Director, Trust & Assurance
Job description
About the role
Sigma Computing is seeking a Director of Trust & Assurance to establish and oversee our compliance and enterprise risk operations. In this leadership position, you will manage our Governance, Risk, and Compliance (GRC) program, which includes SOC 2 and ISO audits, policy development, and vendor risk management. This role is ideal for someone with a proven track record in building and leading similar programs.
Key facts
What you'll do
- Take charge of the SOC 2 and/or ISO 27001 program, managing all aspects from control implementation to audit management and remediation.
- Develop and update our internal policy library and oversee the employee attestation process.
- Stay informed on regulatory requirements related to data privacy and industry standards, collaborating with the Legal team to implement necessary controls.
- Conduct internal audits to assess the effectiveness of controls.
- Oversee enterprise-wide security awareness training initiatives.
- Manage vendor risk assessments and maintain an inventory of vendor risks, including contract evaluations and ongoing monitoring.
- Track subprocessors and ensure proper disclosures are made.
- Collaborate with the Legal team on risk-related vendor contract terms.
- Oversee the process for responding to security questionnaires and maintain customer-facing trust documentation.
- Ensure compliance artifacts and trust center content are readily available to facilitate efficient sales processes.
- Serve as a reliable resource for Sales, Sales Engineering, and Solutions teams regarding security inquiries.
- Maintain the business continuity and disaster recovery plan, conducting regular tests.
- Collaborate with the Security team to manage the incident response plan and lead periodic tabletop exercises.
- Conduct post-incident reviews and track remediation efforts.
- Develop and maintain an enterprise risk register, creating risk treatment plans and monitoring remediation activities across the organization.
- Conduct quarterly risk reviews and identify emerging risks to report to the General Counsel.
- Manage the company's insurance program, including cyber, errors and omissions, and directors and officers insurance, overseeing renewals and coverage evaluations.
- Act as the primary liaison with insurance brokers and carriers.
- Lead and develop a team of 3 or more direct reports, including compliance analysts and vendor risk coordinators.
- Set objectives, conduct performance evaluations, and create career development paths for team members.
Requirements
- A minimum of 8 years of experience in Governance, Risk, and Compliance (GRC), compliance, audit, or risk management, preferably in a SaaS or technology environment, with at least 2-3 years in a managerial role.
- Proven experience managing a SOC 2 or ISO 27001 program through a complete audit cycle, including managing auditor relationships.
- Demonstrated ability to establish a function or program from the ground up.
- Experience with vendor and third-party risk assessment processes.
- Familiarity with risk management frameworks such as COSO, ISO 31000, or NIST RMF.
- Strong communication skills to effectively convey technical concepts to executives and business language to engineers.
- Excellent project management skills, capable of managing multiple audits, questionnaires, and quarterly reports simultaneously.
- Bonus: Experience with GRC tools like Vanta, Drata, or ServiceNow GRC.
- Bonus: Hands-on experience with cloud platforms (GCP, AWS, Azure) from a compliance and security viewpoint.
- Bonus: Knowledge of security frameworks such as NIST CSF or CIS Controls.
- Bonus: Relevant certifications including CISA, CRISC, or CISSP.
What Success Looks Like in Year One
- Achieve and maintain SOC 2 Type II certification with no significant findings.
- Implement a vendor risk assessment process adopted prior to contract execution.
- Mature the enterprise risk register with quarterly reviews.
- Test the incident response plan through tabletop exercises.
- Review the insurance program to ensure no coverage gaps exist.
- Ensure timely responses to security questionnaires that align with sales cycles.
Why Join Sigma
This role presents a chance to create and lead a premier Trust & Assurance function, enabling the business to confidently pursue opportunities. You will work closely with the General Counsel and executive team, build your own team, and significantly influence how Sigma manages risk and fosters customer trust as we expand.
Additional Job details
The annual salary for this position ranges from $225,000 to $265,000. Compensation may vary based on qualifications, skills, and experience. This role includes stock options and a comprehensive benefits package.
- Equity
- Comprehensive health benefits
- Flexible time off policy
- Paid bonding time for new parents
- Traditional and Roth 401k options
- Commuter and FSA benefits
- Lunch program
- Dog-friendly office
Sigma is an equal opportunity employer committed to building a diverse team. We welcome applicants from all backgrounds and look forward to how your experience can contribute to our growth.
Note: This position requires in-office work at our locations in San Francisco or New York.
Our Privacy Practices
When you apply for a job with us, Sigma processes your personal data to evaluate your candidacy and manage the recruitment process. Please review Sigma's Candidate Privacy Notice for more details.
Sigma's use of AI
Our hiring process incorporates AI tools to aid in candidate screening and assessment, designed to complement human decision-making.