Senior Security Grc Lead

Gong Gong · Enterprise · San Francisco, CA · Information Security

This role is for a Senior Security GRC Lead at Gong, a company that uses AI to transform revenue teams. The lead will architect foundational programs like a Common Controls Framework, establish a formal risk process, implement GRC tooling, and manage policies. This is a builder role for someone who thrives in ambiguity and creating order from complexity, working with various teams to ensure compliance and trust in Gong's products.

What you'd actually do

  1. Design and implement Gong’s Common Controls Framework, mapping controls across SOC 2, ISO 27001, 27017, 27018, HIPAA, PCI, and other applicable frameworks.
  2. Rationalize overlapping requirements across frameworks to reduce compliance burden and create a single source of truth for control ownership.
  3. Partner with Engineering, Infrastructure, and Product Security to embed controls at the architecture level, not just as audit checkboxes.
  4. Establish control testing methodology, evidence collection standards, and continuous control monitoring processes.
  5. Serve as the subject-matter expert on control mapping during customer and external audits, RFPs, and enterprise sales engagements.

Skills

Required

  • GRC program design and implementation
  • Compliance framework mapping (SOC 2, ISO 27001, HIPAA, PCI)
  • Risk management and assessment
  • Policy and standards development
  • GRC tooling implementation
  • Stakeholder communication
  • Experience in high-growth SaaS or technology companies

Nice to have

  • CISSP
  • CISM
  • CRISC
  • CISA
  • CCSP

What the JD emphasized

  • architect of foundational programs we are building
  • Gong’s first-ever Common Controls Framework
  • standing up a formal risk process and register
  • implementing a GRC tooling ecosystem
  • owning the full policy, standards, and exceptions management lifecycle
  • not a role for someone looking to inherit a mature program
  • role for a builder
  • thrives in ambiguity
  • operates with urgency
  • creating order from complexity
  • fingerprints will be visible across everything Gong builds for compliance and trust for years to come
  • 7+ years of progressive experience in GRC, Information Security, or a closely related function — with meaningful time spent building or scaling programs, not just running them.
  • Demonstrated hands-on experience building a GRC program at scale
  • Deep expertise across multiple compliance and security frameworks
  • Experience creating and implementing GRC Record of Truth/Tooling.
  • Strong policy and standards writing ability
  • Experience conducting and managing product & enterprise risk assessments
  • Proven ability to manage and communicate with senior stakeholders