Security GRC Lead
San Francisco • FullTime
Posted 5d ago
About the job
Mercor is seeking a Security GRC Lead to establish and own the company's compliance posture. As the first GRC hire, you will be responsible for building and managing the operating cadence of a continuously audited company, including SOC 2 monitoring, ISO 27001 implementation, and managing customer audits. This role involves writing controls in code, pushing back on inefficient tools, and producing artifacts crucial for closing enterprise deals. You will leverage AI extensively in GRC tasks, such as drafting and reviewing responses, to improve efficiency and speed.
Responsibilities
- Establish and own the company's compliance operating cadence, including SOC 2 Type 2, ISO 27001, and future frameworks.
- Develop a customer-audit process to efficiently respond to questionnaires and provide evidence packs.
- Implement and manage a third-party risk program, integrating it with procurement.
- Oversee the policy lifecycle from versioning to exception handling and review.
- Implement controls-as-code where applicable, integrating with tools like Vanta and Panther.
- Define and manage data-handling procedures, including customer data deletion and DSAR workflows.
- Develop the internal trust narrative for customers, including trust pages and disclosure templates.
Requirements
- 7+ years in security GRC, compliance engineering, or audit.
- At least 2 years owning a SOC 2 Type 2 program end-to-end at a company audited by enterprise customers.
- Experience shipping at least one ISO 27001 certification from kickoff to issuance.
- Fluent in Vanta (or similar tools like Drata, Secureframe, Sprinto) at the integration and admin level.
- Experience on the company side of at least one enterprise customer audit conducted by a Big 4 firm.
- Ability to translate cloud security concepts to auditor language and vice versa.
- Experience writing controls as code or querying evidence with SQL, Python, or shell.
- Understanding of the difference between having a control and a compensating control.
- Direct experience with customer trust surfaces like SIG, CAIQ, and custom questionnaires.
Benefits
- Opportunity to build the GRC function from the ground up.
- Direct impact on closing deals and seeing revenue downstream.
- AI-native GRC environment with engineering support for tooling.
- Direct line of communication with auditors, customers, and legal counsel.
- Support from a robust security organization (TachTech, Latacora, Mandiant).