Governance, Risk, and Compliance Manager - Privacy

AI Chopping Block

San Francisco, Northern (CA, KY)

Hybrid

USD 190,000 - 275,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Medical/Dental/Vision
Life Insurance
Disability Benefits
Retirement Plan
Parental Leave
Fertility benefits
Wellness Stipend
Office Lunches
Flexible Vacation

Job summary

Decagon is seeking a Governance, Risk, and Compliance Manager to secure customer trust as we scale to Fortune 500 and international enterprises. Working with the head of security and compliance, you will manage the day-to-day execution of our compliance program and lead customer security engagements.

This high-impact role requires meticulous writing, cross-functional coordination, and deep knowledge of privacy laws and enterprise certifications.

Qualifications

  • 5+ years of GRC experience in high-growth SaaS or technology companies, with direct responsibility for privacy compliance programs.
  • Proven track record contributing to SOC 2, ISO 27001, or similar enterprise compliance certifications.
  • Experience in data privacy regulations including CCPA, GDPR, and emerging AI governance frameworks.
  • Strong project management skills with ability to coordinate cross-functional teams under tight deadlines.
  • Excellent written and verbal communication skills to translate complex security concepts for diverse audiences.
  • Working knowledge of technical security controls and ability to collaborate effectively with engineering teams.

Responsibilities

  • Improve and maintain the privacy program against ISO 27701, ISO 27018, HIPAA, GDPR, CCPA/CPRA and the wider set of US state laws.
  • Own Decagon's privacy program operations end to end: data inventory, DSAR intake and fulfillment, DPAs and cross-border transfer mechanisms, data retention schedule, subprocessor onboarding and our public subprocessor list, breach notification readiness, and company-wide privacy training.
  • Partner with legal team to improve existing programs on data residency, subprocessor flow-downs, retention by data class, DPIAs and transfer impact assessments, while owning and driving day-to-day decision.

Skills

GRC
Privacy Compliance
SOC 2 / ISO 27001
CCPA/GDPR
Project Management
Security Communications
Technical Security Controls

Tools

Vanta
Drata
SecureFrame

Job description

About Decagon

Decagon is the leading conversational AI platform empowering every brand to deliver concierge customer experiences.

Our technology enables industry-defining enterprises like Avis Budget Group, Block's Cash App and Square, Chime, Oura Health, and Hunter Douglas to deploy AI agents that power personalized, deeply satisfying interactions across voice, chat, email, SMS, and every other channel.

We're building a future where customer experiences are being redefined from support tickets and hold music to faster resolutions, richer conversations, and deeper relationships. We're proud to be backed by world-class investors who share that vision, including a16z, Accel, Bain Capital Ventures, Coatue, and Index Ventures, along with many others.

We're an in-office company, driven by a shared commitment to excellence and velocity. Our values — Just Get It Done, Invent What Customers Want, Winner's Mindset, and The Polymath Principle — shape how we work and grow as a team.

About the Team

The Security Engineering team at Decagon protects the platform that powers the most advanced conversational AI agents for enterprise customers across voice, chat, email and SMS. We build the security foundations that enable Decagon's AI agents to handle sensitive customer data with complete trust while defending against sophisticated, AI-enabled threats at massive scale.

Our mission is to secure magical support experiences, ensuring that AI agents and human agents can collaborate safely to help users resolve their issues while maintaining the highest standards of security and privacy.

About the Role

Join Decagon as a Governance, Risk, and Compliance Manager and play a critical role in securing customer trust as we scale to serve Fortune 500 and international enterprises. Working closely with the head of security and compliance, you'll be responsible for the day-to-day execution of our compliance program and customer security engagements. This is a high-impact role where you'll directly contribute to closing enterprise deals by efficiently managing security communications with customers, supporting compliance audits, and improving our security documentation. Perfect for someone who thrives in a high impact organization with attention to detail, excellent writing skills, and who wants to build expertise in enterprise AI compliance.

In this role, you will
  • Improve and maintain the privacy program against ISO 27701, ISO 27018, HIPAA, GDPR, CCPA/CPRA and the wider set of US state laws.

  • Own Decagon's privacy program operations end to end: data inventory, DSAR intake and fulfillment, DPAs and cross-border transfer mechanisms, data retention schedule, subprocessor onboarding and our public subprocessor list, breach notification readiness, and company-wide privacy training.

  • Partner with legal team to improve existing programs on data residency, subprocessor flow-downs, retention by data class, DPIAs and transfer impact assessments, while owning and driving day-to-day decision.

Your background looks something like this
  • 5+ years of GRC experience in high-growth SaaS or technology companies, with direct responsibility for privacy compliance programs

  • Proven track record successfully contributing to SOC 2, ISO 27001, or similar enterprise compliance certifications

  • Experience in data privacy regulations including CCPA, GDPR, and emerging AI governance frameworks

  • Strong project management skills with ability to coordinate cross-functional teams under tight deadlines

  • Excellent written and verbal communication skills to translate complex security concepts for diverse audiences

  • Working knowledge of technical security controls and ability to collaborate effectively with engineering teams

Even better if you have
  • Experience with AI/ML compliance frameworks and understanding of unique risks in conversational AI systems

  • Background in healthcare or financial services with knowledge of HIPAA or PCI requirements

  • Track record of building GRC programs at companies scaling from startup to enterprise

  • Experience with GRC platforms like Vanta, Drata, or SecureFrame to automate compliance workflows

  • Understanding of cloud security particularly Google Cloud Platform compliance and security features

Compensation

$190K – $275K + Offers Equity

Benefits

We proudly offer the following benefits for our full-time employees:

  • Medical, Dental, and Vision benefits for you and your family

  • Life Insurance and Disability Benefits

  • Retirement Plan (e.g., 401K, pension)

  • Parental Leave

  • Fertility and family building benefits through Carrot

  • Monthly stipend to support your wellness, lifestyle, and work-life balance

  • Daily lunches and snacks in the office to keep you at your best

  • Take what you need vacation policy (subject to local requirements; UK employees receive 25 days of statutory leave)

These benefits are described in more detail in Decagon's policies, may vary by location, and can change at any time according to applicable compensation and benefits plans.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Governance, Risk, and Compliance Manager - Privacy
Governance, Risk, and Compliance Manager - Privacy

decagon • San Francisco (CA)

On-site
USD 190,000 - 275,000
Medical, Dental, and Vision benefits
Life Insurance and Disability Benefits
Retirement Plan (e.g., 401K)
+5
Senior Software Engineer, Application Security
Senior Software Engineer, Application Security

Decagon • San Francisco (CA)

On-site
USD 200,000 - 400,000
Medical, Dental, and Vision
Life Insurance
Retirement Plan
+5
Senior Security Engineer
Senior Security Engineer

Decagon • San Francisco (CA)

On-site
USD 200,000 - 330,000
Take what you need vacation policy
Medical, Dental, and Vision benefits
Life Insurance and Disability Benefits
+4
Security Engineer
Security Engineer

decagon • San Francisco (CA)

On-site
USD 200,000 - 330,000
Take what you need vacation policy
Medical, Dental, and Vision benefits
Life Insurance and Disability Benefits
+4
Senior Software Engineer, Application Security
Senior Software Engineer, Application Security

Decagon • New York (NY)

On-site
USD 200,000 - 400,000
Medical, Dental, and Vision benefits
Life Insurance and Disability Benefits
401K or pension
Senior Research Engineer, Safety
Senior Research Engineer, Safety

Decagon • New York (NY)

On-site
USD 200,000 - 400,000
Medical, Dental, and Vision benefits
Life Insurance and Disability Benefits
Retirement Plan (e.g., 401K)
+3
Senior Research Engineer, Safety
Senior Research Engineer, Safety

Speedrun Talent Network • San Francisco (CA), Northern (KY)

Hybrid
USD 200,000 - 400,000
Medical, Dental, and Vision benefits
Life Insurance and Disability Benefits
Retirement Plan (e.g., 401K)
+5
Senior Research Engineer, Safety
Senior Research Engineer, Safety

Decagon • San Francisco (CA)

On-site
USD 200,000 - 400,000
Medical, Dental, and Vision benefits
Life Insurance and Disability Benefits
Retirement Plan (401K/pension)
+5
Senior Research Engineer, Safety
Senior Research Engineer, Safety

Neura Market • San Francisco (CA), Northern (KY)

Hybrid
USD 200,000 - 400,000
Medical, Dental, and Vision benefits
Life Insurance and Disability Benefits
Retirement Plan
+5
AI Acceleration Engineer
AI Acceleration Engineer

AI Chopping Block • San Francisco (CA), Northern (KY)

Hybrid
USD 180,000 - 220,000
Medical, Dental, and Vision
401K Retirement Plan
Parental Leave
+3