Senior Security GRC Lead

Gong

Austin (CO)

Hybrid

USD 121,000 - 185,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, dental, and vision plans
Flexible wellness stipend
401(k) program
Education & learning stipend
Paid parental leave

Job summary

Gong is seeking a Senior GRC Security Lead to architect foundational security and compliance programs. This high-impact role will involve creating Gong's first Common Controls Framework and engagement with various teams to ensure compliance across multiple regulatory standards.

The ideal candidate will have over 7 years of experience in GRC, with a strong background in building programs at high-growth companies. Benefits include flexible vacation, a wellbeing fund, and comprehensive medical coverage, among others.

Qualifications

  • 7+ years of experience in GRC or Information Security.
  • Hands-on experience building a GRC program at scale.
  • Deep expertise in compliance frameworks including SOC 2 and ISO 27001.

Responsibilities

  • Design and implement Gong’s Common Controls Framework.
  • Partner with Engineering to embed controls in architecture.
  • Serve as subject-matter expert during audits and sales engagements.
  • Create and maintain risk treatment plans across the business.

Skills

GRC program building
Information Security expertise
Policy writing
Risk assessment management
Stakeholder communication

Education

Bachelor’s degree in Information Security or related field

Tools

GRC tooling

Job description

Company Overview

Gong harnesses the power of AI to transform how revenue teams win. The Gong Revenue AI Operating System unifies data, insights, and workflows into a single, trusted system that observes, guides, and acts alongside the world’s most successful revenue teams. Powered by the Gong Revenue Graph, AI‑powered intelligence, specialized agents, and trusted applications, Gong helps more than 5,000 companies around the world deeply understand their teams and customers, automate critical sales workflows, and close more deals with less effort. For more information, visit www.gong.io.

At Gong, you will join a company built on innovative products, ambitious goals, and passionate people. We are shaping the future of revenue intelligence and we want people who are excited to build what comes next. You will work with a team that dreams big, moves fast, and cares deeply about the craft and about each other. Here, transparency and trust are core to how we operate, and every person has the opportunity to make a visible impact. If you want to grow, stretch, and do work that truly matters, Gong is the place to do the best work of your career.

Role Summary

This is a high‑visibility, high‑impact role at the center of Gong’s security and compliance story. As our Senior GRC Security Lead, you will be the architect of foundational programs we are building — Gong’s first‑ever Common Controls Framework, standing up a formal risk process and register, implementing a GRC tooling ecosystem, and owning the full policy, standards, and exceptions management lifecycle. It’s a role for a builder — someone who thrives in ambiguity, operates with urgency, and finds energy in creating order from complexity. You will work directly with Legal, Sales, Engineering, Customer Audit teams, and executive stakeholders, and your fingerprints will be visible across everything Gong builds for compliance and trust for years to come.

Responsibilities
  • Design and implement Gong’s Common Controls Framework, mapping controls across SOC 2, ISO 27001, 27017, 27701, 27018, HIPAA, PCI, and other applicable frameworks.
  • Rationalize overlapping requirements across frameworks to reduce compliance burden and create a single source of truth for control ownership.
  • Partner with Engineering, Infrastructure, and Product Security to embed controls at the architecture level, not just as audit checkboxes.
  • Establish control testing methodology, evidence collection standards, and continuous control monitoring processes.
  • Serve as the subject‑matter expert on control mapping during customer and external audits, RFPs, and enterprise sales engagements.
  • Build Gong’s product & enterprise risk register from the ground up—defining risk taxonomy, scoring methodology, risk appetite thresholds, and ownership models.
  • Implementation of a GRC platform and system of record, and ability to build executive‑level dashboards to track vulnerability, risk, and control remediation.
  • Create and maintain risk treatment plans in partnership with risk owners across the business, tracking remediation milestones and escalating blockers.
  • Develop executive‑level risk reporting cadences and dashboards for the Head of GRC and senior leadership.
  • Own the complete lifecycle of Gong’s information security policy suite—creation, review cycles, version control, and employee acknowledgment tracking.
  • Establish and operate a formal exceptions management program, including intake, risk assessment, approval workflows, compensating controls, and periodic review.
  • Ensure policies remain aligned with evolving regulatory requirements, industry frameworks, and Gong’s rapidly changing technology environment.
  • Drive policy adoption through clear communication, training support, and cross‑functional partnership.
  • Liaise with external auditors and certification bodies for SOC 2, ISO, and other certifications.
Qualifications
  • 7+ years of progressive experience in GRC, Information Security, or a closely related function— with meaningful time spent building or scaling programs, not just running them.
  • Demonstrated hands‑on experience building a GRC program at scale—ideally in a high‑growth SaaS or technology company.
  • Deep expertise across multiple compliance and security frameworks, including SOC 2 Type II, ISO 27001, NIST CSF, and at least one regulatory framework (GDPR, CCPA, HIPAA, or equivalent).
  • Experience creating and implementing GRC record of truth/tooling.
  • Strong policy and standards writing ability—capable of translating complex regulatory language into clear, actionable documentation.
  • Experience conducting and managing product & enterprise risk assessments, with a working knowledge of risk quantification methodologies.
  • Proven ability to manage and communicate with senior stakeholders, including Legal, Engineering, and executive audiences.
  • Bachelor’s degree in Information Security, Computer Science, Business, or a related field; equivalent practical experience considered.
  • Relevant certifications strongly preferred: CISSP, CISM, CRISC, CISA, CCSP, or comparable credentials.
Benefits
  • Medical, dental, and vision plans designed to fit you and your family’s needs.
  • Wellbeing Fund—flexible wellness stipend to support a healthy lifestyle.
  • Mental health benefits with covered therapy and coaching.
  • 401(k) program to help you invest in your future.
  • Education & learning stipend for personal growth and development.
  • Flexible vacation time to promote a healthy work‑life blend.
  • Paid parental leave to support you and your family.
  • Company‑wide recharge days each quarter.
  • Work‑from‑home stipend to help you succeed in a remote environment.
Compensation

The annual salary hiring range for this position is $121,000 - $185,000 USD. Compensation is based on factors unique to each candidate, including, but not limited to, job‑related skills, qualification, education, experience, and location. At Gong, we have a location‑based compensation structure, which means there may be a different range for candidates in other locations. The total compensation package for this position, in addition to base compensation, may include incentive compensation, bonus, equity, and benefits.

Important Notice

We have noticed a rise in recruiting impersonations across the industry, where scammers attempt to access candidates' personal and financial information through fake interviews and offers. All Gong recruiting email communications will always come from the @gong.io domain. Any outreach claiming to be from Gong via other sources should be ignored.

Equal‑Opportunity Employer Statement

Gong is an equal‑opportunity employer. We believe that diversity is integral to our success, and do not discriminate based on race, color, religion, age, sex, sexual orientation, gender identity, national origin, disability, military status, genetic information, or any other basis protected by applicable law.

Privacy Policy

To review Gong's privacy policy, visit https://www.gong.io/gong-io-job-candidates-privacy-notice/ for more details.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security GRC Lead
Senior Security GRC Lead

Gong • San Francisco (CA)

On-site
USD 121,000 - 185,000
Medical, dental, and vision plans
Wellbeing Fund
401(k) program
+2
Senior Security GRC Lead
Senior Security GRC Lead

Gong.io • United States

Hybrid
USD 121,000 - 185,000
Medical, dental, and vision plans
Flexible wellness stipend
Mental health benefits
+6
Sr Manager, Cyber Defense & Engineering
Sr Manager, Cyber Defense & Engineering

Gong • Salt Lake City (UT)

On-site
USD 159,000 - 242,000
Medical/Dental/Vision plans
Wellbeing Fund
Mental Health benefits
+6
Sr Manager, Cyber Defense & Engineering
Sr Manager, Cyber Defense & Engineering

Gong • San Francisco (CA)

On-site
USD 159,000 - 242,000
Medical, dental, and vision plans
Wellbeing Fund
Mental Health benefits
+6
Sr Manager, Cyber Defense & Engineering
Sr Manager, Cyber Defense & Engineering

Gong • Chicago (IL)

On-site
USD 159,000 - 242,000
Medical, dental, vision plans
Wellbeing Fund
Mental Health benefits
+5
Sr Manager, Cyber Defense & Engineering
Sr Manager, Cyber Defense & Engineering

Gong • Austin (CO)

On-site
USD 159,000 - 242,000
Medical, dental, vision plans
Wellbeing Fund
Mental Health benefits
+6
Senior Corporate Security Engineer
Senior Corporate Security Engineer

Gong • Chicago (IL)

On-site
USD 134,000 - 205,000
Medical, dental, and vision plans
Wellbeing stipend
Mental health benefits
+6
Senior Corporate Security Engineer
Senior Corporate Security Engineer

Gong • San Francisco (CA)

On-site
USD 134,000 - 205,000
Medical/dental/vision plans
Wellbeing fund
Mental health benefits
+6
Global Safety and Security Lead, Workplace and Facilities
Global Safety and Security Lead, Workplace and Facilities

Gong • Austin (TX)

On-site
USD 130,000 - 195,000
Medical, dental, and vision plans
Wellbeing Fund
Mental Health benefits
+5
Senior Corporate Security Engineer
Senior Corporate Security Engineer

Gong • Austin (TX)

On-site
USD 134,000 - 205,000
Medical, dental, and vision plans
Wellbeing Fund
Mental Health benefits
+5