Sigma is seeking an experienced GRC Manager to lead and scale our governance, risk, and compliance programs. This role is based in our San Francisco office or upcoming New York office and reports to the General Counsel.
Requirements
- 4+ years of experience in governance, risk management, and/or compliance roles, preferably in SaaS or technology companies
- Demonstrated experience building or significantly maturing a GRC program from the ground up
- Track record of successfully leading certification audits (SOC 2, ISO 27001, HIPAA, or similar)
- Experience implementing risk management frameworks (COSO, ISO 31000, NIST RMF, or similar)
- Strong knowledge of data privacy regulations and their practical application (GDPR, CCPA, etc.)
- Experience developing and maintaining information security and privacy policies, procedures, and control frameworks
- Strong business acumen with ability to translate risk and compliance requirements into business value
- Excellent communication skills with ability to influence stakeholders at all levels, including leadership
- Proven ability to manage multiple priorities and stakeholders in a fast-paced, high-growth environment
- Collaborative mindset and commitment to enabling business success while managing risk
Benefits
- Equity
- Generous health benefits
- Flexible time off policy
- Paid bonding time for all new parents
- Traditional and Roth 401k
- Commuter and FSA benefits
- Lunch Program
- Dog friendly office