SlipstreamJobsFresh Startup & VC-Backed Jobs

Director of GRC

San Francisco Compute Company - San Francisco, CA, United States - In-office - posted 2026-09-09

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

San Francisco Compute (SFC) is building the next generation of GPU cloud infrastructure, enabling customers to lease supercomputers with flexible contracts and subleasing rights—eliminating the long-term commitment risk that plagues traditional GPU cloud providers. The company operates data centers and GPU clusters while partnering with financially motivated parties to build and operate infrastructure on their behalf. SFC's leadership includes senior technologists from Lambda, Crusoe, Digital Ocean, AWS, and Hut8, with a CTO who co-founded Voltage Park. As Director of GRC, you will own governance, risk, and compliance across the organization and build the GRC function from the ground up. You are the first hire in this role, reporting to engineering leadership. Your mandate is to maintain the company's recently completed SOC 2 audit and lead the pursuit of ISO 27001 certification. You will set the function's strategy and operating cadence, hire and manage a small GRC team, and personally drive the program of work from day one—designing controls, running tooling, and managing auditors until the team scales. Much of what your team will operate does not yet exist; this is a build role focused on designing new functions and processes rather than inheriting mature ones. Key responsibilities include: - Team Leadership: Hire, manage, and develop the GRC team from inception; set structure, priorities, and operating cadence. - Compliance Program Ownership: Own the SOC 2 Type 2 program and lead ISO 27001 certification end-to-end (readiness, gap remediation, control implementation, auditor management, continuous monitoring). - Risk Management: Stand up enterprise risk management including risk assessments, risk register, treatment plans, and leadership reporting. - Policy & Process Design: Author and operationalize policies for access reviews, business continuity, security awareness, vendor management, change management, and incident response. - GRC Tooling: Own the compliance automation platform (Vanta) and drive selection and integration of GRC-related tools. - Third-Party Risk: Own vendor security reviews and third-party risk assessments. You will work cross-functionally with engineering on controls, tooling, and technical remediation. REQUIREMENTS: - Prior experience in a senior, high-impact GRC or security compliance role at a startup, with demonstrated ability to build programs under resource constraints rather than operate within mature functions. - Hands-on experience driving a company through its first ISO 27001 certification from readiness through audit—standing up the program, not inheriting one already in place. - Experience owning or running a SOC 2 program. - Proven people leadership: you have hired, managed, and developed a team. - Comfortable working cross-functionally with engineering on controls, tooling, and technical remediation. Nice to haves: relevant certifications (CISA, CISM, CISSP, CRISC, ISO 27001 Lead Implementer/Auditor); experience with compliance automation platforms (Vanta or similar); privacy program experience (GDPR/CCPA).

Similar roles