GRC & AI Governance Leader

Guava

Los Angeles (CA)

On-site

USD 140,000 - 180,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Base salary + equity
Medical/dental/vision
401(k) matching
Flexible PTO
Parental leave
Equipment & tools

Job summary

Guava in Downtown Los Angeles is seeking a Head of Governance, Risk & Compliance to own our GRC program end to end, including SOC 2 Type II, HITRUST, PCI DSS, and our enterprise risk register. You will partner with engineering, sales, and product to design controls and guardrails that keep customers compliant with TCPA, FCC, and GDPR.

This role requires 10+ years in GRC, and a proven track record of leading audits, building a harmonized controls framework, and guiding executive decisions.

Qualifications

  • 10+ years in GRC, compliance, security, IT audit, or technology risk, including owning programs end to end.
  • Proven experience owning SOC 2, HITRUST, and PCI DSS programs through successful audits.
  • Experience building and maintaining an enterprise risk register and risk‑management program (inherent/residual risk scoring and treatment plans).
  • Strong understanding of internal control design, testing, documentation, and framework mapping across SOC 2, ISO 27001, HIPAA, PCI DSS, and NIST CSF.
  • Working knowledge of TCPA, FCC telephony regulations, and GDPR, ideally in a communications, telephony, or AI/voice context.
  • A track record of partnering with engineering to implement controls in the SDLC.
  • Experience enabling sales through security questionnaires, RFIs, and customer trust conversations.
  • Experience designing and running security training and tabletop and incident‑response exercises.
  • Excellent written and verbal communication; able to translate complex risk and compliance concepts for technical and executive audiences at all levels.
  • Ability to operate hands‑on in an early‑stage, high‑velocity environment.

Responsibilities

  • Own certifications. Lead SOC 2, HITRUST, and PCI DSS programs: scoping, evidence collection, control design, and remediation.
  • Run audits end to end. Organize audit activities and maintain audit artifacts across frameworks.
  • Manage control deficiencies. Analyze deficiencies and drive resolution.
  • Own the enterprise risk register end to end: risk intake, triage, scoring, and risk treatment decisions.
  • Own the controls framework across SOC 2, HITRUST, PCI DSS and related standards.
  • Run policy governance: full policy lifecycle and documentation standards.
  • Implement controls with engineering to embed controls in the SDLC.
  • Stand up AI governance: policies, risk assessments, oversight, and alignment with AI regulation.
  • Own RFIs and questionnaires: respond and build reusable knowledge base for deals.
  • Build customer guardrails with sales/product for TCPA, FCC, GDPR compliance.
  • Lead training and tabletop exercises across engineering, sales, leadership.
  • Report KPIs/KRIs and executive dashboards for control maturity and audit readiness.
  • Own GRC tooling and automate evidence collection.

Skills

GRC leadership
SOC 2 management
HITRUST management
PCI DSS program
Risk management
Audit management
Policy governance
SDLC controls
AI governance
Vendor management
Executive communication

Tools

GRC tooling

Job description

Guava in Downtown Los Angeles is seeking a Head of Governance, Risk & Compliance to own our GRC program end to end, including SOC 2 Type II, HITRUST, PCI DSS, and our enterprise risk register. You will partner with engineering, sales, and product to design controls and guardrails that keep customers compliant with TCPA, FCC, and GDPR.

This role requires 10+ years in GRC, and a proven track record of leading audits, building a harmonized controls framework, and guiding executive decisions.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Lead: AI Compliance Certifications (SOC 2, ISO 27001)
GRC Lead: AI Compliance Certifications (SOC 2, ISO 27001)

Thinking Machines Lab Inc. • San Francisco (CA), Northern (KY)

Hybrid
USD 225,000 - 350,000
Health, dental, and vision benefits
Unlimited PTO
Paid parental leave
+1
GRC Manager, AI Security & Privacy
GRC Manager, AI Security & Privacy

AI Chopping Block • San Francisco (CA), Northern (KY)

Hybrid
USD 190,000 - 275,000
Medical/Dental/Vision
Life Insurance
Disability Benefits
+6
GRC & Compliance Supervisor — Audit & Risk
GRC & Compliance Supervisor — Audit & Risk

Glovis America, Inc. • Irvine (CA), Northern (KY)

Hybrid
USD 74,000 - 84,000
Medical Insurance
Vision Insurance
Dental Insurance
+9
Senior GRC Engineer: AI Governance & Continuous Controls
Senior GRC Engineer: AI Governance & Continuous Controls

ezCater • United States

Hybrid
USD 165,000 - 210,000
Stock options
401K matching
Flexible PTO
+2
VP of Governance, Risk & Compliance
VP of Governance, Risk & Compliance

Tiro Security • Los Angeles (CA)

Hybrid
USD 200,000 - 280,000
Hybrid GRC Lead for Regulated Compliance & Audit
Hybrid GRC Lead for Regulated Compliance & Audit

Acuren Inspection, Inc. • Houston (TX)

Hybrid
USD 120,000 - 170,000
Senior GRC Leader: Governance, Risk & Compliance Strategy
Senior GRC Leader: Governance, Risk & Compliance Strategy

Brobston Group LLC • Seattle (WA)

On-site
USD 180,000 - 260,000
GRC Program Lead – Security, Privacy & Compliance
GRC Program Lead – Security, Privacy & Compliance

Doppel • New York (NY)

On-site
USD 170,000 - 190,000
Senior GRC Lead: AI Governance & Compliance (Remote)
Senior GRC Lead: AI Governance & Compliance (Remote)

Mixpeek • Northern (KY)

Hybrid
USD 174,000 - 205,000
Health, Dental & Vision coverage
401(k) with company match
Equity grant participation
+5
GRC Risk & Compliance Manager | Equity & Impact
GRC Risk & Compliance Manager | Equity & Impact

WHOOP • Boston (MA)

On-site
USD 155,000 - 195,000