17h ago
GRC Manager
Boston, MA
โจ $150k-$200k / yearest.
full-timesenior Hybridsoftware
๐ Tech Stack
๐ผ About This Role
You'll own and scale governance, risk, and compliance programs at CloudZero, a fast-growing SaaS platform. You'll partner across Legal, Engineering, and Sales to build a GRC function that protects the business and enables sales velocity through automated security responses. This role has a hybrid schedule with 2-3 days per week in office.
๐ฏ What You'll Do
- Design and operate the GRC framework including risk management and compliance programs
- Own SOC 2 audits and certification programs across the organization
- Lead enterprise risk assessments and maintain a living risk register
- Own the security questionnaire process and build automation for response
- Manage business continuity, disaster recovery, and third-party risk programs
๐ Requirements
- 5+ years of experience in governance, risk, and compliance roles at a SaaS or cloud company
- Proven experience building or maturing a GRC program with hands-on SOC 2 audit involvement
- Working knowledge of risk management frameworks such as COSO, ISO 31000, or NIST RMF
- Solid understanding of GDPR and CCPA and how to translate obligations into controls
โจ Nice to Have
- Experience with Vanta or Drata for continuous compliance monitoring
- Familiarity with security frameworks such as NIST CSF, CIS Controls, or OWASP
- Professional certifications like CRISC, CISA, CISM, CISSP, or CIPP
๐ Benefits & Perks
- ๐๏ธ Unlimited PTO
- ๐ฅ Comprehensive health insurance
- ๐ป Remote-friendly culture
- ๐ Equity grants
- ๐ Team lunches and events
๐จ Hiring Process
Estimated timeline: 3-5 weeks ยท AI estimate
- 1Recruiter phone screenยท 30 min
- 2Hiring manager interviewยท 45 min
- 3Technical / cross-functional interviewยท 60 min
- 4Final round with leadershipยท 45 min
๐ฉ Heads Up
- Mixes GRC, sales engineering, and contract negotiation into one role, suggesting scope creep
0 0 0