97 grc jobs at 65 companies in Napa, CA

2mo
Save
Mark Applied
Hide
GRC Engineer
Palo Alto or San Francisco
$130k-$170k/yr OnsiteAll Commitments Available
Zania
Zania: Automates enterprise risk and compliance using agentic AI teammates.
3+ YOE3–8 years in GRC, information security, risk management, audit, or enterprise tech customer success; strong frameworks knowledge (SOC 2, ISO 27001, NIST CSF, FedRAMP, HIPAA, PCI-DSS); proven stakeholder management and communication; SaaS/technical product experience.
GRC frameworks, SOC 2, ISO 27001, NIST CSF, FedRAMP, HIPAA, PCI-DSS
1mo
Save
Mark Applied
Hide
Senior Security GRC Lead
Austin or Chicago or New York City or Salt Lake City or San Francisco
$121k-$185k/yr OnsiteFull Time
Gong
Gong: AI platform analyzing customer interactions to improve sales performance.
7+ YOE7+ years building/scaling GRC or InfoSec programs, deep expertise with SOC 2/ISO/NIST frameworks, hands-on GRC tooling, policy and risk assessment experience, bachelor’s preferred, relevant certifications strongly preferred.
SOC 2, SOC 2 Type II, ISO 27001, ISO 27017, ISO 27701, ISO 27018, HIPAA, PCI, NIST CSF, GDPR, CCPA, GRC platform
4w
Save
Mark Applied
Hide
Senior GRC Engineer
San Francisco, California, United States
$180k-$200k/yr OnsiteFull Time
Postman
Postman: Platform for building, testing, and managing software APIs.
6+ YOE6+ years GRC experience in tech, SOC2/ISO27001/HIPAA/GDPR/CCPA/FedRAMP knowledge, proficiency in Python or JavaScript, experience integrating GRC tooling, and strong communication.
Python, JavaScript
1w
Save
Mark Applied
Hide
GRC Analyst
San Francisco, California, United States
$95k-$150k/yr HybridFull Time
Zip
Zip: AI-powered intake-to-procure platform for enterprise spend management
2+ YOEBachelor's degree,2+ years GRC or security risk/audit experience,knowledge of SOC/ISO/PCI/FedRAMP/WCAG frameworks,strong written and verbal communication.
SOC 1, SOC 2, ISO 27001, ISO 42001, PCI DSS, WCAG, FedRAMP
1w
Save
Mark Applied
Hide
GRC Manager
San Francisco or New York or United States
$150k-$250k/yr HybridFull Time
Baseten
Baseten: Scalable infrastructure platform for deploying and serving AI models.
5+ YOE5+ years GRC or security compliance experience in SaaS/cloud; strong knowledge of SOC 2, ISO 27001, NIST, GDPR; audit and certification management; third-party risk and cross-functional collaboration.
Vanta, Drata, Secureframe, Anecdotes, AWS, GCP
1mo
Save
Mark Applied
Hide
Security GRC Analyst
San Francisco, California, United States
$116k-$160k/yr OnsiteFull Time
Salesforce
SalesforceNYSE: CRM: Sells cloud-based customer relationship management and business software solutions.
2+ YOE2–4 years GRC/compliance/audit or information security experience; working knowledge of at least two of SOC 2, HIPAA, ISO 27001, or GxP; proficiency with GRC/audit tools and Microsoft Office or Google Workspace; strong communication skills.
SOC 2, HIPAA, ISO 27001, GxP, Microsoft Office Suite, Google Workspace, Drata, Vanta, OneTrust, ServiceNow GRC
2w
Save
Mark Applied
Hide
Head of Security GRC
New York City or Chicago or Austin or Dallas or Denver or Miami or San Francisco or Seattle
$270k-$290k/yr HybridFull Time
DriveWealth
DriveWealth: Provides API-based brokerage infrastructure for fractional stock trading.
15+ YOE15+ years in information security/GRC in regulated financial services; deep SEC/FINRA and global privacy knowledge; hands-on GRC, audit, TPRM, incident response, and executive/board reporting; relevant certifications preferred.
MITRE ATT&CK, FS-ISAC
2mo
Save
Mark Applied
Hide
Senior GRC Lead
Vancouver or New York City or San Francisco
$154k-$192k/yr HybridFull Time
Brex
Brex: Corporate cards and spend management software for businesses.
5+ YOE5+ years in GRC or Security Engineering; strong automation; security frameworks SOC 2, PCI DSS, ISO 27001; Python and API integrations; cross-functional collaboration; cloud native; Terraform.
Python, APIs, Terraform, Tines
1mo
Save
Mark Applied
Hide
Senior GRC Analyst, HIPAA
United States or San Francisco
$133k-$195k/yr OnsiteFull Time
DoorDash
DoorDashNASDAQ: DASH: On-demand delivery platform connecting consumers with local merchants.
6+ YOE6+ years in security compliance/GRC with 3+ years implementing HIPAA programs in technology or regulated environments; strong HIPAA Security Rule knowledge, multi-framework experience, technical fluency with cloud/IAM/CI/CD, and stakeholder communication skills.
HITRUST, SOC 2, ISO 27001, NIST 800-53, PCI DSS, GDPR, CCPA, IAM, CI/CD, infrastructure-as-code, GRC tooling
1mo
Save
Mark Applied
Hide
Director, Cybersecurity & GRC
Berkeley or Somerville or Weirton
$200k-$294k/yr HybridFull Time
Form Energy
Form Energy: Developing multi-day batteries for grid-scale energy storage.
10+ YOE5+ Mgmt10+ years in cybersecurity/IT GRC with 5+ years leadership; deep ITGC, IAM, EDR/MDR, vulnerability management, incident response, and audit liaison experience; ISO 27001/SOC 2/NIST familiarity; strong executive communication.
ISO 27001, SOC 2, NIST CSF, NIST 800-53, NIST 800-171, CMMC, EDR, MDR, IAM, ITGC, SOC
6d
Save
Mark Applied
Hide
Security GRC Specialist
South San Francisco or Toronto
OnsiteFull Time
Phylo
Phylo: An applied research lab building AI agents for biomedical discovery.
5+ YOE5+ years in security GRC or adjacent role; experience leading SOC 2, ISO 27001, HIPAA, FedRAMP or similar; cloud and application security knowledge; audit and enterprise customer review experience; strong cross-functional communication.
20h
Save
Mark Applied
Hide
GRC Controls Automation Engineer
Austin or Chicago or New York City or Redwood City or San Francisco or United States
$130k-$145k/yr HybridFull Time
Box
BoxNYSE: BOX: Provides cloud-based content management and secure file sharing services.
5+ YOE5+ years in SaaS GRC or information security; GCP, AI architectures, data governance, model validation, NIST, PCI, ISO, SOC 2, communication, and process improvement experience.
GCP, AI, NIST 800-53, PCI, ISO 27x, AICPA SOC, SOC 2
2w
Save
Mark Applied
Hide
Senior GRC Specialist
Mexico City or San Francisco
$120k-$185k/yr HybridFull Time
Airwallex
Airwallex: Global financial platform for business payments and money management.
5+ YOE5-7 years cybersecurity experience, Mexican Tax ID (RFC) or dual Mexican citizenship required, fluent English and Spanish, knowledge of PCI-DSS/ISO 27001/SOC2, fintech and cloud compliance experience, CISSP/CEH/CISA strong advantage.
PCI-DSS, ISO 27001, SOC2
1mo
Save
Mark Applied
Hide
Member of GRC Staff
New York City or San Francisco or Seattle or United States
$150k-$210k/yr RemoteFull Time
Runway
Runway: Develops generative AI software for creative video production.
7+ YOE7+ years in information security, risk or compliance; deep knowledge of NIST/SOC 2/ISO frameworks; hands-on SOC 2 Type II and ISO 27001 audits; GDPR/CCPA operational experience; cloud security and ML/AI understanding.
NIST, SOC 2, ISO 27001, ISO 27701, ISO 42001, FedRAMP, GDPR, CCPA
1mo
Save
Mark Applied
Hide
GRC Program Manager, Product and Customer Trust
San Francisco, California, United States
$216k-$252k/yr HybridFull Time
OpenAI
OpenAI: Develops artificial intelligence models and generative AI software services.
Experienced GRC/product assurance professional with product launch review, customer trust, and security compliance experience; able to build operating models, automation, metrics, and clear customer-facing security narratives.
Codex
2mo
Save
Mark Applied
Hide
Senior Governance, Risk, Compliance (GRC) Analyst
San Francisco, California, United States
$162k-$202k/yr OnsiteFull Time
Headway
Headway: A healthtech accelerating access to mental healthcare
5+ YOE5+ years in GRC/compliance/security risk; knowledge of HITRUST/SOC 2/PCI-DSS/HIPAA; experience with GRC platforms; strong communication; ability to build repeatable processes; interest in AI-enabled security workflows; healthcare/healthtech HIPAA understanding a plus
HITRUST, SOC 2, PCI-DSS, HIPAA, GRC platform (e.g., Vanta, Drata, OneTrust)
2mo
Save
Mark Applied
Hide
Senior AI GRC Engineer
United States or San Francisco or New York City or London or Dublin or Tel Aviv or Sydney
$178k-$209k/yr RemoteFull Time
Vanta
Vanta: Automated security compliance and trust management software for businesses.
Deep expertise in AI governance, risk, and compliance; experience using AI agents and building automations; coding experience with TypeScript, Go, or Python; cloud-native security knowledge (AWS); experience with compliance programs (SOC 2, ISO).
Anthropic products, OpenAI products, LangChain products, Cursor, TypeScript, Go, Python, AWS
1mo
Save
Mark Applied
Hide
Security GRC Manager: Customer Trust Enablement
San Francisco, California, United States
OnsiteFull Time
Sierra
Sierra: Conversational AI platform for building enterprise customer agents
10+ YOE3+ Mgmt10+ years in compliance/security/customer trust, 3+ years building/scaling customer-facing security programs, experience with regulated industries, knowledge of security frameworks and multi-cloud, and experience implementing trust automation platforms.
NIST 800-53, SOC 2, ISO 27001, PCI DSS, HIPAA, AWS, GCP, GDPR, UK GDPR, EU AI Act, SIG, CAIQ, ISO 42001, NIST AI RMF, CRM
3w
Save
Mark Applied
Hide
Security Engineer, GRC
San Francisco or Seattle or New York City
$156k-$214k/yr HybridFull Time
Plaid
Plaid: Provides financial data connectivity and payment infrastructure via APIs.
Strong Python and SQL, AWS and cloud security experience, Terraform and policy-as-code (OPA/Rego, Sentinel), CI/CD integration, continuous controls monitoring, GRC framework knowledge, and AI tooling experience.
Python, SQL, AWS, GitHub, Terraform, OPA/Rego, Sentinel, Mode, Claude, OpenAI, Anecdotes, Drata, Vanta, Paramify
1mo
Save
Mark Applied
Hide
Governance, Risk & Compliance (GRC) Manager
San Francisco or New York City or London or Sydney
$190k-$215k/yr OnsiteFull Time
Sigma Computing
Sigma Computing: Cloud-native analytics platform featuring a spreadsheet-style interface.
4+ YOE4+ years GRC experience in SaaS/tech, proven track record building GRC programs and leading SOC 2/ISO 27001/HIPAA audits, experience with ERM frameworks (COSO, ISO 31000, NIST RMF), data privacy (GDPR/CCPA), policy and control development, strong communication.
ServiceNow GRC, Archer, LogicGate, GCP, AWS, Azure, Vanta, Drata, Secureframe, Tugboat, NIST CSF, CIS Controls, OWASP, VSAs, SIGs, SQL, Python, SOC 2, ISO 27001, HIPAA, COSO, ISO 31000, NIST RMF