Lead and mature the GRC program across SOC 2, ISO 27001, PCI DSS, and other compliance frameworks, including audit preparation and evidence collection.
Own the annual security risk assessment process using NIST SP 800-30 methodology, including stakeholder interviews and risk scoring.
Drive security awareness training, AI governance, and Data Loss Prevention program development while collaborating with cross-functional teams.
Serve as a hands-on GRC advisor for customers, guiding them through risk assessments, audit preparation, and control rollouts.
Help customers navigate audits like SOC 2, ISO 27001, HIPAA, PCI-DSS, and NIST, translating requirements into practical steps.
Spot GRC complexity early and partner with Support and Customer Success to own escalations requiring real GRC expertise.
Compyl is a GRC and automated security compliance platform built by security practitioners. Backed by Venture Guides, Contour Venture Partners, and Armory Square Ventures, it is a high-growth Series A company.
Own and continuously improve Camunda's Information Security Management System (ISMS), driving measurable improvements.
Drive security audit cycles for ISO 27001, SOC 2, and future frameworks with minimal supervision.
Review information security requirements in customer contracts and lead responses to complex security questionnaires.
We are the enterprise platform for agentic orchestration, enabling organizations to coordinate AI agents, people, and systems across complex business processes. We are a fully remote, global team trusted by over 700 organizations, named a GP Bullhound Next Unicorn and Great Place to Work certified.
Lead the design and governance of control frameworks and risk workflows within the GRC platform, ensuring alignment with compliance requirements like HIPAA, HITRUST, and NIST.
Oversee risk assessments, control testing, and vendor evaluations to identify and mitigate security risks.
Manage policy lifecycle, audit coordination, and reporting on control effectiveness and risk indicators.
USAP is a healthcare organization focused on providing anesthesia services and patient safety. It is a growing company with a culture of security, compliance, and collaboration.
Manage and implement complex controls frameworks for large systems consisting of Cloud infrastructure and SaaS services.
Design and develop automation solutions for evidence collection across Cloud infrastructure, endpoints, and SaaS services.
Conduct risk assessments across business units and processes, identifying risk findings and recommending remediation strategies.
Virtru is a data protection platform that enables secure sharing without sacrificing security or privacy. Backed by top venture capital firms, the company helps Fortune 500 companies and government agencies achieve true data security with freedom to share.
Monitor and enforce compliance with security frameworks like NIST CSF, ISO 27001, SOC 2, and regulations such as GLBA, CCPA, and GDPR.
Conduct comprehensive risk assessments, develop security policies, and lead internal and external security audits with cross-functional teams.
Evaluate third-party vendor security posture, maintain compliance records, and define metrics to assess the success of the security program.
Clear Capital is a national real estate analytics, data solutions and valuation technology company with a simple purpose: to build confidence in real estate decisions to strengthen communities and improve lives. The company values integrity, kindness, and grit, and has been committed to excellence since 2001.
Perform enterprise risk assessments using NIST CSF, SOC 2, and CIS frameworks.
Develop and execute security awareness programs including training and phishing simulations.
Support governance and control management by maintaining policies and control libraries.
Protective helps protect customers against life's uncertainties by providing insurance and peace of mind. The company offers a collaborative environment with a focus on employee wellbeing and work-life balance.
Drive compliance, risk management, and security assurance as a GRC Specialist.
Own third-party risk management and maintain security documentation.
Support audits, self-assessments, and customer security inquiries.
Avid provides technology and collaboration tools for creators to entertain, inform, educate, and enlighten the world. The company fosters a culture of passion, customer focus, and innovation, with employees who believe in their mission.
Own and continuously improve the company's compliance program across SOC 2, GDPR, ISO 27001, and other frameworks.
Lead external audits, develop security policies, and partner with engineering teams to implement controls.
Manage third-party risk, respond to customer security questionnaires, and build compliance metrics for executive reporting.
10a Labs is the safety and threat-intelligence layer trusted by frontier AI labs, AI unicorns, Fortune 10 companies, and leading global technology platforms. They are a high-growth technology company with a collaborative culture, operating in a fast-moving environment.
Lead customer security reviews, RFPs, RFIs, and questionnaires to keep deals moving.
Own SOC 2 Type II program management and the customer-facing trust portal.
Author security policies and manage AI compliance frameworks.
Sparkrock helps social benefit organizations like nonprofits, school boards, and government agencies reach their full potential through technology. They are a best-in-class, 100% remote organization with a focus on culture and growth, serving over 150,000 users.
Partner with Sales, Customer Success, and Marketing on strategic enterprise opportunities, bringing security and GRC expertise into customer conversations.
Lead executive briefings and CISO-to-CISO conversations to build trust and confidence in Drata's platform.
Represent Drata at industry conferences, CISO dinners, and roundtables across the Americas, EMEA, and APAC, building relationships and credibility.
Drata helps companies earn and keep trust by providing a proof layer that shows they deserve it. The company has over 600 employees worldwide and fosters a culture built on trust, speed, and continuous growth.
Support enterprise cybersecurity governance, compliance, and risk management programs.
Conduct security control assessments, audit readiness, and policy development.
Coordinate with technical teams and executive leadership to drive cybersecurity modernization.
ERP International is a nationally respected provider of health, science, and technology solutions supporting government and commercial clients. The company has been named a Top Workplace by WTOP News for 7 years and offers a culture of employee recognition, community outreach, and professional development.
Maintain and mature the ISMS, including the Statement of Applicability, risk treatment plans, and Management Review Meetings.
Support ISO 27001 and SOC 2 Type 2 audits from readiness through certification, including evidence preparation.
Lead the security policy program and collaborate across teams to translate compliance requirements into practical practices.
Mozilla Corporation is a non-profit-backed tech company behind Firefox, focused on making the internet better. With 225+ million monthly users, it is a wholly owned subsidiary of the Mozilla Foundation, promoting privacy, AI, and open-source.
Own and drive the compliance roadmap across multiple frameworks like ISO 27001, TISAX, and SOC 2.
Implement ISO 27001 end-to-end for customers and mentor junior compliance specialists.
Act as the senior compliance voice for customers, auditors, and product, partnering with CS and founders.
Secfix automates security compliance in Europe, helping companies achieve ISO 27001, GDPR, TISAX, and SOC 2 quickly and easily. We are a 100% remote team with hubs in Munich, Berlin, and London, backed by top VCs with a high-performing, ownership-driven culture.
Own the design and implementation of Onebrief's GRC framework across RMF, FedRAMP, CMMC, SOC 2, and other applicable standards.
Build and manage the control environment, including policies, procedures, and evidence collection systems.
Design and implement technical security controls in partnership with Product, Engineering, Infrastructure and Corporate IT.
Onebrief builds collaboration and AI-powered workflow software for military planning and operational coordination. Founded in 2019 and valued at over $2 billion, the company is a distributed team of builders from military, operational, and technology backgrounds.
Lead the GRC strategy, shifting from bureaucratic to strategic enabler focused on real business risk.
Manage cyber risk quantification, third-party risk, and continuous compliance programs.
Oversee information security governance, AI governance, and IAM governance, reporting to the CISO.
Grupo QuintoAndar is the largest real estate ecosystem in Latin America, covering all phases of the housing journey. The company is valued at over USD 5.1 billion, with a culture of innovation, collaboration, and high performance working with top professionals.
Support solution sales as a technical and domain expert for a client-facing sales team.
Lead discovery workshops and give product demonstrations to align solutions with customer needs.
Act as domain SME across risk areas including Risk Management, Compliance, and Cyber Risk.
ServiceNow makes the world work for everyone through innovative technology. With over 7,700 customers including 85% of the Fortune 500, we are recognized as one of FORTUNE 100 Best Companies to Work For® and World's Most Admired Companies™.
Build and own federal compliance frameworks for FedRAMP, NIST, and CMMC.
Interpret controls at the mechanics level and author precise technical guidance.
Lead Vanta's machine-readable future with OSCAL and FedRAMP 20x.
Vanta helps businesses earn and prove trust by automating security monitoring and compliance. Founded in 2018, the company has a kind and talented team and is used by thousands of companies.
Lead bespoke customer engagements end-to-end, from discovery to solution architecture and configuration of tailored Risk Cloud solutions.
Leverage AI and automation to accelerate delivery, optimize processes, and provide strategic GRC advisory to enterprise customers.
Manage project scope, timelines, and account health while mentoring junior consultants and collaborating cross-functionally.
LogicGate is the leading AI GRC platform for the enterprise, helping governance, risk, and compliance teams manage uncertainty and drive business value. The company is recognized as a top workplace and fosters a culture of ownership, impact, and inclusion, with a commitment to employee growth and community involvement.
Assist in monitoring compliance with frameworks like ISO 27001, SOC 2, and Cyber Essentials.
Maintain the central Risk Register and track remediation progress across departments.
Support policy management and compliance training across the organization.
We are a global Physical AI company using data and AI to improve critical industries like healthcare, water, energy, and telecom. Our teams are ambitious, curious, and practical, with colleagues across Africa, Europe, the UK, and the US.
Operate as a trusted advisor to executive teams, guiding them through complex cybersecurity challenges and building security programs.
Develop enterprise security strategies, roadmaps, and governance frameworks, translating technical risks into business impact.
Lead risk assessments, incident response planning, and compliance initiatives aligned with NIST, CIS, and ISO frameworks.
DYOPATH simplifies technology for clients while investing deeply in its people. Recognized as a Great Place to Work for five consecutive years, the company prides itself on building exceptional teams to deliver secure solutions.