About the Role
Beacon is seeking a GRC leader to establish and scale the governance, risk, compliance, and privacy function for its expanding portfolio of software companies. This founding role emphasizes building, automation, and modern AI tooling.
Responsibilities
- Shape and scale the GRC function across the portfolio.
- Guide portfolio companies through audits and certifications.
- Design a scalable GRC program.
- Manage security compliance, data privacy, risk, and AI governance.
- Build an AI-first GRC function using automation platforms and LLM-assisted workflows.
- Develop and manage Beacon's enterprise governance program, including security policy, AI governance, data governance and privacy, enterprise and third-party risk, and posture reporting.
- Lead governance initiatives for Beacon, pursuing relevant frameworks.
- Deliver hands-on, repeatable GRC services to portfolio companies for audits and certifications (e.g., SOC 2, ISO 27001, accessibility conformance).
- Establish a common control architecture that maps controls once to satisfy multiple standards.
- Implement AI-first automation and clear program reporting.
Requirements
- Experience building or substantially maturing a GRC program.
- Experience taking an organization through SOC 2 Type 2.
- Typically several years (5+) in GRC, IT governance, or security compliance.
- A builder with a bias for action, focused on automating manual processes.
- Strong systems thinker, capable of designing scalable GRC architectures.
- Fluent with a compliance automation platform (e.g., Vanta, Drata, Secureframe).
- Current on AI tooling in practice.
- Comfortable across security compliance and data privacy, or able to ramp quickly.
- Excellent cross-functional communicator, able to influence and translate compliance requirements.
- Clear writer.
Skills
- Governance, Risk, and Compliance (GRC)
- Data Privacy
- Security Compliance
- AI Governance
- SOC 2
- ISO 27001
- Accessibility Conformance
- Compliance Automation Platforms
- AI Tooling
- Cross-functional Communication
- Systems Thinking
- Automation
Location
- Remote
Work Type
- Full-time
Experience Level
- 5+ years
Education Level
- Privacy or audit certifications (CIPP, CIPM, CISA, CISSP, or ISO 27001 Lead Auditor or Implementer) are a plus.
- Experience with regimes beyond SOC 2 (ISO 27001, PCI DSS, HIPAA, FedRAMP, StateRAMP) and accessibility conformance (WCAG, VPAT) are a plus.
- Technical fluency to partner with engineering is a plus.
- Multi-entity, private-equity, or holding-company experience is a plus.
- M&A security and privacy diligence experience is a plus.
About the Company
- Beacon Software acquires and operates a portfolio of vertical SaaS companies.
- Beacon focuses on scaling through software, not just adding people.
- The company's thesis is that agentic operating systems can significantly lift the ceiling on bottlenecked operations, value creation, and deal sourcing.
- Beacon Software values Humility, Honesty, Hunger, and Horizon.
Equal Opportunity
- Beacon Software uses Artificial Intelligence and AI-enabled tools to assist with screening, reviewing, organizing and highlighting profiles and applications that match the key requirements for each role.
- AI does not make hiring decisions: Every application is reviewed by a member of our team, and all decisions throughout the process are made by humans.
- AI is used to support efficiency and consistency, not to replace human judgment.
- The company is committed to a fair, thoughtful, and equitable experience for every candidate.
