← Back to job listings
PA
Founding GRC Lead
Pallet · San Francisco, United States
About The Role
Join Pallet, a fast-growing startup, as the Founding GRC Lead. In this role, you will be responsible for building and managing the company's compliance programs, including SOC 1 and SOC 2, GDPR, and CCPA. You will work closely with various teams, including engineering, product, sales, and legal, to integrate compliance into the company's operations. This is a unique opportunity to shape the compliance function from the ground up and fast-track your career in a dynamic and supportive environment.
- Conduire les programmes SOC 1 et SOC 2, construire les opérations de confidentialité GDPR et CCPA, et travailler en étroite collaboration avec les équipes d'ingénierie, de produit, de vente et juridique.
- Concevoir le modèle opérationnel de conformité à partir d'une page blanche, avec les outils GRC et le soutien exécutif nécessaires pour le faire correctement.
- Être le principal point de contact pour les auditeurs externes et les évaluateurs, collecter les preuves, répondre aux audits et traduire les résultats des audits en plans d'action.
- Deep hands-on experience with compliance automation platforms and evidence workflows
- Built or significantly matured SOC, ISO, GDPR, and privacy compliance programs in-house - you've operationalized privacy, not just advised on it
- Technically credible with engineers: comfortable discussing access controls, encryption, logging, and cloud infrastructure (AWS/GCP) without needing translation
- Startup-calibrated judgment: you know which risks matter, build lightweight process, and have certifications (CISA, CISSP, ISO 27001 LA) as a bonus rather than a substitute for experience
- 7–12 years across GRC, security compliance, or audit, including full ownership of at least two SOC 2 Type II cycles
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring