Senior GRC Program Lead - SOC 2, GDPR & Security

Tandem Inc.

Draper (UT)

Hybrid

USD 110,000 - 170,000

Full time

10 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

On-site gym
Flexible PTO
Redo perks: monthly ecommerce credit
Company HSA contributions
Weekly team lunches

Job summary

Redo is seeking a Senior GRC Program Manager to own and scale governance, risk, and compliance across SOC 2, GDPR, CCPA, PCI, and HIPAA. You will translate framework requirements with engineering, lead audits, and partner with sales on security reviews to close deals.

You will build and enforce security policies, manage vendor risk, and drive continuous compliance with AI-enabled automation, all while advocating for security at a rapidly growing ecommerce platform.

Qualifications

  • 5+ years in GRC, security compliance, or related role with hands-on ownership of a full program.
  • Experience leading a SOC 2 certification and ongoing surveillance.
  • Depth in GDPR/data privacy obligations for SaaS platforms.
  • Experience in HIPAA and PCI environments.
  • Able to translate control requirements into engineering actions and collaborate with software engineers.
  • Experience responding to customer security reviews and security questionnaires.
  • Strong writing and communication skills for policies and security posture explanations.
  • Experience using AI for automating compliance activities.

Responsibilities

  • Own, mature, and scale the GRC program end to end (SOC 2, GDPR, CCPA, PCI, HIPAA).
  • Translate framework and control requirements into actionable engineering requirements.
  • Lead audits, manage auditor relationships, and collect evidence.
  • Support security reviews and questionnaires to accelerate sales deals.
  • Develop and maintain security policies, standards, and procedures across the company.
  • Oversee third-party/vendor risk management and GRC tooling.
  • Drive AI-enabled automation for evidence collection and monitoring.

Skills

GRC ownership
SOC 2 experience
GDPR/data privacy
HIPAA/PCI experience
engineering collaboration
security questionnaires
AI for compliance
writing/communication

Tools

Vanta
Drata
Secureframe

Job description

Redo is seeking a Senior GRC Program Manager to own and scale governance, risk, and compliance across SOC 2, GDPR, CCPA, PCI, and HIPAA. You will translate framework requirements with engineering, lead audits, and partner with sales on security reviews to close deals.

You will build and enforce security policies, manage vendor risk, and drive continuous compliance with AI-enabled automation, all while advocating for security at a rapidly growing ecommerce platform.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior GRC Program Manager for SaaS Security & Privacy
Senior GRC Program Manager for SaaS Security & Privacy

Tandem Ventures • Draper (UT)

On-site
USD 140,000 - 180,000
On-site gym
Flexible PTO
Company holidays
+3
Remote GRC & Security Compliance Lead
Remote GRC & Security Compliance Lead

PVH (Tommy Hilfiger/Calvin Klein) • United States

On-site
USD 140,000 - 210,000
Remote-first environment
Annual team summits
Unlimited PTO
+2
GRC Lead for AI Security: SOC 2 & ISO 27001
GRC Lead for AI Security: SOC 2 & ISO 27001

Replit • Foster City (CA)

On-site
USD 180,000 - 240,000
401(k) program
Health insurance
Dental insurance
+10
Senior GRC & Privacy Compliance Analyst
Senior GRC & Privacy Compliance Analyst

United States Digital Space LLC • San Francisco (CA)

On-site
USD 120,000 - 180,000
Senior GRC & Compliance Strategist
Senior GRC & Compliance Strategist

B Capital • San Francisco (CA)

On-site
USD 140,000 - 200,000
GRC & Security Compliance Lead
GRC & Security Compliance Lead

Neura Market • San Francisco (CA)

On-site
USD 140,000 - 190,000
Equity
Medical, dental, and vision coverage
Flexible PTO
+4
GRC Engineering Manager: Lead Secure Cloud Compliance
GRC Engineering Manager: Lead Secure Cloud Compliance

Workstreet • Northern (KY)

Hybrid
USD 150,000 - 190,000
Career Development
Role-Related Training
Competitive Compensation
+2
GRC Lead – SOC 2 & ISO 27001 Risk Champion
GRC Lead – SOC 2 & ISO 27001 Risk Champion

Replit • United States

On-site
USD 180,000 - 240,000
401(k) program
Health, dental, vision, life insurance
Short and long-term disability
+8
Senior GRC Engineer - Automate Compliance & Risk
Senior GRC Engineer - Automate Compliance & Risk

laptop-battery • San Francisco (CA)

On-site
USD 180,000 - 200,000
Medical coverage
Flexible PTO
Wellness reimbursement
+2
Senior GRC Director: FedRAMP, ISO 27001 & SOC 2 Lead
Senior GRC Director: FedRAMP, ISO 27001 & SOC 2 Lead

Anomali • Redwood City (CA)

Hybrid
USD 180,000 - 230,000