GRC Program Manager

Tandem Inc.

Draper (UT)

Hybrid

USD 110,000 - 170,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

On-site gym
Flexible PTO
Redo perks: monthly ecommerce credit
Company HSA contributions
Weekly team lunches

Job summary

Redo is seeking a Senior GRC Program Manager to own and scale governance, risk, and compliance across SOC 2, GDPR, CCPA, PCI, and HIPAA. You will translate framework requirements with engineering, lead audits, and partner with sales on security reviews to close deals.

You will build and enforce security policies, manage vendor risk, and drive continuous compliance with AI-enabled automation, all while advocating for security at a rapidly growing ecommerce platform.

Qualifications

  • 5+ years in GRC, security compliance, or related role with hands-on ownership of a full program.
  • Experience leading a SOC 2 certification and ongoing surveillance.
  • Depth in GDPR/data privacy obligations for SaaS platforms.
  • Experience in HIPAA and PCI environments.
  • Able to translate control requirements into engineering actions and collaborate with software engineers.
  • Experience responding to customer security reviews and security questionnaires.
  • Strong writing and communication skills for policies and security posture explanations.
  • Experience using AI for automating compliance activities.

Responsibilities

  • Own, mature, and scale the GRC program end to end (SOC 2, GDPR, CCPA, PCI, HIPAA).
  • Translate framework and control requirements into actionable engineering requirements.
  • Lead audits, manage auditor relationships, and collect evidence.
  • Support security reviews and questionnaires to accelerate sales deals.
  • Develop and maintain security policies, standards, and procedures across the company.
  • Oversee third-party/vendor risk management and GRC tooling.
  • Drive AI-enabled automation for evidence collection and monitoring.

Skills

GRC ownership
SOC 2 experience
GDPR/data privacy
HIPAA/PCI experience
engineering collaboration
security questionnaires
AI for compliance
writing/communication

Tools

Vanta
Drata
Secureframe

Job description

GRC Program Manager

Draper, UT, United States
Full Time
Senior

About Redo
Redo is an e-commerce growth platform. We help merchants personalize every step of the buyer journey to maximize profit and lifetime value, with solutions spanning returns, warranties, order tracking, and post-purchase communications. We're growing fast, moving quickly, and building the systems that let some of the best brands in commerce trust us with their customers.
About the Role
Security and compliance are core to how Redo operates and how our merchants trust us with their customers. We're growing explosively, and as we scale, we're investing in a dedicated owner to take our governance, risk, and compliance program to the next level — and that's where you come in.
Redo is growing fast, which makes this a rare blue-ocean opportunity to own GRC end to end. This isn't a box-checking role — it's a chance to drive real impact and influence across the organization. You'll deepen and expand our compliance across SOC 2, GDPR, CCPA, and the frameworks that come next, setting the strategy, owning the execution, and shaping how security is built into the company as we grow. You'll also work directly with our merchants, where a strong security story helps close deals.
You'll partner shoulder-to-shoulder with engineering to turn compliance requirements into concrete controls, keep us audit-ready as we scale, and be the person our merchants trust when they run a security review. We're looking for a seasoned practitioner who can operate independently and be the go-to expert on all things GRC.
If you want ownership, visible impact, and the chance to shape a maturing security program at a fast-growing company, this is it.

What You’ll Do
  • Own, mature, and scale Redo's GRC program end to end — SOC 2, GDPR, CCPA, PCI, and HIPAA and additional frameworks as our merchant base demands them.
  • Partner closely with engineering to translate framework and control requirements into clear, actionable technical and engineering requirements — and make sure they get implemented and stay implemented.
  • Own audit readiness: lead audits and assessments, manage auditor relationships, and run evidence collection and continuous control monitoring.
  • Lead compliance sales enablement by responding to merchant and prospect security reviews — questionnaires, due‑diligence requests, and trust/security documentation — and turn it into a low friction process that smooths sales deals.
  • Build and maintain security policies, standards, and procedures, and drive their adoption across the company.
  • Manage third‑party/vendor risk management.
  • Own our GRC tooling and automation, and drive continuous compliance rather than point‑in‑time scrambles.
  • Lead AI enablement of the compliance program — put AI to work automating evidence collection, control monitoring, security‑questionnaire responses, and documentation so the program scales faster than headcount.
  • Manage access reviews, security awareness training, and evidence of ongoing operating effectiveness.
  • Keep leadership informed on compliance posture, gaps, and progress, and represent Redo's security program to customers and partners.
What We're Looking For
  • 5+ years in GRC, security compliance, or a closely related role, with hands‑on ownership (not just support) of at least one full compliance program.
  • Demonstrated experience taking a company through a full SOC 2 certification and continued surveillance.
  • Depth of experience helping SaaS platforms support GDPR and data privacy obligations.
  • Experience navigating HIPAA and PCI environments.
  • A self‑directed operator who can own and mature a program with minimal oversight — you know what "good" looks like and can drive it independently.
  • Ability to translate control requirements into engineering requirements and to collaborate credibly with software engineers.
  • Experience responding to customer security reviews and security questionnaires.
  • Strong writing and communication skills — you can produce clear policies and explain security posture to both engineers and non‑technical stakeholders.
  • Comfortable in a fast‑moving, high‑growth environment where you set the pace.
  • Experience using AI for custom compliance automation
Nice to Have
  • Relevant certifications such as CISA, CISSP, ISO 27001 Lead Implementer/Auditor, or CIPP/E.
  • Experience with GRC automation platforms (e.g., Vanta, Drata, Secureframe).
Benefits
  • Work with a dynamic, innovative team in the fast‑growing ecommerce industry
  • Opportunities for career growth and advancement
  • On‑site gym with showers, pickleball, and basketball
  • Flexible PTO & company holidays
  • Redo perks: monthly allowance to support purchases from ecommerce stores
  • Company HSA contributions
  • Weekly lunches & fully stocked break room
  • $100 monthly babysitting reimbursement
  • Office is minutes from biking and running trails

Redo is an equal opportunity employer and prohibits discrimination and harassment of any kind. We are committed to creating a diverse and inclusive work environment where all employees feel valued, respected, and supported.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Program Manager
GRC Program Manager

Tandem Ventures • Draper (UT)

On-site
USD 140,000 - 180,000
On-site gym
Flexible PTO
Company holidays
+3
Head of IT
Head of IT

Tandem Ventures • Salt Lake City (UT)

On-site
USD 180,000 - 230,000
On-site gym
Flexible PTO
Company holidays
+3
Senior GRC Program Manager for SaaS Security & Privacy
Senior GRC Program Manager for SaaS Security & Privacy

Tandem Ventures • Draper (UT)

On-site
USD 140,000 - 180,000
On-site gym
Flexible PTO
Company holidays
+3
Talent Architect
Talent Architect

Uniting Holding • Draper (UT)

On-site
USD 75,000 - 95,000
On-site gym
Flexible PTO
Company HSA contributions
+1
Head of IT
Head of IT

Tandem Inc. • Salt Lake City (UT), Northern (KY)

Hybrid
USD 150,000 - 210,000
On-site gym with showers
Pickleball facilities
Basketball facilities
+2
Talent Architect
Talent Architect

Tandem Inc. • Draper (UT)

On-site
USD 70,000 - 90,000
On-site gym
Flexible PTO
Monthly e-commerce allowance
+2
Risk and Compliance Lead
Risk and Compliance Lead

Replit • Foster City (CA)

On-site
USD 180,000 - 240,000
401(k) program
Health insurance
Dental insurance
+10
Risk and Compliance Lead
Risk and Compliance Lead

Replit • United States

On-site
USD 180,000 - 240,000
401(k) program
Health, dental, vision, life insurance
Short and long-term disability
+8
IT Specialist
IT Specialist

Tandem Inc. • Draper (UT)

On-site
USD 55,000 - 75,000
Flexible PTO
Weekly lunches
On-site gym
Director, GRC & Privacy Security
Director, GRC & Privacy Security

Jobtailor • New York (NY)

On-site
USD 130,000 - 160,000
Competitive salary & equity
Unlimited PTO
Full Health, Vision, & Dental coverage
+2