Governance, Risk, and Compliance Manager
TensorWave · Las Vegas, NV · 6 days ago
On-siteFinanceFull-time
About the role
This role is for a Governance, Risk & Compliance Manager who will design, implement, and continuously test a unified controls framework, including IT General Controls (ITGCs), across a growing regulatory landscape. They will also run audits in-house, build the SOX roadmap, stand up vendor & third party risk, operationalize a risk register, enable the business, shift compliance left, optimize the policy program, and provide leadership visibility into risk.
Responsibilities
- Own the GRC framework
- Design, implement, and continuously test a unified controls framework, including IT General Controls (ITGCs), across a growing regulatory landscape
- Run audits in-house
- Maintain and mature our SOC 2 Type II and ISO 27001 certifications, driving toward automated, continuous evidence collection instead of manual scramble before audit cycles
- Build the SOX roadmap
- Design and test internal controls over financial reporting (ICFR) and ITGCs aligned to AICPA / PCAOB standards, delivering a gap analysis and remediation roadmap that keeps us futureready
- Stand up vendor & third party risk
- Operationalize a risk register
- Run formal, continuous internal risk assessments, map them to a corporate risk register, and review it quarterly with leadership to prioritize security spend
- Enable the business
- Build and maintain a centralized Trust Center that cuts the time sales and engineering spend answering security questionnaires
- Shift compliance left
- Partner with engineering to embed compliance into the development lifecycle so new features ship without breaking existing controls
- Optimize the policy program
- Maintain a policy suite that satisfies legal and security requirements while minimizing overhead on the teams that support our growth
Requirements
- 5–8+ years in Information Security, IT Audit, or GRC
- Hands-on experience designing, implementing, and defending controls for SOC 2 Type II, ISO 27001, SOX, and/or PCI DSS
- Strong working knowledge of Sarbanes-Oxley compliance, including evidence preparation to AICPA or PCAOB standards
- A track record spanning both fast-paced Series B/C startups and a mature enterprise or Big 4 audit environment: you've built processes from scratch and you've seen what "good" looks like at scale
- Comfortably operates as a hands-on owner, not just a program overseer
Preferred Qualifications
- Experience with API-driven / continuous GRC tooling (e.g., Vanta, Drata, or similar)
- Exposure to cloud or GPU infrastructure security
- Relevant certifications (CISA, CISSP, CRISC, ISO 27001 Lead Auditor/Implementer)
- Experience embedding compliance into CI/CD pipelines
Benefits
- Stock Options
- 100% paid Medical, Dental, and Vision insurance for Employees
- Company Health Savings Account Contributions
- 100% paid Short Term and Long Term Disability Insurance for Employees
- Life and Voluntary Supplemental Insurance Options
- Various Supplementary Health Benefits, such as discounted Virtual Healthcare Appointments and Serious Illness Support
- Flexible Spending Account
- 401(k)
- Employee Assistance Program
- Paid Holidays
- Parental Leave
- Other In-Office Perks
Pay
TBD
Schedule
TBD