Skip to content
← Back to job listings

Founding GRC Lead

Pallet · San Francisco, United States

External listingfull-timeabout 1 month ago

About The Role

Join Pallet, a fast-growing startup, as the Founding GRC Lead. In this role, you will be responsible for building and managing the company's compliance programs, including SOC 1 and SOC 2, GDPR, and CCPA. You will work closely with various teams, including engineering, product, sales, and legal, to integrate compliance into the company's operations. This is a unique opportunity to shape the compliance function from the ground up and fast-track your career in a dynamic and supportive environment.

  • Conduire les programmes SOC 1 et SOC 2, construire les opérations de confidentialité GDPR et CCPA, et travailler en étroite collaboration avec les équipes d'ingénierie, de produit, de vente et juridique.
  • Concevoir le modèle opérationnel de conformité à partir d'une page blanche, avec les outils GRC et le soutien exécutif nécessaires pour le faire correctement.
  • Être le principal point de contact pour les auditeurs externes et les évaluateurs, collecter les preuves, répondre aux audits et traduire les résultats des audits en plans d'action.
  • Deep hands-on experience with compliance automation platforms and evidence workflows
  • Built or significantly matured SOC, ISO, GDPR, and privacy compliance programs in-house - you've operationalized privacy, not just advised on it
  • Technically credible with engineers: comfortable discussing access controls, encryption, logging, and cloud infrastructure (AWS/GCP) without needing translation
  • Startup-calibrated judgment: you know which risks matter, build lightweight process, and have certifications (CISA, CISSP, ISO 27001 LA) as a bonus rather than a substitute for experience
  • 7–12 years across GRC, security compliance, or audit, including full ownership of at least two SOC 2 Type II cycles

This is an external listing. JobSpring does not represent or verify the employer. Report this listing