Blitzy: Autonomous AI platform for enterprise software development.
Hands-on ownership of SOC 2 Type II or ISO 27001:2022 audits, Vanta or equivalent GRC platform experience, auditor/vendor management, FedRAMP exposure preferred, strong written and judgment skills.
10+ YOE10+ years in IT risk/audit/GRC, experience with RCSAs/KRIs, vendor risk/SOC reviews, strong writing and communication, knowledge of NIST/COSO/COBIT and US/global regulations; professional certs a plus.
United States or Canada or Washington or New York City or San Francisco or Seattle or Denver or Boston or Los Angeles
$150k-$250k/yrRemoteFull Time
Crux: Platform for financing clean energy and infrastructure projects.
4+ YOE4+ years IT ownership at high-growth startups, SOC2 audit experience, SaaS vendor negotiation, Mac/Windows management, automation mindset, regular use of AI tools.
KlaviyoNYSE: KVYO: Software platform for automated e-commerce marketing and customer data.
3+ YOE3+ years security compliance/GRC engineering experience with automation focus; experience with SOC 2, ISO 27001/27017, PCI or SOX ITGCs; proficiency with cloud (AWS, Kubernetes), scripting (Python, Go, SQL), REST APIs, and compliance automation platforms.
Emburse: Provides AI-powered travel and expense management software for businesses.
5+ YOE5+ years in information security compliance or vendor risk; working knowledge of SOC 2, ISO 27001, NIST, GDPR, CCPA; experience with high-volume DDQ workflows; strong written communication and organization; proficiency with RFPIO.
15+ YOE15+ years in technology audit/compliance/risk, knowledge of access controls, change management, disaster recovery, patching and domestic/global regulations; strong communication and team collaboration skills.
Active Directory, Workiva, AuditBoard, Vanta, Drata, Protect