GRC Program Manager

Mintlify

San Francisco (CA)

On-site

USD 120,000 - 170,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

20 days paid time off every year
401k or RRSP
$420/month wellness stipend
100% coverage for Health, dental, vizn
Free Ubers to and from the Mintlify办公室
Free lunch and dinners while working
Annual team offsite

Job summary

Mintlify in San Francisco seeks a GRC Program Manager to own the security and compliance program supporting our enterprise business. You will manage audits, evidence collection, and remediation, with Drata as the backbone of evidence, policies, and trust center.

You’ll coordinate with auditors, vendors, and engineering DRIs, ensuring timely deliverables and containment of any audit findings. This role requires hands-on platform administration and a bias toward automation, in a fast-growing

Qualifications

  • 3+ years in GRC / compliance program management / security operations with direct audit ownership
  • Hands-on compliance-platform administration (Drata, Vanta, or similar)
  • Vendor and auditor relationship management as the accountable owner
  • Meticulous follow-through — a dropped thread is an audit finding
  • Bias toward automation and pushing work to tests/vendors rather than doing it manually forever
  • Bonus Points: ISO 42001 / AI governance exposure; GDPR operations; startup experience as sole compliance owner

Responsibilities

  • Run five compliance programs end-to-end — own the audit calendar, evidence collection, remediation tracking, and auditor relationships (Sensiba for SOC 2/ISO; A-LIGN for Microsoft SSPA)
  • Administer Drata — keep monitors green, assign and validate evidence, manage policies and the trust center
  • Own the vendor bench — drive the weekly Rhymetec vCISO engagement, manage renewals and contracts across the security/compliance vendor portfolio
  • Run the standing processes — security questionnaire escalation, inbound vendor security reviews, bug bounty coordination (triage, researcher comms, payouts), trainings and access-review cadences
  • Be the customer-facing compliance voice — trust center, DPAs, subprocessor list, and enterprise security requirements (Microsoft, Coinbase, Okta-style programs)
  • Coordinate, don’t silo — route technical work to Engineering DRIs with clear asks, and keep leadership out of the coordination loop

Skills

GRC
Compliance
Audits
Security Operations
Policy

Tools

Drata
Vanta

Job description

Why Mintlify?

We're on a mission to empower builders. Massive reach: Our docs platform serves 100 million+ developers every year and powers documentation for 20,000+ companies, including Anthropic, Microsoft, PayPal, Spotify, Coinbase, X, and over 20% of the last YC batch. Small team, huge impact: We recently passed 65 employees and raised a $45 million Series B led by A16Z and Salesforce Ventures. Each new hire has a huge impact on shaping the company's trajectory. Culture of slope over y-intercept: We value learning velocity, grit, and unapologetically unique personalities. We grew in value faster than headcount and we’re looking to align the two quickly.

The Role

We're hiring our first dedicated GRC Program Manager to own the security & compliance program that our enterprise business runs on: SOC 2 Type II, ISO 27001, ISO 42001, GDPR, and Microsoft SSPA. The program exists and is well-documented — audits are mid-flight, the vCISO and auditors are engaged, the platform (Drata) is deployed. What it needs is a single accountable operator.

What You'll Do
  • Run five compliance programs end-to-end — own the audit calendar, evidence collection, remediation tracking, and auditor relationships (Sensiba for SOC 2/ISO; A-LIGN for Microsoft SSPA)
  • Administer Drata — keep monitors green, assign and validate evidence, manage policies and the trust center
  • Own the vendor bench — drive the weekly Rhymetec vCISO engagement, manage renewals and contracts across the security/compliance vendor portfolio
  • Run the standing processes — security questionnaire escalation, inbound vendor security reviews, bug bounty coordination (triage, researcher comms, payouts), trainings and access-review cadences
  • Be the customer-facing compliance voice — trust center, DPAs, subprocessor list, and enterprise security requirements (Microsoft, Coinbase, Okta-style programs)
  • Coordinate, don't silo — route technical work to Engineering DRIs with clear asks, and keep leadership out of the coordination loop
What We're Looking For
  • 3+ years in GRC / compliance program management / security operations with direct audit ownership
  • Hands-on compliance-platform administration (Drata, Vanta, or similar)
  • Vendor and auditor relationship management as the accountable owner
  • Meticulous follow-through — in this job, a dropped thread is an audit finding
  • Bias toward automation and pushing work to tests/vendors rather than doing it manually forever
  • Bonus Points: ISO 42001 / AI governance exposure. GDPR operations (DSARs, RoPA, consent tooling). Early-stage startup experience as a sole compliance owner.
Company Benefits
  • Competitive compensation and equity
  • 20 days paid time off every year
  • 401k or RRSP
  • $420/month wellness stipend
  • 100% coverage for Health, dental, vision (within the US)
  • Free Ubers to and from the Mintlify office
  • Free lunch and dinners while working at the Mintlify office
  • Annual team offsite (previously went to Alaska, Hawaii)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security & Compliance Operations Manager San Francisco
Security & Compliance Operations Manager San Francisco

Mintlify, Inc. • San Francisco (CA)

On-site
USD 160,000 - 220,000
Competitive compensation and equity
20 days paid time off
401k
+5
Director, GRC & Privacy Security
Director, GRC & Privacy Security

Jobtailor • New York (NY)

On-site
USD 130,000 - 160,000
Competitive salary & equity
Unlimited PTO
Full Health, Vision, & Dental coverage
+2
GRC Lead
GRC Lead

BrainCo • San Francisco (CA)

On-site
USD 180,000 - 260,000
Competitive salary and equity
Daily lunches
Commuter benefits
+3
GRC Engineer
GRC Engineer

Antithesis • Vienna (VA)

On-site
USD 110,000 - 170,000
GRC Lead: AI Compliance & Security Architect
GRC Lead: AI Compliance & Security Architect

BrainCo • San Francisco (CA)

On-site
USD 180,000 - 260,000
GRC Program Manager - Enterprise Compliance Leader
GRC Program Manager - Enterprise Compliance Leader

Socket.dev • San Francisco (CA)

On-site
USD 120,000 - 170,000
20 days paid time off every year
401k or RRSP
$420/month wellness stipend
+4
GRC Engineer - Platform Team
GRC Engineer - Platform Team

Taktile • United States

On-site
USD 120,000 - 180,000
Equity
Cash compensation
Self-development budget
+1
Risk and Compliance Lead
Risk and Compliance Lead

Replit • Foster City (CA)

On-site
USD 180,000 - 240,000
401(k) program
Health insurance
Dental insurance
+10
Risk and Compliance Lead
Risk and Compliance Lead

Replit • United States

On-site
USD 180,000 - 240,000
401(k) program
Health, dental, vision, life insurance
Short and long-term disability
+8
GRC Program Manager
GRC Program Manager

Tandem Inc. • Draper (UT)

Hybrid
USD 110,000 - 170,000
On-site gym
Flexible PTO
Redo perks: monthly ecommerce credit
+2