Jobs · Information Technology · Utah

GRC Program Manager

Tandem Ventures · Draper, UT · 1 wk ago
Information TechnologyFull-time

Redo is an e-commerce growth platform. We help merchants personalize every step of the buyer journey to maximize profit and lifetime value, with solutions spanning returns, warranties, order tracking, and post-purchase communications. We're growing fast, moving quickly, and building the systems that let some of the best brands in commerce trust us with their customers.

About The Role

Security and compliance are core to how Redo operates and how our merchants trust us with their customers. We're growing explosively, and as we scale, we're investing in a dedicated owner to take our governance, risk, and compliance program to the next level. This is a rare blue-ocean opportunity to own GRC end to end. You'll deepen and expand our compliance across SOC 2, GDPR, CCPA, and emerging frameworks, setting the strategy, owning the execution, and shaping how security is built into the company. You'll also work directly with our merchants, where a strong security story helps close deals, and partner with engineering to turn compliance requirements into concrete controls.

Responsibilities

  • Own, mature, and scale Redo's GRC program end to end — SOC 2, GDPR, CCPA, PCI, HIPAA, and additional frameworks as our merchant base demands them.
  • Partner closely with engineering to translate framework and control requirements into clear, actionable technical and engineering requirements — and ensure they get implemented and stay implemented.
  • Own audit readiness: lead audits and assessments, manage auditor relationships, and run evidence collection and continuous control monitoring.
  • Lead compliance sales enablement by responding to merchant and prospect security reviews — questionnaires, due-diligence requests, and trust/security documentation — and turn it into a low-friction process that smooths sales deals.
  • Build and maintain security policies, standards, and procedures, and drive their adoption across the company.
  • Manage third-party/vendor risk management.
  • Own our GRC tooling and automation, and drive continuous compliance rather than point-in-time scrambles.
  • Lead AI enablement of the compliance program — automate evidence collection, control monitoring, security-questionnaire responses, and documentation so the program scales faster than headcount.
  • Manage access reviews, security awareness training, and evidence of ongoing operating effectiveness.
  • Keep leadership informed on compliance posture, gaps, and progress, and represent Redo's security program to customers and partners.

Requirements

  • 5+ years in GRC, security compliance, or a closely related role, with hands-on ownership (not just support) of at least one full compliance program.
  • Demonstrated experience taking a company through a full SOC 2 certification and continued surveillance.
  • Depth of experience helping SaaS platforms support GDPR and data privacy obligations.
  • Experience navigating HIPAA and PCI environments.
  • A self-directed operator who can own and mature a program with minimal oversight — you know what "good" looks like and can drive it independently.
  • Ability to translate control requirements into engineering requirements and collaborate credibly with software engineers.
  • Experience responding to customer security reviews and security questionnaires.
  • Strong writing and communication skills — you can produce clear policies and explain security posture to both engineers and non-technical stakeholders.
  • Comfortable in a fast-moving, high-growth environment where you set the pace.
  • Experience using AI for custom compliance automation.

Nice to Have

  • Relevant certifications such as CISA, CISSP, ISO 27001 Lead Implementer/Auditor, or CIPP/E.
  • Experience with GRC automation platforms (e.g., Vanta, Drata, Secureframe).

Benefits

  • Work with a dynamic, innovative team in the fast-growing ecommerce industry.
  • Opportunities for career growth and advancement.
  • On-site gym with showers, pickleball, and basketball.
  • Flexible PTO & company holidays.
  • Redo perks: monthly allowance to support purchases from ecommerce stores.
  • Company HSA contributions.
  • Weekly lunches & fully stocked break room.
  • $100 monthly babysitting reimbursement.
  • Office is minutes from biking and running trails.

Similar jobs

Program Manager

Horizon Treatment ServicesSan Jose, CA· 2 mo ago
Information Technology$90k–$95k/yrapply on horizonservices.applytojob.com

Program Manager

People, Technology & Processes, LLCMobile, AL· 2 mo ago
Information Technology

Program Manager

Masonic Villages of PennsylvaniaElizabethtown, PA· 1 mo ago
Information Technologyapply on masonicvillageatelizabethtown.recruitpro.com

Program Manager

Choices in Community Living, Inc.Dayton, OH· 1 mo ago
Information Technologyapply on cicljobs.applicantpool.com

Program Manager

AtkinsRéalisOklahoma City, OK· 1 mo ago
Information Technology$175k–$200k/yrapply on careers.atkinsrealis.com

Program Manager

LeidosSt Louis, MO· 1 mo ago
Project Management$108k–$195k/yrapply on careers.leidos.com