Governance, Risk & Compliance (grc) Manager

Sigma Computing Sigma Computing · Data AI · San Francisco, CA · Legal

This role is for a Governance, Risk & Compliance (GRC) Manager at Sigma Computing. The primary focus is on building and scaling enterprise-wide GRC programs, including risk management, policy governance, and compliance with regulations like SOC 2, ISO 27001, and HIPAA. The role involves partnering with various departments to protect the company's interests and enable business growth while managing risk. While the company may use AI, this role is not directly involved in building or researching AI/ML models.

What you'd actually do

  1. Design and implement governance frameworks, including reporting, policy governance, and control oversight
  2. Develop and operate a comprehensive Enterprise Risk Management (ERM) program
  3. Own audit and certification programs including SOC 2, ISO 27001, HIPAA, and other relevant standards
  4. Support sales and customer success teams with compliance documentation and security inquiries
  5. Complete and manage responses to customer security questionnaires and assessments (VSAs, SIGs, custom questionnaires)

Skills

Required

  • 4+ years of experience in governance, risk management, and/or compliance roles, preferably in SaaS or technology companies
  • Demonstrated experience building or significantly maturing a GRC program from the ground up
  • Track record of successfully leading certification audits (SOC 2, ISO 27001, HIPAA, or similar)
  • Experience implementing risk management frameworks (COSO, ISO 31000, NIST RMF, or similar)
  • Strong knowledge of data privacy regulations and their practical application (GDPR, CCPA, etc.)
  • Experience developing and maintaining information security and privacy policies, procedures, and control frameworks
  • Strong business acumen with ability to translate risk and compliance requirements into business value
  • Excellent communication skills with ability to influence stakeholders at all levels, including leadership
  • Proven ability to manage multiple priorities and stakeholders in a fast-paced, high-growth environment
  • Collaborative mindset and commitment to enabling business success while managing risk

Nice to have

  • Experience with GRC platforms (ServiceNow GRC, Archer, LogicGate, or similar)
  • Hands-on experience with cloud environments (GCP, AWS, Azure) from a compliance and security perspective
  • Experience with labor & employment compliance or cross-functional collaboration with HR on regulatory matters
  • Familiarity with multi-state or international employment regulations
  • Experience with continuous compliance automation tools (Vanta, Drata, Secureframe, Tugboat, or similar)
  • Professional certifications such as CRISC, CISA, CISM, CGEIT, CISSP, or CIPP
  • Experience in high-growth SaaS or technology companies
  • Background in both technical and operational risk management
  • Experience working in organizations with distributed or remote teams
  • Familiarity with security frameworks such as NIST CSF, CIS Controls, or OWASP

What the JD emphasized

  • building or significantly maturing a GRC program from the ground up
  • successfully leading certification audits (SOC 2, ISO 27001, HIPAA, or similar)
  • implementing risk management frameworks (COSO, ISO 31000, NIST RMF, or similar)
  • Strong knowledge of data privacy regulations and their practical application (GDPR, CCPA, etc.)
  • Experience developing and maintaining information security and privacy policies, procedures, and control frameworks