- Company Name
- Sigma
- Job Title
- Governance, Risk & Compliance (GRC) Manager
- Job Description
-
Job title: Governance, Risk & Compliance (GRC) Manager
Role Summary: Lead the design, implementation, and continuous improvement of a comprehensive governance, risk, and compliance program across technology, security, privacy, and operations. Align GRC initiatives with business strategy, ensure regulatory compliance, and support rapid business growth.
Expectations: • Establish enterprise‑wide governance, risk, and compliance frameworks within 12 months
• Achieve SOC 2, ISO 27001, and HIPAA certification readiness and maintain ongoing compliance
• Deliver measurable improvements in risk assessment, incident response, and policy adherence, targeting a 30% reduction in audit findings year‑over‑year
Key Responsibilities:
- Design and implement governance structures, dashboards, and policy oversight mechanisms
- Build and sustain an Enterprise Risk Management (ERM) program, maintain dynamic risk registers, and coordinate business continuity and disaster recovery plans
- Lead third‑party risk management, vendor assessments, and contract reviews
- Own and execute compliance monitoring programs for SOC 2, ISO 27001, HIPAA, GDPR, CCPA, labor and employment regulations, and other industry‑specific requirements
- Conduct internal audits, manage external audit coordination, and track remediation actions
- Develop and maintain security awareness training, compliance artifacts, and customer‑facing materials
- Partner with Sales, Engineering, Product, and Legal to integrate compliance into deal cycles and customer engagements
Required Skills:
- 4+ years in governance, risk, or compliance roles (SaaS/technology preferred)
- Proven experience building or maturing a GRC program from scratch
- Expertise in ERM frameworks (COSO, ISO 31000, NIST RMF) and audit certifications (SOC 2, ISO 27001, HIPAA)
- Deep knowledge of data privacy regulations (GDPR, CCPA, etc.) and ability to translate them into policies and controls
- Strong business acumen; ability to articulate risk value to leadership
- Excellent stakeholder influence, communication, and project management in fast‑paced environments
- Experience with GRC platforms (ServiceNow GRC, Archer, LogicGate) and cloud security compliance (GCP, AWS, Azure) is a plus
Required Education & Certifications:
- Bachelor’s degree in Business, Law, Information Security, or related field (or equivalent experience)
- Professional certifications preferred: CRISC, CISA, CISM, CGEIT, or CISSP.
San francisco, United states
On site
Junior
09-03-2026