SlipstreamJobsFresh Startup & VC-Backed Jobs

GRC Lead

Juicebox - San Francisco, CA, USA - In-office - posted 2026-09-04

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Juicebox is a fast-growing AI SaaS company on a mission to help teams win the talent war through intelligent recruiting. The company is on the path to $100M in ARR with 20%+ monthly growth, serving 5,000+ customers from early-stage startups to Fortune 500 companies, and has raised over $116M in funding from top-tier investors including Sequoia Capital, DST Global, and Y Combinator. You will be Juicebox's first GRC Lead, building and owning the governance, risk, compliance, and customer trust function from the ground up. This is a strategic 0→1 role sitting at the intersection of Legal, Security, Product, Engineering, and Go-to-Market teams. As the company moves upmarket to serve larger enterprise customers, security and trust have become critical growth enablers, and you will directly influence enterprise adoption and sales. Key responsibilities include: - Owning and evolving Juicebox's governance, risk, compliance, and customer trust programs - Leading SOC 2 Type 2 audits and driving adoption of ISO 27001 and emerging AI governance standards - Managing all customer-facing security and compliance requests, including security questionnaires, trust documentation, and customer due diligence - Developing and maintaining security, governance, and corporate policies as business needs evolve - Evaluating and improving security tooling and controls in partnership with Engineering and external security partners - Serving as a trusted advisor to Legal, Product, Engineering, Customer Success, and Go-to-Market teams - Positioning security and trust as competitive advantages that support enterprise sales This role offers the opportunity to shape how an AI-native company approaches governance and compliance while building a function from scratch. REQUIREMENTS: - 3+ years of experience in GRC, Customer Trust, Security Compliance, or a related field - Experience owning or supporting compliance frameworks such as SOC 2, ISO 27001, or similar programs - Experience responding to customer security questionnaires and supporting enterprise security reviews - Strong written communication skills and ability to translate technical concepts for business and customer audiences - Hands-on mindset with ability to independently drive projects from concept to execution - Experience working cross-functionally with Legal, Security, Engineering, and Go-to-Market teams BONUS: - Experience building or scaling a GRC, compliance, or customer trust function at a startup - Familiarity with AI governance, AI risk management, or emerging AI compliance frameworks - Experience supporting international compliance initiatives (UK or European requirements) - Experience evaluating security tooling (device management, endpoint protection, data loss prevention)

Similar roles