
Governance, Risk, and Compliance Manager
Job description
About the role
You will drive the execution of our enterprise compliance program as a central pillar of customer trust and deal execution. The role requires you to own the end-to-day management of security certifications, ensuring our controls remain audit-ready at all times. You will act as the primary liaison between our engineering teams and enterprise customers during security reviews and compliance assessments. This position demands a high level of ownership over documentation, processes, and vendor risk management initiatives. You will be instrumental in translating complex regulatory requirements into actionable technical controls for the business. Your work will directly enable faster enterprise sales cycles by de-risking conversations for security-conscious buyers. Ultimately, you will shape how Decagon scales its governance framework to support global Fortune 500 partnerships.
Key facts
What you'll do
Coordinate and drive the attainment of SOC 2 Type II, ISO 27001, PCI DSS, HIPAA, and CCPA compliance certifications across the organization.
Automate and execute the collection of compliance evidence, maintaining a state of readiness for audits and reducing manual overhead.
Own the maintenance and enhancement of security documentation, including policies, procedures, and customer-facing security collateral.
Prepare and deliver materials for security assessments, responding to detailed technical inquiries from Fortune 500 security teams with precision.
Manage security and compliance topics within RFPs from initial response through final delivery, ensuring alignment across engineering, product, and legal stakeholders.
Coordinate with contractors and vendors to uphold response quality and adhere to strict timelines during peak sales periods.
Design, build, and optimize repeatable processes to scale Governance, Risk, and Compliance (GRC) operations in support of hundreds of enterprise customers.
Partner with sales engineering to deeply understand customer security requirements and proactively craft responses for recurring concerns.
Collaborate with Sales and Customer Success teams to accelerate deal velocity by resolving security concerns through proactive content and enablement.
Work closely with Security, Engineering, and Product teams to convert compliance requirements into actionable technical controls for new features.
Establish and maintain vendor risk management programs to evaluate and monitor third-party security risks across our entire supply chain.
Perform gap analyses against regulatory and certification frameworks to identify remediation plans and track mitigation progress.
Serve as the operational owner of the compliance program, ensuring continuous improvement and adherence to strict deadlines.
Leverage data and metrics to report on the state of security controls and drive informed decision-making at the executive level.
Requirements
Candidates must possess 3-5 years of GRC experience within high-growth SaaS or technology companies, with direct responsibility for managing compliance programs.
You must have a proven track record of contributing to successful SOC 2 Type II, ISO 27001, or similar enterprise compliance certifications.
Demonstrated experience with data privacy regulations, including CCPA, GDPR, and emerging AI governance frameworks, is mandatory.
Strong project management skills are required to coordinate cross-functional teams under tight deadlines and competing priorities.
Excellent written and verbal communication skills are essential for translating complex security concepts for diverse technical and non-technical audiences.
You must have a working knowledge of technical security controls and the ability to collaborate effectively with engineering teams.
A background in implementing GRC programs at companies scaling from startup to enterprise is a strict requirement.
Nice to have
Prior experience with AI/ML compliance frameworks and an understanding of unique risks in conversational AI systems is preferred.
A background in healthcare or financial services with knowledge of HIPAA or PCI requirements is strongly valued.
Experience building GRC programs at companies scaling from startup to enterprise.
Experience with GRC platforms like Vanta, Drata, or Secureframe.
Practical notes
This is an in-office role based in San Francisco.
Full-time engagement with standard business hours applies.
Visa sponsorship may be considered for eligible candidates.
Relocation assistance is not provided.
Candidates must be authorized to work in the United States without sponsorship for this role.
Applications will be reviewed on a rolling basis until the position is filled.