SlipstreamJobsFresh Startup & VC-Backed Jobs

Director of GRC

San Francisco Compute Company - San Francisco, CA, United States - In-office

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

San Francisco Compute Company is building a liquid market for GPU offtake contracts—enabling companies to buy and sell compute capacity in a secondary market to mitigate the risk of long-term fixed-price infrastructure contracts. As the company scales its compliance and risk infrastructure, you will join as the first Director of GRC, reporting to engineering leadership. You will own governance, risk, and compliance end-to-end, building and managing a small GRC team from day one. The company has completed its first SOC 2 audit and is committed to obtaining ISO 27001 certification next. Your mandate is to design new functions and processes rather than inherit mature ones—this is a build role in a startup environment. Key responsibilities include: **Team Leadership:** Hire, manage, and develop the GRC team from inception. Set its structure, priorities, operating cadence, and own results. **Compliance Program Ownership:** Own the SOC 2 Type 2 program and lead ISO 27001 certification end-to-end, including readiness assessment, gap remediation, control implementation, auditor management, and continuous monitoring. **Risk Management:** Stand up enterprise risk management—conduct risk assessments, maintain the risk register, develop treatment plans, and report to leadership. **Policy & Process Design:** Author and operationalize policies and functions for a maturing company: access reviews, business continuity, security awareness, vendor management, change management, and incident response. **GRC Tooling:** Own the compliance automation platform (Vanta) and drive selection and integration of GRC-related tools. **Third-Party Risk:** Own vendor security reviews and third-party risk assessments. You will work hands-on from day one—designing controls, running tooling, and managing auditors—until the team is in place to take on these responsibilities. **Requirements:** - Prior experience in a senior, high-impact GRC or security compliance role at a startup, where you built programs under resource constraints rather than operating within an already-mature function. - Hands-on experience driving a company through its first ISO 27001 certification from readiness through audit—standing up the program, not inheriting one already in place. - Experience owning or running a SOC 2 program. - Proven people leadership: you have hired, managed, and developed a team. - Comfortable working cross-functionally with engineering on controls, tooling, and technical remediation. **Nice to Haves:** - Relevant certifications (CISA, CISM, CISSP, CRISC, or ISO 27001 Lead Implementer/Auditor). - Experience with compliance automation platforms (Vanta or similar). - Privacy program experience (GDPR/CCPA).

Similar roles