Risk and Compliance Lead

Applied Intuition Applied Intuition · Robotics · Sunnyvale, CA · Security & IT Operations

This role is for a Risk and Compliance Lead responsible for managing and maturing the security GRC program, conducting risk assessments, leading compliance efforts (SOC2, ISO 27001, TISAX), driving Third Party Risk Management, and partnering with various teams to embed compliance requirements. The role requires significant experience in security GRC and program ownership, with a focus on building or maturing programs.

What you'd actually do

  1. Own and mature the security GRC program, including policy lifecycle management, risk register maintenance, and control framework alignment across the organization
  2. Conduct comprehensive enterprise and product-level risk assessments to identify, prioritize, and track risks against the company's risk appetite - translating findings into actionable remediation plans for stakeholders
  3. Lead, manage and support compliance efforts such as, but not limited to, SOC2, ISO 27001, ISO 9001, TISAX, and federal/defense requirements - owning audit readiness, evidence collection, and remediation tracking end to end
  4. Drive Third Party Risk Management (TPRM) program, including vendor assessments, contract security reviews, and ongoing monitoring of critical third parties
  5. Build and maintain the GRC program infrastructure - including risk tracking, compliance tooling, reporting cadences, and executive-level risk reporting

Skills

Required

  • 6+ years of experience in security GRC, risk management, or compliance program ownership
  • Hands on experience in running Enterprise Risk Assessments aligned with industry standard frameworks, risk register ownership, and translating technical risk into business-level impact
  • Past experience of running Security Maturity Assessments against NIST 800-53, CCF, and more
  • Deep hands-on experience managing SOC 2, ISO 27001, and TISAX audits - including scoping, control mapping, evidence coordination, and auditor management
  • Experience running Third Party Risk Management programs including vendor tiering, security assessments, and ongoing monitoring
  • Ability to interpret compliance frameworks in practical terms and drive cross-functional remediation without direct authority
  • Strong communication skills - comfortable presenting risk posture and program status to executive leadership and board-level stakeholders
  • Experience with GRC tooling such as Vanta, Drata, OneTrust, or similar platforms

Nice to have

  • Experience with Automotive security and safety compliance frameworks such as ISO 21434, ISO 26262
  • Certifications such as CISSP

What the JD emphasized

  • track record of building or maturing programs, not just executing within them
  • Hands on experience in running Enterprise Risk Assessments
  • Deep hands-on experience managing SOC 2, ISO 27001, and TISAX audits
  • Experience running Third Party Risk Management programs