Gong logo
GongPosted 2 months ago

Senior Security GRC Lead

$121,000–$185,000 year

RemoteChicago, Illinois, United States or New York City, New York, United States

Full TimeSenior LevelLargeTechnology

Job Summary

Design and implement Gong's Common Controls Framework, mapping controls across SOC 2, ISO 27001, 27017, 27701, 27018, HIPAA, and PCI frameworks while rationalizing overlapping requirements to create a single source of truth. Partner with Engineering, Infrastructure, and Product Security to embed controls at the architecture level, establish control testing methodologies, and build the product and enterprise risk register from the ground up. Implement a GRC platform as the system of record, develop executive dashboards for vulnerability and risk tracking, and own the full lifecycle of the information security policy suite including exceptions management. Serve as the subject-matter expert during customer audits, RFPs, and enterprise sales engagements, ensuring policies remain aligned with evolving regulatory requirements and Gong's rapidly changing technology environment.

Required Qualifications

  • 7+ years of progressive experience in GRC, Information Security, or a closely related function
  • Meaningful time spent building or scaling programs, not just running them
  • Demonstrated hands-on experience building a GRC program at scale
  • Experience in a high-growth SaaS or technology company
  • Deep expertise across multiple compliance and security frameworks, including SOC 2 Type II, ISO 27001, NIST CSF
  • Experience with at least one regulatory framework (GDPR, CCPA, HIPAA, or equivalent)
  • Experience creating and implementing GRC Record of Truth/Tooling
  • Strong policy and standards writing ability
  • Capability to translate complex regulatory language into clear, actionable documentation
  • Experience conducting and managing product & enterprise risk assessments
  • Working knowledge of risk quantification methodologies
  • Proven ability to manage and communicate with senior stakeholders, including Legal, Engineering, and executive audiences
  • Bachelor's degree in Information Security, Computer Science, Business, or a related field
  • Equivalent practical experience to the degree of the Bachelor's degree

Desired Qualifications

  • Relevant certifications: CISSP, CISM, CRISC, CISA, CCSP, or comparable credentials

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce