Manage SOC 2, HITRUST, and ISO 27001 audits, including internal control testing and external assessments.
Serve as the GRC subject matter expert, maintaining the risk register, compliance policies, and trust center.
Partner with Engineering, Product, People, and Legal to automate GRC tasks and report posture to leadership.
Garner Health uses clinical data and incentives to steer members toward higher-quality, lower-cost care in partnership with employers. We've doubled five years running, raised a Series E, and maintain a mission-driven, high-accountability culture.
Own delivery of standard-framework GRC engagements: ISO 27001, SOC 2, GDPR, PCI DSS, gap assessments, and audit readiness.
Build reusable IP by maintaining templates, control mappings, and AI-assisted playbooks with QA guardrails.
Own commercial outcomes including pricing, margins, utilization, and attach/renewal with Sales and CS.
Sprinto is an autonomous trust platform that centralizes compliance, audits, risk, and AI governance to keep organizations audit-ready. Backed by Accel and Elevation, Sprinto is a remote-first, high-trust company relied on by 4,000+ organizations.
Own SOC 2 end to end, run auditor relationships, and keep the program audit-ready year round.
Run risk management, policy, BC/DR, and vendor/subprocessor programs with automated evidence.
Lead security questionnaires and TPRM reviews to close deals and scale compliance across frameworks.
Aegis AI is a security company founded by ex-Google engineers who built Safe Browsing and reCAPTCHA, now stopping adversarial AI attacks. The team is flat, flexible, and fast, with clear KPIs and a focus on owning decisions while moving at real-world speed.
Own customer security reviews and compliance programs, driving fast and accurate responses.
Ensure practical risk decisions and reliable security answers through automation and AI.
Scale the function by building processes and self-service resources."
The company is a technology company that builds quickly and focuses on security and compliance. It is a remote-first small team with a culture of autonomy and growth.
Drive implementation and continuous improvement of ISO 27001 ISMS and SOC 2 Type II compliance.
Own risk management, internal audits, security policies, and vendor security assessments.
Collaborate with engineering and DevOps on AWS security governance, incident response, and AI/LLM risk governance.
Insider One is an AI-powered marketing and customer engagement platform that unifies data, personalization, and journey orchestration across channels. With 1,500+ employees from 50+ nationalities and offices in over 30 countries, it is a diverse, socially progressive B2B SaaS unicorn backed by major investors.
Own and mature security, privacy, and compliance programs across HIPAA, SOC 2, and HITRUST.
Lead HITRUST certification end to end, including scoping, evidence collection, and assessor coordination.
Partner with Engineering, Product, SRE, and IT to integrate security into architecture, SDLC, and cloud infrastructure.
IntusCare is an end-to-end ecosystem built specifically to help PACE programs deliver exceptional care, strengthen financial performance, and stay compliant. It is a growing healthcare SaaS organization that empowers teams to improve outcomes for dual-eligible seniors.
Lead and mature the organization's governance, risk management, compliance, and audit programs.
Own cybersecurity compliance initiatives including CMMC Level 2, SOC audits, and SOX IT General Controls.
Partner with business, technology, and executive stakeholders to align security controls with regulatory and business requirements.
Loenbro is a trusted construction lifecycle partner serving thousands of customers across the U.S. with services including electrical, mechanical, structural, inspection, and fabrication. The company has a national presence with a local approach and fosters a culture of integrity, teamwork, and purpose.
Act as part vCISO and account manager, guiding clients through security and compliance programs.
Assess security posture, provide recommendations, and design programs using NIST, SOC 2, and ISO 27001.
Liaise with auditors and internal teams to translate programs into policies, procedures, and configurations.
Oneleet provides a platform for companies to build, manage, and monitor cybersecurity programs and achieve SOC 2 and ISO 27001. It raised a $33M Series A and is a fast-growing, remote-first team with an opinionated culture.
Own global certification programs like ISO 27001 and SOC 2, and advise engineering teams on secure development.
Collaborate directly with engineers to audit cloud infrastructure, CI/CD pipelines, and AI-driven security controls.
Assess risks of emerging technologies and drive continuous compliance improvements across the organization.
Picus Security is an exposure validation company that proves what attackers can exploit and what defenses stop, turning exposures into defensible decisions. As a fast-growing global remote team, it values continuous security validation and has a 95% recommendation rate.
Own and mature internal and Managed GRC programs, including federal SSPs, POA&Ms, audits, and risk assessments.
Collaborate with CISOs, engineers, and control owners to translate compliance requirements into practical technical controls.
Lead and develop a GRC team while introducing automation and AI to improve scalability and consistency.
The company provides managed Governance, Risk & Compliance (GRC) and security assurance services, with a strong focus on federal security programs and frameworks like NIST, SOC 2, and CMMC. It supports a growing GRC team and emphasizes low-ego collaboration, automation, and AI-enabled approaches to scale delivery.