Security Grc Manager

Hex Hex · Data AI · United States · Engineering

Hex is seeking a Security GRC Manager to establish and manage their security and privacy compliance programs, covering frameworks like SOC 2, ISO 27001, HIPAA, GDPR, and PCI DSS. This role involves architecting systems, processes, and culture for compliance, risk management, and audit readiness, requiring technical understanding of the product to translate it into defensible compliance narratives. The manager will own program development, risk assessment, customer trust initiatives, audit management, third-party risk, and program automation, partnering closely with engineering, sales, and legal teams.

What you'd actually do

  1. Own and mature Hex’s security and privacy compliance program across SOC 2, ISO 27001, ISO 27701, HIPAA, GDPR, CCPA, PCI DSS, and other frameworks relevant to our business.
  2. Own Hex’s risk management lifecycle: identify, assess, track, and drive mitigation of security, privacy, operational, and regulatory risks.
  3. Serve as the primary owner of customer and prospect security questionnaires, risk assessments, and contractual security provisions.
  4. Lead internal and external audits from planning through remediation.
  5. Own Hex’s third-party risk management program, including vendor assessments, reviews, and ongoing monitoring.

Skills

Required

  • 5–8+ years in GRC, compliance, security engineering, privacy, audit, or a related field.
  • Deep familiarity with frameworks such as SOC 2, ISO 27001, ISO 27701, PCI DSS, HIPAA, GDPR, and associated security controls.
  • Experience running or contributing significantly to audit cycles and certification processes.
  • Technical literacy in cloud-native environments (AWS preferred), SaaS architectures, and modern security tooling.
  • Ability to understand and explain product architecture, data flows, and control implementations to auditors and customers.
  • Experience building or maturing GRC programs at a high-growth company.
  • Strong project/program management skills: you can set roadmaps, drive timelines, and deliver on deadlines.
  • Comfort creating order out of ambiguity—you design the playbook, not just follow one.
  • Exceptional communicator with the ability to translate complex topics into clear, concise, customer-ready language.
  • Strong stakeholder management skills—you can collaborate with engineering, sales, legal, executives, and prospects with equal effectiveness.
  • Empathic, diplomatic, and able to balance customer expectations with business realities.
  • Highly organized and detail-oriented; rigorous in execution.
  • Naturally curious with a continuous-improvement mindset.
  • Thrives in distributed, fast-paced environments.
  • Comfortable making risk-based decisions and presenting tradeoffs to leadership.

Nice to have

  • Certifications such as CISA, CISM, CISSP, CRISC, ISO 27001 Lead Implementer/Auditor.

What the JD emphasized

  • SOC 2
  • ISO 27001
  • ISO 27701
  • HIPAA
  • GDPR
  • CCPA
  • PCI DSS
  • security questionnaires
  • risk assessments
  • contractual security provisions
  • Trust Center / trust portal
  • audit cycles
  • certification processes