GRC Lead

Hightouch

United States

Remote

USD 160,000 - 230,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Equity compensation

Job summary

Hightouch is seeking a GRC Lead to own our customer security assurance and compliance program. You will drive audits, risk management, and evidence collection, coordinating with engineering, security, IT, legal, and customer-facing teams with high autonomy.

This senior role emphasizes impact and growth, leveraging AI-assisted workflows to accelerate reviews. Remote-first across North America, with meaningful equity compensation included.

Qualifications

  • Must have owned a compliance program or major audit cycle.
  • Hands-on experience with customer security reviews.
  • Ability to build AI-assisted workflows and verify complex details.

Responsibilities

  • Own customer security reviews, including questionnaires and calls.
  • Drive practical risk decisions with cross-functional teams and clear ownership.
  • Maintain approved responses and evidence across products and configurations.
  • Own SOC 2 and ISO 27001 programs, including audits and evidence collection.
  • Track commitments and automate repetitive work to reduce questions.

Skills

Judgment
Technical curiosity
AI fluency
Clear writing
Ownership & urgency
Builder's approach

Job description

GRC Lead

Remote (North America)

About the Role

We're hiring our first dedicated GRC Lead to own customer security assurance and our compliance program. Your first priority will be making customer security reviews fast and accurate, alongside ownership of audits, compliance obligations, and risk follow-through.

We build quickly, and this role requires someone who can keep pace. You'll understand the risks behind customer requirements, make practical recommendations, and drive decisions through to completion. You'll have substantial autonomy and work directly with engineering, security, IT, legal, and our customer-facing teams.

We're open to experienced individual contributors, managers who enjoy hands-on work, and people looking to grow into management. You'll initially handle questionnaires, customer conversations, and audits directly, using AI and automation to increase what a small team can accomplish. As the function grows you'll be able to grow with it.

What You'll Own
  • Customer security reviews. Own questionnaires, due diligence, and customer security calls. Use AI to accelerate research and drafting, apply your own judgment to ensure precision, and resolve unfamiliar questions with the right technical experts.

  • Practical risk decisions. Help teams work through customer security requirements, vendor concerns, and compliance gaps. Understand what's at stake, bring the right people together, and make sure decisions have clear owners and follow-through.

  • Reliable security answers. Maintain approved responses and supporting evidence. Use AI to surface inconsistencies and outdated information, and ensure answers accurately reflect differences across products, configurations, and planned capabilities.

  • Compliance strategy and audits. Own our SOC 2 and ISO 27001 programs, set priorities for external partners, assess their work, and close gaps. Ensure controls remain effective between audits, reuse controls across frameworks, and automate evidence collection. Evaluate new programs based on customer demand, the markets we want to enter, and the cost to implement and maintain them.

  • Execution and follow-through. Track commitments and remediation with clear owners and deadlines. Build automation and self-service resources that reduce repetitive work, and turn recurring customer questions into improvements to documentation, controls, and product.

About You

You've personally owned a compliance program or major audit cycle, and have hands-on experience with customer security reviews.

You Bring:
  • Judgment. You can describe tradeoffs you've made, the risks you accepted or escalated, and why those decisions were reasonable.

  • Technical curiosity. You dig into how systems work and can discuss data flows, access controls, cloud infrastructure, and data storage with engineers.

  • AI fluency and attention to detail. You build AI-assisted workflows and catch convincing but unsupported answers. You know which details materially change a claim and how to verify them.

  • Clear writing and credible customer communication. You explain our security posture accurately, including when the answer is complicated or a capability doesn't yet exist.

  • Ownership and urgency. You make progress with incomplete information, communicate clearly, and close loops without repeated prompting.

  • A builder's approach. You've simplified a process, automated recurring work, or found a faster way to satisfy a requirement—and can explain the result.

This is a senior role, but we focus on impact and potential for growth more than years of experience. The salary range for this position is $160,000 to 230,000 USD per year, which is location independent in accordance with our remote-first policy. We also offer meaningful equity compensation.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

GRC Lead
GRC Lead

Hightouch • San Francisco (CA)

On-site
USD 160,000 - 230,000
GRC Engineer
GRC Engineer

Aegis AI • United States

On-site
USD 120,000 - 180,000
Security GRC Engineer
Security GRC Engineer

Cursor • Palo Alto (CA)

On-site
USD 180,000 - 240,000
Entry Level GRC Analyst
Entry Level GRC Analyst

Hotman Group • United States

On-site
USD 55,000 - 75,000
Senior GRC Lead - Remote, Impact & Equity
Senior GRC Lead - Remote, Impact & Equity

Hightouch • United States

Remote
USD 160,000 - 230,000
Equity compensation
GRC Manager
GRC Manager

Mattermost • United States

On-site
USD 120,000 - 190,000
GRC Manager
GRC Manager

Glocomms • San Francisco (CA)

On-site
USD 120,000 - 180,000
Full Health Benefits
Equity participation
Relocation Support
+1
Security Engineer, GRC
Security Engineer, GRC

Candid Health • San Francisco (CA)

On-site
USD 140,000 - 200,000
Group Security & Compliance Manager ($60,000/year USD), Sparkrock
Group Security & Compliance Manager ($60,000/year USD), Sparkrock

Ionic Partners, LLC • United States

Remote
USD 140,000 - 210,000
100% remote and global
Stipend for home office
Flexible work hours
+2
Security Assurance & GRC Lead
Security Assurance & GRC Lead

Wispr Flow • San Francisco (CA)

On-site
USD 150,000 - 190,000