Beacon Software

Director - Governance, Risk, Compliance & Privacy (GRC)

Full-time · San Francisco, CA (Remote)
✓ Verified live on the employer's own system · added 20 days ago
Save search
Mid-level · 3+ yrs exp

Requirements

Experience: 3+ years

Skills & tools

SecurityMachine LearningEmbeddedServing
Apply on company site ↗ See your fit → free

Full job description

We are looking for a GRC leader to build and scale the governance, risk, compliance, and privacy function for a growing portfolio of software companies. This is a founding, high-ownership role for someone who has built before and treats automation and modern AI tooling as the default way to operate.

Beacon has raised $550M+ from investors including General Catalyst, Lightspeed, D1 Capital, CPMG, and the family offices of the founders of Stripe, DoorDash, and Ramp.

Our GRC function is at an early, formative stage. You would shape it from the foundations and scale it across the portfolio, working directly with our portfolio companies to take them through their own audits and certifications, and designing a program that grows with the business rather than one built for a single audit.

The mandate spans security compliance, data privacy, risk, and AI governance. We expect it to be built AI-first: modern automation platforms and LLM-assisted workflows over manual process.

- Beacon. The holdco's enterprise governance program: security policy, AI governance, data governance and privacy, enterprise and third-party risk, and posture reporting. Governance-led, including any frameworks Beacon itself elects to pursue.

- Portfolio companies. Taking our portfolio companies through their own audits and certifications (SOC 2, ISO 27001, accessibility conformance, and others as their customers require), delivered hands-on as a repeatable service that scales across the portfolio.

Underpinning both: a common control architecture that maps a control once to satisfy many standards, AI-first automation, and clear program reporting.

- You have built or substantially matured a GRC program before and taken an organization through SOC 2 Type 2. Typically several years (5+) in GRC, IT governance, or security compliance, though what you have built matters more to us than the count.

- A builder with a bias for action. When you see a manual process, your first instinct is how to automate it.

- A strong systems thinker. You design scalable GRC architectures, not one-off fixes for the next audit.

- Fluent with a compliance automation platform (Vanta, Drata, Secureframe, or similar) and current on AI tooling in practice, not just in theory.

- Comfortable across both security compliance and data privacy, or able to ramp quickly on regimes you have not personally run.

- An excellent cross-functional communicator who works through influence and can translate compliance requirements into terms both technical and non-technical teams can act on.

- Privacy or audit certifications (CIPP, CIPM, CISA, CISSP, or ISO 27001 Lead Auditor or Implementer).

- Experience with regimes beyond SOC 2 (ISO 27001, PCI DSS, HIPAA, FedRAMP, StateRAMP) and accessibility conformance (WCAG, VPAT).

- Enough technical fluency to scope what the program needs and partner closely with engineering, even without building the tooling yourself.

- Multi-entity, private-equity, or holding-company experience.

More jobs at Beacon Software

Similar jobs near San Francisco, CA (Remote)

Tell me when more Research Engineer, Privacy jobs post near San Francisco (Remote) We re-check every listing against the employer’s own board — no résumé needed.

Search Director - Governance, Risk, Compliance & Privacy (GRC) jobs near San Francisco, CA (Remote) → Browse all live jobs

This posting was published by Beacon Software on their own careers system and is shown here with a direct link to apply there. Employers: for corrections or removal, contact jobs@veritahire.com.