp, SIEM, AWS, Azure
Austin or Chicago or New York City or Salt Lake City or San Francisco
$117k-$185k/yrOnsiteFull Time
Gong: AI platform analyzing customer interactions to improve sales performance.
7+ YOE7+ years in third‑party/vendor risk management or GRC; strong knowledge of security/privacy frameworks, vendor assessments, and TPRM tooling; excellent communication and risk translation skills.
Risk Consulting - Risk Technology - GRC/IRM Platforms - Manager (New York, NY, US, 10001-8604)
New York or Atlanta or Boston or Chicago or Cleveland or Dallas or Detroit or Pittsburgh or Hoboken or Houston or Los Angeles or McLean or Miami or Minneapolis or North Carolina or Philadelphia or Portland or San Francisco or Seattle or Tampa
$150k-$260k/yrHybridFull Time
EY: Global firm providing audit, tax, and professional consulting services.
4+ YOEBachelor's + 5 yrs (or Master's + 4 yrs) implementing ServiceNow IRM/TPRM/BCM; ServiceNow CSA and GRC certifications; experience leading implementations, integrations, and client engagements; Microsoft Office proficiency.
ServiceNow IRM, Archer, AuditBoard, OneTrust, Spotfire, PowerBI, Tableau, Microsoft PowerPoint, Microsoft Word, Microsoft Excel, Vision, Integration Hub, REST, SOAP
Thinking Machines: Building AI systems to extend human will and judgment.
7+ YOE7+ years GRC experience in technology and cybersecurity; led SOC 2/ISO 27001/FedRAMP from scoping through audit close; hands-on evidence collection, control documentation, and recurring compliance processes; strong technical fluency.
Third Party Risk Management and Customer Trust Lead
Foster City, California, United States
$210k-$270k/yrHybridFull Time
Replit: Cloud-based platform for building and hosting software applications.
8+ YOE8+ years in third-party/vendor risk or GRC, ability to assess vendor risk from SOC 2/pen tests/architecture, contract review/redlining, knowledge of GDPR/CCPA, cross-functional collaboration, and building scalable vendor review processes.
SOC 2, GDPR, CCPA, NIST AI RMF, ISO 42001, EU AI Act
AmazonNASDAQ: AMZN: Global online retail and cloud computing technology provider.
7+ YOE7+ years finance/accounting experience with process improvement and automation; 5+ years financial analysis and cross-functional leadership; bachelor’s in accounting or related field (or equivalent); strong knowledge of assurance standards and sustainability reporting.
Perplexity: AI-powered search engine providing conversational answers with citations.
6+ YOE6+ years leading audit and compliance engagements; experience with SOC2/ISO27001/HIPAA, GDPR/CCPA/CPRA; building GRC tooling and automation; strong communication and cross-functional collaboration skills.
Governance, Risk Management and Compliance, Senior Director
San Jose, California, United States
$225k-$250k/yrOnsiteFull Time
Astera LabsNASDAQ: ALAB: Designs connectivity solutions for cloud and AI infrastructure.
10+ YOE5+ Mgmt10+ years in GRC/internal audit with 5+ years leading teams; experience with SOX, ERM, SOC 2/ISO 27001/NIST, third-party risk, and executive/Board reporting.
AKASA: Develops AI-powered automation software for healthcare revenue cycle management.
8+ YOE2+ MgmtRequires 8+ years in security compliance, GRC, or risk management, including 2+ years leading a team or function; expertise in HITRUST, SOC 2, HIPAA, AI governance, and compliance automation.
NIST AI RMF, Okta, Google Workspace, Kandji, Iru, SentinelOne, Nightfall, AWS, Vanta, Drata, Hyperproof, ChatGPT, Claude, Python, Zapier, Tray.io
Chicago or Tampa or Charlotte or Atlanta or Austin or Washington or Dallas or Los Angeles or Boston or Florham Park or New York or San Francisco or San Jose or Philadelphia or Houston
$99k-$232k/yrOnsiteFull Time
PwC: Providing audit, tax, and management consulting services to businesses.
4+ YOEBachelor's degree, 4+ years delivering SAP compliance, security, and governance solutions; proficiency with SAP GRC and SAP BW/4HANA; experience leading teams, implementing compliance programs, and audit processes.
SAP, SAP Governance, Risk and Compliance (GRC), SAP BW/4HANA
Zapier: Connects web applications to automate repetitive workflows without coding.
Executive security leader to set strategy, lead App/Infra/Detection & Response/GRC teams, run risk and incident programs, partner with executives and Product/Engineering, and drive enterprise trust for an AI-native SaaS platform.