Security GRC Lead

Added
29 minutes ago
Type
Full time
Salary
Upgrade to Premium to se...

Related skills

iso 27001 vanta fedramp soc 2 hipaa

πŸ“‹ Description

  • Build the Mercor compliance operating cadence: SOC 2 Type 2 (continuous), ISO 27001, HIPAA, FedRAMP
  • Operate a customer-audit machine responding to major clients (Anthropic, Google, Meta, NVIDIA
  • Establish the third-party risk program: formal vendor intake, recurring review cadence, evidence
  • Own the policy lifecycle end-to-end including versioning, attestation, exception handling, and
  • Implement controls-as-code: Vanta integrations, Wiz policy packs, Panther rules tied to SOC 2 CC
  • Develop data-handling procedures: customer-data-deletion gap, DSAR workflow, KMS scheduled

🎯 Requirements

  • 7+ years in security GRC, compliance engineering, or audit
  • At least 2 years owning SOC 2 Type 2 program end-to-end
  • Shipped at least one ISO 27001 certification (including Stage 1 and Stage 2)
  • Fluent in Vanta (or Drata, Secureframe, Sprinto) at integration and admin level
  • Experience on the company side of enterprise customer audits conducted by Big 4 firms (KPMG, EY
  • Ability to translate cloud-security language to auditor language

🎁 Benefits

  • Bi-annual performance bonus structure
  • Generous equity grant vested over 4 years
  • Up to $15k relocation bonus
  • $10K housing bonus (if you live within 0.5 miles of our office)
  • $1.5K monthly stipend for meals
  • Free Equinox membership

🚚 Relocation support

πŸ›ƒ Visa sponsorship

Share job

Meet JobCopilot: Your Personal AI Job Hunter

Automatically Apply to Legal Jobs. Just set your preferences and Job Copilot will do the rest β€” finding, filtering, and applying while you focus on what matters.

Related Legal Jobs

See more Legal jobs β†’