Governance, Risk, and Compliance Manager

Decagon
San Francisco
Workplace: OnsiteFull timeUSD 190,000 - 275,000 annuallyFunction: Legal, Risk & ComplianceExperience: 3-5 yearsSkills: ["Writing","Communication","Project management","Stakeholder management","Attention to detail"]

Compliance-focused security professional responsible for day-to-day execution of a growing GRC program, driving enterprise-ready certifications (SOC 2 Type II, ISO 27001, PCI DSS, HIPAA, CCPA), managing RFP responses, and coordinating cross-functional teams to support Fortune 500 customers and scale security documentation and processes.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Decagon
Decagon
4 months ago

Governance, Risk, and Compliance Manager

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 21 hours agoStatus: Live

Job Summary

Compliance-focused security professional responsible for day-to-day execution of a growing GRC program, driving enterprise-ready certifications (SOC 2 Type II, ISO 27001, PCI DSS, HIPAA, CCPA), managing RFP responses, and coordinating cross-functional teams to support Fortune 500 customers and scale security documentation and processes.
Location: San Francisco
Workplace: Onsite
Employment Type: Full time
Job Function: Legal, Risk & Compliance
Seniority: Mid level

Key Responsibilities

  • •Drive compliance certifications including SOC 2 Type II, ISO 27001, PCI DSS, HIPAA, and CCPA
  • •Automate or execute compliance evidence collection, ensuring all controls are properly documented and audit-ready
  • •Maintain and improve security documentation including policies, procedures, and customer-facing security collateral
  • •Support customer security assessments by preparing materials for security reviews and helping address technical inquiries from Fortune 500 security teams
  • •Manage security and compliance topics in RFPs end-to-end, coordinating responses across engineering, product, and legal teams to deliver accurate, timely responses to enterprise customers.

Pay and Benefits

Salary: USD 190,000 - 275,000 annually
Equity and Bonus:Equity
Perks:Health InsuranceDentalVisionRetirementPar ParentalMeal Allowance

Key Requirements

  • •3-5 years of GRC experience in high-growth SaaS or technology companies, with direct responsibility for compliance programs
  • •Proven track record contributing to SOC 2, ISO 27001, or similar enterprise compliance certifications
  • •Experience in data privacy regulations including CCPA, GDPR, and emerging AI governance frameworks
  • •Strong project management skills with ability to coordinate cross-functional teams under tight deadlines
  • •Excellent written and verbal communication skills to translate complex security concepts for diverse audiences
Experience:3-5 yearsSaaSEnterprise software
Skills:WritingCommunicationProject managementStakeholder managementAttention to detail
Certifications:SOC 2ISO 27001PCI DSSHIPAACCPA
Languages:English
Tech Stack:VantaDrataSecureFrameGoogle Cloud Platform

Company Brief

Decagon
Builds conversational AI agents and a platform that automates customer support across chat, email, and voice, enabling brands to deliver concierge-level customer experiences at scale.
Industry: AI & Machine Learning
Company Size: Medium (51 to 250 employees)
Growth: Scaleup
Valuation: Unicorn (USD 1B+)
Funding: Series C
Headquarters: San Francisco, United States
Founded: 2023
Glassdoor
Glassdoor: 3.9
WebsiteLinkedInGlassdoor