Director of GRC at The San Francisco Compute Company | CA, US | Rezi

Director of GRC at The San Francisco Compute Company

Director of GRC

The San Francisco Compute Company · CA, US

1 weeks ago

Director of GRC

The San Francisco Compute Company · CA, US

14 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now
Resume preview

Tailor your resume to this Director of GRC role.

Rezi rewrites your resume against The San Francisco Compute Company's job description. Free.

Resume score gauge reading 58 out of 100

Don't guess if your resume is good enough.

See how it scores against the Director of GRC posting at The San Francisco Compute Company — free, in seconds.

About the Role

As Director of GRC, you will own governance, risk, and compliance at SFCompute, build the team that runs it, and set the function's strategy and operating cadence. You will personally build and drive the program of work from day one, designing controls, running tooling, and managing auditors until the team is in place. This is a build role focused on designing new functions and processes.

Responsibilities

  • Hire, manage, and develop the GRC team from day one, setting its structure, priorities, and operating cadence, and owning its results.
  • Own our SOC 2 Type 2 program and lead ISO 27001 certification end to end, including readiness, gap remediation, control implementation, auditor management, and continuous monitoring.
  • Stand up enterprise risk management, including risk assessments, the risk register, treatment plans, and reporting to leadership.
  • Author and operationalize policies and functions for a maturing company, such as access reviews, business continuity, security awareness, and vendor management.
  • Collaborate with departments to ensure change management and incident response policies are sensible and meet compliance obligations.
  • Own our compliance automation platform, Vanta, and drive selection and integration of GRC-related tooling.
  • Own vendor security reviews and third-party risk assessments.

Requirements

  • Prior startup experience in a high-impact, senior capacity.
  • Personally taken a company through an ISO 27001 certification for the first time.
  • Prior experience in a senior, high-impact GRC or security compliance role at a startup, having built programs under resource constraints.
  • Hands-on experience driving a company through its first ISO 27001 certification, from readiness through audit.
  • Experience owning or running a SOC 2 program.
  • Proven people leadership experience, including hiring, managing, and developing a team.
  • Comfortable working cross-functionally with engineering on controls, tooling, and technical remediation.

Skills

  • GRC
  • Security compliance
  • ISO 27001 certification
  • SOC 2
  • Risk management
  • Policy design
  • Process design
  • Access reviews
  • Business continuity
  • Security awareness
  • Vendor management
  • Change management
  • Incident response
  • GRC tooling
  • Vanta
  • Third-party risk assessment
  • CISA
  • CISM
  • CISSP
  • CRISC
  • ISO 27001 Lead Implementer/Auditor
  • Privacy program experience (GDPR/CCPA)

Location

  • San Francisco

Work Type

  • Full-time

Experience Level

  • Director
  • Senior

Salary/Compensations

  • Competitive salary

Benefits

  • Generous equity grant
  • Competitive salary
  • Visa Sponsorships
  • 401(k) matching up to 4%
  • Medical, dental, vision insurance (100% premium coverage)
  • Unlimited paid time off
  • 10+ observed holidays
  • Paid parental leave (biological, adoptive, and foster parents)
  • Daily lunch coverage
  • Unlimited office book budget

About the Company

  • Building a company that de-risks the largest infrastructure build-out in history by creating a liquid market for GPU offtake.
  • Enabling companies to exit GPU offtake contracts by selling them back to the market.
  • Addressing the challenge of AI scaling where compute availability is limited to those who can take on significant risk.

Equal Opportunity

  • The San Francisco Compute Company is committed to maintaining a workplace free from discrimination and harassment.
  • Employment decisions are based on business needs, job requirements, and individual qualifications, without regard to race, color, religion, belief, national origin, social or ethical origin, age, physical, mental, or sensory disability, sexual orientation, gender identity or expression, marital status, civil union or domestic partnership status, past or present military service, HIV status, family medical history or genetic information, family or parental status including pregnancy, or any other status protected by law.
  • Welcomes qualified applicants with prior arrest or conviction records, in accordance with local, state, and federal laws, including San Francisco’s Fair Chance Ordinance and California’s ban-the-box laws.