Governance, Risk, and Compliance Manager - Privacy at Decagon | CA, US | Rezi

Governance, Risk, and Compliance Manager - Privacy at Decagon

Governance, Risk, and Compliance Manager - Privacy

Decagon · CA, US

1 months ago

Governance, Risk, and Compliance Manager - Privacy

Decagon · CA, US

a month ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now
Resume preview

Tailor your resume to this Governance, Risk, and Compliance Manager - Privacy role.

Rezi rewrites your resume against Decagon's job description. Free.

Resume score gauge reading 58 out of 100

Don't guess if your resume is good enough.

See how it scores against the Governance, Risk, and Compliance Manager - Privacy posting at Decagon — free, in seconds.

About the Role

Join Decagon as a Governance, Risk, and Compliance Manager and play a critical role in securing customer trust as we scale to serve Fortune 500 and international enterprises. Working closely with the head of security and compliance, you'll be responsible for the day-to-day execution of our compliance program and customer security engagements. This is a high-impact role where you'll directly contribute to closing enterprise deals by efficiently managing security communications with customers, supporting compliance audits, and improving our security documentation. Perfect for someone who thrives in a high impact organization with attention to detail, excellent writing skills, and who wants to build expertise in enterprise AI compliance.

Responsibilities

  • Improve and maintain the privacy program against ISO 27701, ISO 27018, HIPAA, GDPR, CCPA/CPRA and the wider set of US state laws.
  • Own Decagon's privacy program operations end to end: data inventory, DSAR intake and fulfillment, DPAs and cross-border transfer mechanisms, data retention schedule, subprocessor onboarding and our public subprocessor list, breach notification readiness, and company-wide privacy training.
  • Partner with legal team to improve existing programs on data residency, subprocessor flow-downs, retention by data class, DPIAs and transfer impact assessments, while owning and driving day-to-day decision.

Requirements

  • 5+ years of GRC experience in high-growth SaaS or technology companies, with direct responsibility for privacy compliance programs
  • Proven track record successfully contributing to SOC 2, ISO 27001, or similar enterprise compliance certifications
  • Experience in data privacy regulations including CCPA, GDPR, and emerging AI governance frameworks
  • Strong project management skills with ability to coordinate cross-functional teams under tight deadlines
  • Excellent written and verbal communication skills to translate complex security concepts for diverse audiences
  • Working knowledge of technical security controls and ability to collaborate effectively with engineering teams

Skills

  • ISO 27701
  • ISO 27018
  • HIPAA
  • GDPR
  • CCPA/CPRA
  • US state laws
  • Data inventory
  • DSAR intake and fulfillment
  • DPAs
  • Cross-border transfer mechanisms
  • Data retention schedule
  • Subprocessor onboarding
  • Public subprocessor list
  • Breach notification readiness
  • Company-wide privacy training
  • Data residency
  • Subprocessor flow-downs
  • Retention by data class
  • DPIAs
  • Transfer impact assessments
  • SOC 2
  • ISO 27001
  • AI governance frameworks
  • Project management
  • Written communication
  • Verbal communication
  • Technical security controls
  • AI/ML compliance frameworks
  • Conversational AI systems
  • Healthcare compliance
  • Financial services compliance
  • PCI requirements
  • GRC platforms
  • Vanta
  • Drata
  • SecureFrame
  • Cloud security
  • Google Cloud Platform compliance
  • Google Cloud Platform security features

Work Type

  • In-office

Experience Level

  • 5+ years of GRC experience

Salary/Compensations

  • $190K – $275K + Offers Equity

Benefits

  • Medical, Dental, and Vision benefits for you and your family
  • Life Insurance and Disability Benefits
  • Retirement Plan (e.g., 401K, pension)
  • Parental Leave
  • Fertility and family building benefits through Carrot
  • Monthly stipend to support your wellness, lifestyle, and work-life balance
  • Daily lunches and snacks in the office to keep you at your best
  • Take what you need vacation policy

About the Company

  • Decagon is the leading conversational AI platform empowering every brand to deliver concierge customer experiences.
  • Our technology enables industry-defining enterprises like Avis Budget Group, Block’s Cash App and Square, Chime, Oura Health, and Hunter Douglas to deploy AI agents that power personalized, deeply satisfying interactions across voice, chat, email, SMS, and every other channel.
  • We’re building a future where customer experiences are being redefined from support tickets and hold music to faster resolutions, richer conversations, and deeper relationships.
  • We’re proud to be backed by world-class investors who share that vision, including a16z, Accel, Bain Capital Ventures, Coatue, and Index Ventures, along with many others.
  • We’re an in-office company, driven by a shared commitment to excellence and velocity.
  • Our values — Just Get It Done, Invent What Customers Want, Winner’s Mindset, and The Polymath Principle — shape how we work and grow as a team.