Grc Lead (governance, Risk, And Compliance)

Replit

Foster City, CA, US
Competitive salary & equity; 401(k) program with 4...
3 days onsite (monday, wednesday, and friday)
8+ years grc or information security leadership experience
Deep experience with soc 2 and iso 27001 frameworks
Technical fluency in cloud architecture (gcp/aws)
Replit is seeking a GRC Lead to oversee their governance, risk, and compliance efforts, focusing on compliance automation and risk management within a high-growth startup environment. The ideal candidate will have extensive experience in GRC and information security, with a strong emphasis on technical fluency and cross-functional collaboration

Job Summary

  • The role involves architecting systems and processes that automate trust while guiding a team of GRC specialists across the organization.
  • You will own the Cybersecurity Risk Register and manage the evolution of compliance posture across SOC 2, ISO 27001, and future certifications.
  • Replit offers competitive salary and equity, 401(k) matching, flexible time off, and an autonomous work environment with hybrid office requirements.

Matching Summary

Match Score: 85

Replit is seeking a GRC Lead to oversee their governance, risk, and compliance efforts, focusing on compliance automation and risk management within a high-growth startup environment. The ideal candidate will have extensive experience in GRC and information security, with a strong emphasis on technical fluency and cross-functional collaboration.

Salary

Competitive Salary & Equity; 401(k) Program with 4% match; Health, Dental, Vision, Life Insurance, Paid Parental Leave, Commuter Benefits

Skills & Requirements

Must-have

  • 8+ years GRC or Information Security Leadership experience
  • Deep experience with SOC 2 and ISO 27001 frameworks
  • Technical fluency in cloud architecture (GCP/AWS)
  • Experience with GRC automation tools like Vanta or Drata
  • Ability to mentor GRC analysts and engineers

Nice-to-have

  • Familiarity with FedRAMP, ITAR, or AI regulations
  • Pragmatic approach balancing rigor with startup velocity
  • Strong collaboration skills with Sales and Legal teams
  • Experience managing third-party risk for AI providers

Key Requirements

  • 8+ years of experience in GRC or Information Security Leadership
  • Proven experience mentoring other GRC professionals
  • Deep regulatory breadth including PCI and HIPAA

Work Rights

Not specified

Tailored Resume

Cover Letter