Governance, Risk, and Compliance Manager

Decagon Decagon · Vertical AI · San Francisco, CA · Engineering

The role is for a Compliance Manager at Decagon, a conversational AI platform company. The manager will be responsible for driving compliance certifications (SOC 2, ISO 27001, PCI DSS, HIPAA, CCPA), automating evidence collection, maintaining security documentation, supporting customer security assessments, managing RFPs, and establishing vendor risk management programs. The goal is to secure customer trust and accelerate enterprise deals by addressing security concerns.

What you'd actually do

  1. Drive compliance certifications including SOC 2 Type II, ISO 27001, PCI DSS, HIPAA, and CCPA
  2. Automate or execute compliance evidence collection, ensuring all controls are properly documented and audit-ready
  3. Maintain and improve security documentation including policies, procedures, and customer-facing security collateral
  4. Support customer security assessments by preparing materials for security reviews and helping address technical inquiries from Fortune 500 security teams
  5. Manage security and compliance topics in RFPs end-to-end, coordinating responses across engineering, product, and legal teams to deliver accurate, timely responses to enterprise customers.

Skills

Required

  • 3-5 years of GRC experience in high-growth SaaS or technology companies, with direct responsibility for compliance programs
  • Proven track record successfully contributing to SOC 2, ISO 27001, or similar enterprise compliance certifications
  • Experience in data privacy regulations including CCPA, GDPR, and emerging AI governance frameworks
  • Strong project management skills with ability to coordinate cross-functional teams under tight deadlines
  • Excellent written and verbal communication skills to translate complex security concepts for diverse audiences
  • Working knowledge of technical security controls and ability to collaborate effectively with engineering teams

Nice to have

  • Experience with AI/ML compliance frameworks and understanding of unique risks in conversational AI systems
  • Background in healthcare or financial services with knowledge of HIPAA or PCI requirements
  • Track record of building GRC programs at companies scaling from startup to enterprise
  • Experience with GRC platforms like Vanta, Drata, or SecureFrame to automate compliance workflows
  • Understanding of cloud security particularly Google Cloud Platform compliance and security features

What the JD emphasized

  • AI governance frameworks
  • HIPAA
  • PCI DSS
  • CCPA
  • SOC 2
  • ISO 27001