Serve as a hands-on GRC advisor for customers, guiding them through risk assessments, audit preparation, and control rollouts.
Help customers navigate audits like SOC 2, ISO 27001, HIPAA, PCI-DSS, and NIST, translating requirements into practical steps.
Spot GRC complexity early and partner with Support and Customer Success to own escalations requiring real GRC expertise.
Compyl is a GRC and automated security compliance platform built by security practitioners. Backed by Venture Guides, Contour Venture Partners, and Armory Square Ventures, it is a high-growth Series A company.
Own and drive the compliance roadmap across multiple frameworks like ISO 27001, TISAX, and SOC 2.
Implement ISO 27001 end-to-end for customers and mentor junior compliance specialists.
Act as the senior compliance voice for customers, auditors, and product, partnering with CS and founders.
Secfix automates security compliance in Europe, helping companies achieve ISO 27001, GDPR, TISAX, and SOC 2 quickly and easily. We are a 100% remote team with hubs in Munich, Berlin, and London, backed by top VCs with a high-performing, ownership-driven culture.
Lead the design and governance of control frameworks and risk workflows within the GRC platform, ensuring alignment with compliance requirements like HIPAA, HITRUST, and NIST.
Oversee risk assessments, control testing, and vendor evaluations to identify and mitigate security risks.
Manage policy lifecycle, audit coordination, and reporting on control effectiveness and risk indicators.
USAP is a healthcare organization focused on providing anesthesia services and patient safety. It is a growing company with a culture of security, compliance, and collaboration.
Support and scale the Assurance & Compliance function through an engineering-driven, automation-first approach.
Partner with Engineering, Security, Legal, and other teams to support compliance programs and audit readiness.
Help transform compliance into a continuous, measurable capability embedded into operations.
Flock builds technology that reduces crime and protects privacy, partnering with cities, businesses, schools, and neighborhoods. With over $1B in funding and an $8.3B valuation, the company is a high-performance team united by urgency, ownership, and a shared commitment to meaningful impact.
Lead the governance, risk, and compliance function across security policies, standards, risk management, audits, and third-party risk.
Own audit readiness and ongoing compliance programs across frameworks such as SOC 2, ISO 27001, GovRAMP, PCI DSS, HIPAA, NIST CSF, and more.
Manage third-party and supply chain risk management, including vendor security reviews, due diligence, and remediation tracking.
Accela provides government software solutions to improve efficiency, increase citizen engagement, and enable thriving communities. They have been an industry leader for nearly 20 years and are committed to diversity, equity, and inclusion.
Manage and conduct internal and external compliance audits for frameworks like ISO, SOC, and NIST.
Work with global teams to implement and update compliance controls, policies, and training.
Stay updated on regulatory changes and perform gap analysis to maintain certifications.
QAD is building a world-class SaaS company that solves real-world problems in manufacturing and supply chain. They are a growing, virtual-first company with a collaborative culture that values idea-sharing and growth.
Own the complete internal audit lifecycle, from initial kickoff through final reporting.
Review and assess customer evidence against ISO 27001 controls.
Conduct customer discussions to explain audit findings and provide recommendations.
The company provides security compliance services, helping organizations achieve and maintain industry-leading standards. It operates as a remote-first environment where ownership, expertise, and clear communication are highly valued.
Own and continuously improve the company's compliance program across SOC 2, GDPR, ISO 27001, and other frameworks.
Lead external audits, develop security policies, and partner with engineering teams to implement controls.
Manage third-party risk, respond to customer security questionnaires, and build compliance metrics for executive reporting.
10a Labs is the safety and threat-intelligence layer trusted by frontier AI labs, AI unicorns, Fortune 10 companies, and leading global technology platforms. They are a high-growth technology company with a collaborative culture, operating in a fast-moving environment.
Own the end-to-end GRC strategy and roadmap, driving compliance maturity and reducing audit risk.
Design and implement policy-as-code systems, translating compliance frameworks into enforceable code.
Lead full audit cycles, manage evidence collection, and architect GRC platform strategy for continuous compliance.
Smartsheet empowers teams to manage work and scale solutions, now uniting human teams with AI agents to automate tasks and uncover insights. With a history of over 20 years, the company fosters a culture of inclusion, creativity, and big thinking, offering professional growth and a supportive environment.
Own and run the ISMS, lead ISO 27001 certification, and manage risk, policies, and audits end-to-end.
Handle customer security questionnaires, RFIs, and supplier audits independently as the sole security expert.
Manage GDPR compliance, including DPAs, subprocessor lists, vendor reviews, and DSARs with operational ownership.
Cosuno is a fast-growing tech startup revolutionizing the construction industry through a digital platform for tenders and procurement, using AI to analyze price data and create efficient bids. They are a lean, 100-person team with a culture of high autonomy, pragmatism, and AI-first thinking, offering a remote-first work environment.
Manage and implement complex controls frameworks for large systems consisting of Cloud infrastructure and SaaS services.
Design and develop automation solutions for evidence collection across Cloud infrastructure, endpoints, and SaaS services.
Conduct risk assessments across business units and processes, identifying risk findings and recommending remediation strategies.
Virtru is a data protection platform that enables secure sharing without sacrificing security or privacy. Backed by top venture capital firms, the company helps Fortune 500 companies and government agencies achieve true data security with freedom to share.
Own RMF authorizations across Department of War components and FedRAMP High, alongside CMMC 2.0 and SOC 2 compliance for corporate systems.
Maintain authorization and audit evidence, including SSPs, SARs, POA&Ms, STIGs, and control mappings.
Partner with Engineering, Product, and Security to embed compliance requirements into system design and CI/CD workflows.
Onebrief builds collaboration and AI-powered workflow software for military planning and operational coordination. Founded in 2019, valued at over $2 billion, they are a distributed team of builders from military, operational, and technology backgrounds.
Perform testing and validation of ITGC and security controls.
Assess control effectiveness and support remediation efforts.
Support internal and external audits including SOC 2 and ISO 27001.
Marlabs is a global AI and Digital Solutions Consulting firm that delivers intelligent solutions across AI, data, analytics, and product engineering. Since 2000, they have partnered with large organizations worldwide, fostering a culture of innovation and collaboration.
Own delivery for standard-framework GRC engagements including ISO 27001, SOC 2, GDPR, and PCI DSS.
Build and maintain reusable IP such as templates, control-mapping libraries, and AI-assisted playbooks.
Own commercial outcomes including pricing, utilization, margin, and delivery forecasting for your own engagement book.
Sprinto is an Autonomous Trust Platform that centralizes trust requirements across security frameworks, vendors, and customers. Backed by top-tier investors such as Accel, Elevation, and Blume Ventures, they have raised $31.8M in funding and are trusted by over 3,000 organizations across 75 countries, with a remote culture organized around problems rather than job titles.
Lead compliance initiatives across commercial and federal lines, driving FedRAMP, CMMC, ISO 27001, SOC 2, and HITRUST programs.
Coordinate internal and external audits, ensuring stakeholder readiness and timely remediation of findings.
Manage program roadmaps, risk registers, and cross-functional execution to translate regulatory requirements into actionable plans.
We provide an AI-infused scenario planning and analysis platform to optimize business decision-making. We serve over 2,400 global customers including Fortune 50 companies and foster a Winning Culture focused on innovation, diversity, and leadership.
Own and continuously mature the company risk register, designing AI-assisted workflows for real-time risk posture.
Lead external audit management (SOC 2 Type II) and automate evidence collection pipelines in Vanta.
Engineer the Trust and Assurance program for scale, including automated vendor risk intake and AI-assisted response generation.
ButterflyMX empowers people to open and manage doors & gates from a smartphone, with products installed in over 20,000 properties worldwide. As a distributed, primarily remote workforce, they seek intelligent, passionate, and collaborative individuals driven by shared commitment to excellence and innovation.
Act as a regional anchor for security compliance, managing controls and audits.
Develop and maintain security documentation, including policies and metrics.
Implement AI and automation to streamline compliance and security work.
Airwallex provides a unified payments and financial platform for global businesses, empowering over 250,000 companies with integrated solutions. With over 2,300 employees across 27 global offices, the company values innovation and ambitious work.
Manage and maintain version control of all documentation related to compliance for each standard and track implementation status of security controls.
Oversee preparation and execution of external compliance audits, including facilitating security assessments.
Support mapping of compliance requirements to security control implementation using agile development processes.
Hypori is a high-growth cybersecurity SaaS company providing a virtual workspace platform for secure mobile access. Backed by $55M in funding, the company is expanding into commercial and regulated markets with a focus on innovation and security.
Drive compliance, risk management, and security assurance as a GRC Specialist.
Own third-party risk management and maintain security documentation.
Support audits, self-assessments, and customer security inquiries.
Avid provides technology and collaboration tools for creators to entertain, inform, educate, and enlighten the world. The company fosters a culture of passion, customer focus, and innovation, with employees who believe in their mission.
Defines program goals, governance frameworks, and measurable objectives for cyber risk and compliance programs.
Manages user attestations, third-party risk, cyber contract negotiation, and coordination of IT audits/assessments.
Implements GRC tooling and monitors program effectiveness through KPIs, QA reviews, and control testing.
Velera is a credit union service organization providing fintech solutions to over 4,000 financial institutions. The company fosters a remote-first, inclusive culture with a focus on employee wellbeing and belonging.