SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 230,000 - 275,000 / annual
Profound is a fast-growing AI marketing platform used by 15% of the Fortune 500 (including Comcast, Estée Lauder, Walmart) and innovators like Ramp, MongoDB, and Figma. The platform consolidates marketing work—research, briefs, content, campaigns, reporting—in one place, powered by AI agents that automate tasks like reporting, content drafting, page audits, and competitive research.
You will own and scale Profound's security and compliance programs as GRC Director, working closely with engineering, sales, and customer success. This is a hands-on, strategic role central to closing enterprise deals, sustaining customer trust, and meeting regulatory requirements across the markets Profound operates in.
Key responsibilities include:
- Own and operate compliance frameworks (SOC 2, ISO 27001, GDPR, and others)
- Drive audits end-to-end: readiness, evidence collection, auditor coordination
- Continuously improve controls and reduce compliance overhead through automation
- Partner with Sales and Customer Success to unblock deals and build trust with security teams at Fortune 500 customers
- Develop and maintain trust center, security whitepapers, and customer-facing documentation
- Work directly with engineering to design and implement practical security controls across cloud infrastructure, data pipelines, and customer-facing surfaces
- Partner on identity and access work (SSO, SAML, SCIM, IdP integrations)
- Translate compliance requirements into technical, scalable solutions
- Identify gaps and drive remediation proactively
- Run risk assessments across systems, vendors, and processes
- Maintain lightweight, current, and useful policies and standards
- Track and report security posture and compliance status to leadership
- Evaluate and implement GRC and security tooling
Requirements:
- 7+ years in security GRC, compliance, or adjacent security engineering roles
- Hands-on experience with SOC 2, ISO 27001, or similar frameworks
- Experience supporting audits and leading customer-facing security conversations
- Comfortable working with engineers and reasoning about cloud infrastructure, APIs, identity systems, and data flows
- Ability to translate between compliance language and engineering reality
- Experience with modern cloud environments (AWS, GCP, or Azure) is a strong plus
- Proactive and hands-on approach; you drive changes, not just track them
- Comfortable balancing rigor with pragmatism in a fast-moving environment
- Strong written communication, especially with enterprise customers and cross-functional partners
- Experience building or scaling a GRC program from early stages
- Familiarity with automation in compliance workflows
- Background in security engineering, DevOps, or identity and access management is valued