GRC Program Manager
On-siteDraper, Utah, United States
Job Summary
Own and scale Redo's GRC program end to end, covering SOC 2, GDPR, CCPA, PCI, and HIPAA frameworks. Partner with engineering to translate control requirements into actionable technical specs and ensure implementation. Lead audit readiness by managing auditor relationships, running evidence collection, and maintaining continuous control monitoring. Drive sales enablement by responding to merchant security reviews, questionnaires, and due-diligence requests. Build security policies, manage vendor risk, and own GRC tooling and automation to automate evidence collection and control monitoring. Lead AI enablement for compliance automation and manage access reviews and security awareness training. Keep leadership informed on compliance posture and represent the security program to customers and partners.
Required Qualifications
- 5+ years in GRC, security compliance, or a closely related role
- hands-on ownership (not just support) of at least one full compliance program
- Demonstrated experience taking a company through a full SOC 2 certification and continued surveillance
- Depth of experience helping SaaS platforms support GDPR and data privacy obligations
- Experience navigating HIPAA and PCI environments
- A self-directed operator who can own and mature a program with minimal oversight
- Ability to translate control requirements into engineering requirements and to collaborate credibly with software engineers
- Experience responding to customer security reviews and security questionnaires
- Strong writing and communication skills
- Comfortable in a fast-moving, high-growth environment where you set the pace
- Experience using AI for custom compliance automation
Desired Qualifications
- Relevant certifications such as CISA, CISSP, ISO 27001 Lead Implementer/Auditor, or CIPP/E
- Experience with GRC automation platforms (e.g., Vanta, Drata, Secureframe)
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.