Head of GRC (Governance, Risk, & Compliance)
About Blitzy
Blitzy is a Cambridge, MA-based AI software development platform dedicated to revolutionizing the software development lifecycle through autonomous software creation. Backed by tier 1 investors, Blitzy has a proven track record in founding successful startups.
Location
1 Kendall Square, Cambridge, MA
On-site
Compensation
$220,000 - $260,000 plus bonus and equity, commensurate with experience
The Role
Security and compliance at Blitzy currently rely on a patchwork approach, with a Security Delegate managing frameworks, backend engineers handling compliance, and audit evidence compiled post-audit. We're seeking a Head of GRC to address these inefficiencies by creating an audit-ready compliance program.
What Success Looks Like
- Identify gaps before auditors discover them.
- Run SOC 2 Type II and ISO 27001:2022 cycles personally.
- Own Vanta (or equivalent GRC platform) as the single source of truth.
- Manage auditor and compliance partner relationships directly.
- Reduce engineering interruptions by taking security scope questions off their plates.
- Write clear policies, audit narratives, and questionnaire responses that withstand scrutiny.
Areas of Ownership
- Proactive Compliance & GRC Ownership
- Own Vanta (or equivalent) as the system of record
- Run SOC 2 Type II and ISO 27001:2022 compliance cycles
- Manage auditor and partner relationships directly
- Evaluate evidence critically
Required Experience
- Personal, hands-on ownership of at least one full SOC 2 Type II or ISO 27001:2022 audit cycle.
- Direct experience running a GRC/compliance platform (Vanta or equivalent).
- Track record of managing vendor and auditor relationships independently.
- Seniority and judgment to reduce engineering interrupt load.
What Makes You Stand Out
- FedRAMP exposure, even at Moderate.
- Track record of building a compliance process from scratch.
- Experience managing multiple frameworks concurrently.
- Familiarity with Google Workspace as an identity provider.
- Data privacy program experience, including GDPR, cookie consent, Article 27 representative coordination, and DPA review.
What Makes This Role Different
You'll have direct ownership of a function currently split across engineering, a Security Delegate, and an external vendor, with full autonomy to build it right from day one. This includes a seat at the table on FedRAMP, one of the most demanding compliance programs a company can pursue.
Culture
We are a fast-growing company in the U.S., creating our own category of enterprise autonomous software development. We automate thousands of hours of software development for our customers, including strong representation within the Fortune 500. Our culture is driven by:
- Blitzy Moves Fast: Time is both our company's and our clients' most precious asset. We move quickly and decisively to innovate internally and deliver exceptional software externally.
- Championship Mindset: We operate like a professional sports team. We win as a team by holding ourselves and each other to high standards, collaborating in-person, and remaining focused on the mission.
- Passion for Invention: We're pushing the frontier of what's possible, requiring constant innovation and iteration.
- We Work for the Customer: We focus on delivering outsized value to the customers we work with and expanding those relationships into deep, meaningful partnerships.
- We believe in being 'everyday athletes': taking care of ourselves so we can bring our best minds to work. We promote great sleep, movement, and restorative activities for optimal mental performance.
We are an equal opportunity employer committed to building a diverse and inclusive team. We believe different perspectives make us stronger.