About the Role
Beacon is seeking a GRC leader to establish and scale the governance, risk, compliance, and privacy functions across its growing portfolio of software companies. This founding role emphasizes automation and modern AI tooling for operational efficiency.
Responsibilities
- Shape and scale the GRC function from its foundations across the portfolio.
- Work directly with portfolio companies to guide them through audits and certifications.
- Design a scalable GRC program that grows with the business.
- Manage security compliance, data privacy, risk, and AI governance.
- Build an AI-first GRC program utilizing modern automation platforms and LLM-assisted workflows.
- Oversee Beacon's enterprise governance program, including security policy, AI governance, data governance and privacy, enterprise and third-party risk, and posture reporting.
- Lead governance initiatives for Beacon, pursuing relevant frameworks.
- Facilitate portfolio companies through audits and certifications such as SOC 2, ISO 27001, and accessibility conformance.
- Deliver hands-on support as a repeatable service to portfolio companies.
- Develop and implement a common control architecture to satisfy multiple standards.
- Implement AI-first automation for GRC processes.
- Ensure clear program reporting for both Beacon and portfolio companies.
Requirements
- Experience building or substantially maturing a GRC program.
- Experience taking an organization through SOC 2 Type 2.
- Typically 5+ years in GRC, IT governance, or security compliance.
- Demonstrated ability to automate manual processes.
- Strong systems thinking for designing scalable GRC architectures.
- Fluent with a compliance automation platform (e.g., Vanta, Drata, Secureframe).
- Current knowledge of AI tooling in practice.
- Comfortable with both security compliance and data privacy, or able to quickly learn new regimes.
- Excellent cross-functional communication skills, able to influence and translate requirements for technical and non-technical teams.
- Clear writing ability.
Skills
- Governance, Risk, and Compliance (GRC)
- Data Privacy
- Security Compliance
- AI Governance
- Risk Management
- Compliance Automation Platforms
- LLM-assisted Workflows
- SOC 2
- ISO 27001
- Accessibility Conformance
- Common Control Architecture
- Program Reporting
- Cross-functional Communication
- Systems Thinking
- Automation
Location
- Remote
Work Type
- Full-time
Experience Level
- 5+ years in GRC, IT governance, or security compliance
Education Level
- Privacy or audit certifications (CIPP, CIPM, CISA, CISSP, or ISO 27001 Lead Auditor or Implementer) are a plus.
- Experience with regimes beyond SOC 2 (ISO 27001, PCI DSS, HIPAA, FedRAMP, StateRAMP) and accessibility conformance (WCAG, VPAT) are a plus.
- Technical fluency to scope program needs and partner with engineering is a plus.
- Multi-entity, private-equity, or holding-company experience is a plus.
- M&A security and privacy diligence experience is a plus.
About the Company
- Beacon Software acquires and operates a portfolio of vertical SaaS companies, focusing on scaling through software rather than just adding people.
- The company's thesis is that agentic operating systems can significantly lift the ceiling on operations, value creation, and deal sourcing, which are currently bottlenecked by human attention.
- Beacon has raised over $550M from prominent investors including General Catalyst, Lightspeed, D1 Capital, CPMG, and family offices of founders from Stripe, DoorDash, and Ramp.
- Beacon Software values Humility, Honesty, Hunger, and Horizon, aiming to build a generational software company over decades.
Equal Opportunity
- Beacon Software uses Artificial Intelligence and AI-enabled tools to assist with screening, reviewing, organizing and highlighting profiles and applications. AI does not make hiring decisions; every application is reviewed by a human, and all decisions are made by humans. The company is committed to a fair, thoughtful, and equitable experience for every candidate.
