Security Compliance Program Lead: SOC 2, HITRUST & ISO

Jobtailor

California (MO)

On-site

USD 130,000 - 165,000

Full time

7 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Jobtailor is seeking a Senior GRC/Compliance Lead to own end-to-end certification programs (SOC 2, HITRUST, ISO 27001) and drive audit calendars in a fast-paced SaaS environment. You will coordinate with Engineering, IT, HR, Legal, andSales to gather evidence, close findings, and translate regulatory changes into control updates.

The role requires 6+ years in GRC or IT audit, direct ownership of at least one audit cycle, and strong communications.

Qualifications

  • 6+ years of experience in GRC, information security compliance, or IT audit.
  • Direct ownership of at least one SOC 2 or similar audit cycle from start to finish.
  • Working knowledge of SOC 2, HITRUST, and ISO 27001 frameworks.
  • Experience responding to customer security questionnaires/RFIs, ideally in a B2B SaaS or healthcare-adjacent environment.
  • Strong cross-team collaboration skills.
  • Project management skills, including sequencing overlapping audits and certification projects, tracking dependencies and remediation items, and meeting deadlines.
  • Strong written communication skills for policies, RFI responses, and audit narratives.
  • Strongly preferred: experience establishing new certifications such as SOC 2, HITRUST, ISO 27001, or ISO 42001.
  • Strongly preferred: experience with GRC/compliance automation tools such as Vanta, Drata, Secureframe, or Hyperproof.
  • Strongly preferred: background in health tech, digital health, fintech, insurtech, or another regulated B2B vertical.
  • Strongly preferred: CISA, CRISC, CISSP, PMP, CAPM, CISM, or CTRC/CAP certification.
  • Strongly preferred: exposure to vulnerability management or IT operations.
  • Strongly preferred: experience partnering with Sales or Sales Engineering as a technical or compliance resource.

Responsibilities

  • Demonstrates expertise in managing SOC 2, HITRUST, and ISO certification processes, including audit preparation and compliance management.
  • Possesses strong project management and cross-team collaboration skills to effectively coordinate with various stakeholders and ensure adherence to regulatory requirements.

Skills

GRC
Information Security
IT Audit
SOC 2
HITRUST
ISO 27001
Control Mapping
Audit Calendar Management
Regulatory Tracking
Security Questionnaire Management
Policy Adherence
Cross-Team Collaboration
Project Management
Written Communication
SOC 2/Audit Ownership

Tools

Vanta
Drata
Secureframe
Hyperproof

Job description

Jobtailor is seeking a Senior GRC/Compliance Lead to own end-to-end certification programs (SOC 2, HITRUST, ISO 27001) and drive audit calendars in a fast-paced SaaS environment. You will coordinate with Engineering, IT, HR, Legal, andSales to gather evidence, close findings, and translate regulatory changes into control updates.

The role requires 6+ years in GRC or IT audit, direct ownership of at least one audit cycle, and strong communications.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior GRC & Compliance Strategist
Senior GRC & Compliance Strategist

Jobtailor • Kansas

On-site
USD 70,000 - 90,000
Senior Cloud GRC Analyst - Salesforce Compliance & Audits
Senior Cloud GRC Analyst - Salesforce Compliance & Audits

Jobtailor • California (MO)

On-site
USD 120,000 - 170,000
Security GRC Lead - SOC 2, ISO 27001 & HIPAA Programs
Security GRC Lead - SOC 2, ISO 27001 & HIPAA Programs

Jobtailor • South San Francisco (CA)

On-site
USD 170,000 - 210,000
GRC Lead: Compliance, Risk & Vendor Oversight
GRC Lead: Compliance, Risk & Vendor Oversight

Jobtailor • Houston (TX)

On-site
USD 120,000 - 180,000
Client-Facing Project Lead, GRC & SOC2/HITRUST
Client-Facing Project Lead, GRC & SOC2/HITRUST

Jobtailor • Atlanta (GA)

On-site
USD 90,000 - 120,000
Chief Enterprise GRC & Security Risk Leader
Chief Enterprise GRC & Security Risk Leader

Jobtailor • Illinois

On-site
USD 180,000 - 240,000
Senior SaaS Security & Compliance Strategist
Senior SaaS Security & Compliance Strategist

Jobtailor • Burlington (MA)

On-site
USD 120,000 - 165,000
Senior GRC Lead for AI – End-to-End Certifications & Audits
Senior GRC Lead for AI – End-to-End Certifications & Audits

Thinking Machines Lab • San Francisco (CA)

On-site
USD 225,000 - 350,000
Health, dental, and vision benefits
Unlimited PTO
Parental leave
+1
Senior GRC & Compliance Leader (SOC 2)
Senior GRC & Compliance Leader (SOC 2)

Triwill Group • San Francisco (CA), Northern (KY)

Hybrid
USD 183,000 - 205,000
Stock equity
GRC Lead: AI Compliance Certifications (SOC 2, ISO 27001)
GRC Lead: AI Compliance Certifications (SOC 2, ISO 27001)

Thinking Machines Lab Inc. • San Francisco (CA), Northern (KY)

Hybrid
USD 225,000 - 350,000
Health, dental, and vision benefits
Unlimited PTO
Paid parental leave
+1