Skip to content
← Back to job listings

Risk and Compliance Lead

Applied Intuition · Sunnyvale, United States

External listingfull-timeabout 2 months ago

About The Role

Join our team as a Risk and Compliance Lead, where you will spearhead our security compliance initiatives and ensure adequate security controls are in place to identify and mitigate risks across the organization. You will collaborate with various departments, own and mature the security GRC program, conduct comprehensive risk assessments, and drive our Third Party Risk Management program. Additionally, you will build and maintain the GRC program infrastructure, develop and maintain security policies, and support customer-facing security assurance activities. Enjoy a range of benefits including health insurance, a fitness stipend, 401(k) match, learning stipend, parental leave, and more.

  • Lead and manage security compliance initiatives across the organization, ensuring adequate security controls to identify and mitigate risk.
  • Own and mature the security Governance, Risk, and Compliance (GRC) program, including policy lifecycle management, risk register maintenance, and control framework alignment.
  • Conduct comprehensive enterprise and product-level risk assessments, lead compliance efforts for various standards, and drive Third Party Risk Management (TPRM) program.
  • Deep hands-on experience managing SOC 2, ISO 27001, and TISAX audits - including scoping, control mapping, evidence coordination, and auditor management
  • Experience running Third Party Risk Management programs including vendor tiering, security assessments, and ongoing monitoring
  • Past experience of running Security Maturity Assessments against NIST 800-53, CCF, and more
  • 6+ years of experience in security GRC, risk management, or compliance program ownership - with a track record of building or maturing programs, not just executing within them
  • Strong communication skills - comfortable presenting risk posture and program status to executive leadership and board-level stakeholders
  • Hands on experience in running Enterprise Risk Assessments aligned with industry standard frameworks, risk register ownership, and translating technical risk into business-level impact
  • Ability to interpret compliance frameworks in practical terms and drive cross-functional remediation without direct authority
  • Experience with GRC tooling such as Vanta, Drata, OneTrust, or similar platforms
  • Certifications such as CISSP
  • Experience with Automotive security and safety compliance frameworks such as ISO 21434, ISO 26262
  • Don’t meet every single requirement? If you’re excited about this role but your past experience doesn’t align perfectly with every qualification in the job description, we encourage you to apply anyway. You may be just the right candidate for this or other roles

This is an external listing. JobSpring does not represent or verify the employer. Report this listing