Governance, Risk & Compliance (GRC) Manager at Sigma Computing | San Francisco, CA | Rezi

Governance, Risk & Compliance (GRC) Manager at Sigma Computing

Governance, Risk & Compliance (GRC) Manager

Sigma Computing · San Francisco, CA

1 months ago

Governance, Risk & Compliance (GRC) Manager

Sigma Computing · San Francisco, CA

2 months ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

Lead and scale Sigma's governance, risk, and compliance programs, building a strategic, enterprise-wide GRC function that enables business growth while managing organizational risk. Partner with various departments to develop a comprehensive GRC framework, mature governance structures, implement scalable risk management processes, and ensure regulatory compliance.

Responsibilities

  • Design and implement governance frameworks, including reporting, policy governance, and control oversight.
  • Establish and maintain enterprise policies, standards, and procedures across technology, security, privacy, and operational functions.
  • Build and lead a governance committee structure that provides appropriate oversight and decision-making.
  • Create governance dashboards and metrics to provide visibility into program maturity and effectiveness.
  • Partner with leadership to align governance activities with business strategy and risk appetite.
  • Develop and operate a comprehensive Enterprise Risk Management (ERM) program.
  • Conduct regular enterprise-wide risk assessments and maintain a dynamic risk register.
  • Build and maintain business continuity and disaster recovery programs, including regular testing and tabletop exercises.
  • Implement third-party risk management processes, including vendor risk assessments, contract reviews, and ongoing monitoring.
  • Create risk treatment plans and track remediation activities across the organization.
  • Facilitate risk-informed decision-making at all levels of the organization.
  • Coordinate with functional leaders to ensure risks across all business areas are identified and managed appropriately.
  • Own audit and certification programs including SOC 2, ISO 27001, HIPAA, and other relevant standards.
  • Develop and maintain compliance monitoring programs to track regulatory changes and work with the legal team to assess impact.
  • Partner with HR and Legal to support labor & employment compliance programs, including workplace safety, anti-discrimination, wage and hour requirements, and multi-jurisdictional employment regulations.
  • Monitor and ensure adherence to industry-specific regulatory requirements relevant to Sigma's business operations.
  • Manage security awareness training programs enterprise-wide.
  • Conduct internal audits and assessments to validate control effectiveness.
  • Coordinate external audits and assessments with third-party auditors.
  • Support sales and customer success teams with compliance documentation and security inquiries.
  • Develop customer-facing materials that articulate Sigma's risk management and compliance posture.
  • Complete and manage responses to customer security questionnaires and assessments (VSAs, SIGs, custom questionnaires).
  • Enable efficient deal cycles by maintaining ready-to-use compliance artifacts, trust center content, and documentation.
  • Partner with Sales Engineering and Solutions teams to address prospect security and compliance requirements.

Requirements

  • 4+ years of experience in governance, risk management, and/or compliance roles, preferably in SaaS or technology companies.
  • Demonstrated experience building or significantly maturing a GRC program from the ground up.
  • Track record of successfully leading certification audits (SOC 2, ISO 27001, HIPAA, or similar).
  • Experience implementing risk management frameworks (COSO, ISO 31000, NIST RMF, or similar).
  • Strong knowledge of data privacy regulations and their practical application (GDPR, CCPA, etc.).
  • Experience developing and maintaining information security and privacy policies, procedures, and control frameworks.
  • Strong business acumen with ability to translate risk and compliance requirements into business value.
  • Excellent communication skills with ability to influence stakeholders at all levels, including leadership.
  • Proven ability to manage multiple priorities and stakeholders in a fast-paced, high-growth environment.
  • Collaborative mindset and commitment to enabling business success while managing risk.

Skills

  • GRC platforms (ServiceNow GRC, Archer, LogicGate, or similar)
  • Cloud environments (GCP, AWS, Azure) from a compliance and security perspective
  • Labor & employment compliance
  • Cross-functional collaboration with HR on regulatory matters
  • Multi-state or international employment regulations
  • Continuous compliance automation tools (Vanta, Drata, Secureframe, Tugboat, or similar)
  • CRISC, CISA, CISM, CGEIT, CISSP, or CIPP
  • High-growth SaaS or technology companies
  • Technical and operational risk management
  • Distributed or remote teams
  • Security frameworks such as NIST CSF, CIS Controls, or OWASP

Location

  • San Francisco
  • New York

Work Type

  • In-office

Experience Level

  • 4+ years

Salary/Compensations

  • $190k - $215k annually

Benefits

  • Stock options
  • Comprehensive benefits package
  • Equity
  • Generous health benefits
  • Flexible time off policy
  • Paid bonding time for all new parents
  • Traditional and Roth 401k
  • Commuter and FSA benefits
  • Lunch Program
  • Dog friendly office

About the Company

  • Sigma is the AI Apps and agentic analytics platform built on the cloud data warehouse. Business and technical teams use Sigma to explore live data, build intelligent applications, and automate critical workflows all without moving data or breaking governance. Sigma supports a spreadsheet interface, SQL, Python, and native AI in a single governed workspace, giving every team the speed to act and IT the control to scale. Sigma is trusted by more than 2,000 customers, including AMD, Duolingo, Colgate-Palmolive, and JPMorgan Chase. Sigma announced its $80M in Series E financing in May 2026. The round was led by Princeville Capital, with new strategic investors Databricks Ventures, ServiceNow Ventures, and Workday Ventures participating alongside returning investors Altimeter Capital, Avenir Growth Capital, D1 Capital Partners, K5 Global, NewView Capital, Spark Capital, Sutter Hill Ventures, and XN. This milestone follows Sigma reaching $200M in annual recurring revenue in April 2026, with more than 100% year-over-year growth and 1.1 million new active users added in the latest fiscal year.

Equal Opportunity

  • Sigma is an equal opportunity employer. We are committed to building a smart and strong team regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender, gender identity or expression, veteran, or any other protected status. We look forward to learning how your experience can enable all of us to grow.