GRC Program Manager

Tandem Ventures

Draper (UT)

On-site

USD 140,000 - 180,000

Full time

38 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

On-site gym
Flexible PTO
Company holidays
Monthly ecommerce allowance
HSA contributions
Weekly lunches

Job summary

Redo is an e-commerce growth platform headquartered in Draper, Utah. We are seeking a seasoned GRC leader to own governance, risk, and compliance—driving SOC 2, GDPR/CCPA, HIPAA, and PCI programs end-to-end with minimal oversight.

You will partner with engineering to translate requirements into controls and ensure audit readiness across the organization. The role demands a self-directed operator who can influence security posture while collaborating with merchants and cross-functional teams in a

Qualifications

  • 5+ years in GRC, security compliance, or a closely related role, with hands-on ownership of at least one full compliance program.
  • Demonstrated experience taking a company through a full SOC 2 certification and continued surveillance.
  • Depth of experience helping SaaS platforms support GDPR and data privacy obligations.
  • Experience navigating HIPAA and PCI environments.
  • A self-directed operator who can own and mature a program with minimal oversight — you know what 'good' looks like and can drive it independently.
  • Ability to translate control requirements into engineering requirements and to collaborate credibly with software engineers.
  • Experience responding to customer security reviews and security questionnaires.
  • Strong writing and communication skills — you can produce clear policies and explain security posture to both engineers and non-technical stakeholders.
  • Comfortable in a fast-moving, high-growth environment where you set the pace.
  • Experience using AI for custom compliance automation

Responsibilities

  • Own governance, risk, and compliance program end-to-end as Redo scales.
  • Collaborate with engineering to translate compliance requirements into concrete controls.
  • Maintain audit readiness and lead security reviews with merchants.
  • Serve as go-to expert on GRC and security posture across the organization.

Job description

About RedoRedo is an e-commerce growth platform. We help merchants personalize every step of the buyer journey to maximize profit and lifetime value, with solutions spanning returns, warranties, order tracking, and post-purchase communications. We're growing fast, moving quickly, and building the systems that let some of the best brands in commerce trust us with their customers.

Draper, UT, United States

Full Time

Senior

About Redo

Redo is an e-commerce growth platform. We help merchants personalize every step of the buyer journey to maximize profit and lifetime value, with solutions spanning returns, warranties, order tracking, and post-purchase communications. We're growing fast, moving quickly, and building the systems that let some of the best brands in commerce trust us with their customers.

About The Role

Security and compliance are core to how Redo operates and how our merchants trust us with their customers. We're growing explosively, and as we scale, we're investing in a dedicated owner to take our governance, risk, and compliance program to the next level — and that's where you come in.

Redo is growing fast, which makes this a rare blue-ocean opportunity to own GRC end to end. This isn't a box-checking role — it's a chance to drive real impact and influence across the organization. You'll deepen and expand our compliance across SOC 2, GDPR, CCPA, and the frameworks that come next, setting the strategy, owning the execution, and shaping how security is built into the company as we grow. You'll also work directly with our merchants, where a strong security story helps close deals.

You'll partner shoulder-to-shoulder with engineering to turn compliance requirements into concrete controls, keep us audit-ready as we scale, and be the person our merchants trust when they run a security review. We're looking for a seasoned practitioner who can operate independently and be the go-to expert on all things GRC.

If you want ownership, visible impact, and the chance to shape a maturing security program at a fast-growing company, this is it.

What We're Looking For
  • 5+ years in GRC, security compliance, or a closely related role, with hands-on ownership (not just support) of at least one full compliance program.
  • Demonstrated experience taking a company through a full SOC 2 certification and continued surveillance.
  • Depth of experience helping SaaS platforms support GDPR and data privacy obligations.
  • Experience navigating HIPAA and PCI environments.
  • A self-directed operator who can own and mature a program with minimal oversight — you know what "good" looks like and can drive it independently.
  • Ability to translate control requirements into engineering requirements and to collaborate credibly with software engineers.
  • Experience responding to customer security reviews and security questionnaires.
  • Strong writing and communication skills — you can produce clear policies and explain security posture to both engineers and non-technical stakeholders.
  • Comfortable in a fast-moving, high-growth environment where you set the pace.
  • Experience using AI for custom compliance automation
Nice to Have
  • Relevant certifications such as CISA, CISSP, ISO 27001 Lead Implementer/Auditor, or CIPP/E.
  • Experience with GRC automation platforms (e.g., Vanta, Drata, Secureframe).
Benefits
  • Work with a dynamic, innovative team in the fast-growing ecommerce industry
  • Opportunities for career growth and advancement
  • On-site gym with showers, pickleball, and basketball
  • Flexible PTO & company holidays
  • Redo perks: monthly allowance to support purchases from ecommerce stores
  • Company HSA contributions
  • Weekly lunches & fully stocked break room
  • $100 monthly babysitting reimbursement
  • Office is minutes from biking and running trails

Redo is an equal opportunity employer and prohibits discrimination and harassment of any kind. We are committed to creating a diverse and inclusive work environment where all employees feel valued, respected, and supported.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Program Manager
GRC Program Manager

Tandem Inc. • Draper (UT)

Hybrid
USD 110,000 - 170,000
On-site gym
Flexible PTO
Redo perks: monthly ecommerce credit
+2
Head of IT
Head of IT

Tandem Ventures • Salt Lake City (UT)

On-site
USD 180,000 - 230,000
On-site gym
Flexible PTO
Company holidays
+3
Senior GRC Program Manager for SaaS Security & Privacy
Senior GRC Program Manager for SaaS Security & Privacy

Tandem Ventures • Draper (UT)

On-site
USD 140,000 - 180,000
On-site gym
Flexible PTO
Company holidays
+3
Talent Architect
Talent Architect

Uniting Holding • Draper (UT)

On-site
USD 75,000 - 95,000
On-site gym
Flexible PTO
Company HSA contributions
+1
Head of IT
Head of IT

Tandem Inc. • Salt Lake City (UT), Northern (KY)

Hybrid
USD 150,000 - 210,000
On-site gym with showers
Pickleball facilities
Basketball facilities
+2
Talent Architect
Talent Architect

Tandem Inc. • Draper (UT)

On-site
USD 70,000 - 90,000
On-site gym
Flexible PTO
Monthly e-commerce allowance
+2
IT Specialist
IT Specialist

Tandem Inc. • Draper (UT)

On-site
USD 55,000 - 75,000
Flexible PTO
Weekly lunches
On-site gym
Account Executive [Conversions, Marketing Cloud, OMS]
Account Executive [Conversions, Marketing Cloud, OMS]

Tandem Inc. • Draper (UT)

On-site
USD 70,000 - 100,000
Medical coverage starting at $20/mo
Flexible PTO & 7 company holidays
$100/month childcare reimbursement
+1
IT Specialist
IT Specialist

Uniting Holding • Draper (UT)

On-site
USD 60,000 - 80,000
Career growth opportunities
On-site gym and sports facilities
Flexible PTO
+4
Product Marketer
Product Marketer

Cervin • Draper (UT)

On-site
USD 80,000 - 100,000
Dynamic team environment
Career growth opportunities
On-site gym
+6