- Company Name
- Faire
- Job Title
- Security Compliance Lead (GRC)
- Job Description
-
Job Title: Security Compliance Lead (GRC)
Role Summary: Design, implement, and scale the Governance, Risk, and Compliance (GRC) program. Drive policy development, risk assessment, audit readiness (SOX ITGC), and compliance certifications (ISO 27001, SOC 2 Type II, CCPA, GDPR). Partner with engineering, IT, legal, finance, and external auditors to embed risk management into daily operations and report on compliance metrics.
Expectations: • 8+ years in Security & IT Governance, Risk, and Compliance. • Big 4 audit experience or equivalent in regulated tech/financial environments. • Proven record building GRC frameworks, policies, and audit programs. • Experience with SOX ITGC, ISO 27001, SOC 2 Type II. • Strong cross‑functional collaboration, communication, and analytical skills.
Key Responsibilities:
1. Develop and execute the GRC roadmap and policy framework.
2. Conduct vendor security reviews and employee awareness training.
3. Manage SOX ITGC readiness: define scope, document controls, and enhance audit processes.
4. Lead efforts to achieve ISO 27001, SOC 2 Type II, CCPA, GDPR, and related certifications.
5. Partner with external auditors for security compliance certifications and audit reporting.
6. Report status, metrics, and KPIs to leadership and stakeholders.
7. Continuously improve risk and compliance processes to align with strategic objectives.
Required Skills:
- Security & IT governance, risk management, and compliance expertise.
- Audit and certification experience (SOX ITGC, ISO 27001, SOC 2 Type II, CCPA, GDPR).
- Proficiency with GRC tools and technologies.
- Cross‑functional collaboration with engineering, IT, legal, finance.
- Strong written and verbal communication.
- Analytical, results‑driven mindset.
Required Education & Certifications:
- Bachelor’s degree in Information Security, Risk Management, Business, or related field.
- Relevant certifications such as CISSP, CISA, CISM, or equivalent.
- ISO 27001 Lead Implementer/Lead Auditor, SOC 2, or SOX ITGC knowledge is preferred.
San francisco, United states
Hybrid
Senior
26-12-2025