Hightouch Logo

Hightouch

GRC Lead

Posted 4 Days Ago
Remote
Hiring Remotely in USA
160K-230K Annually
Senior level
Remote
Hiring Remotely in USA
160K-230K Annually
Senior level
Own customer security reviews, questionnaires, due diligence, audits, and the company’s SOC 2 and ISO 27001 compliance programs. Lead practical risk decisions, maintain accurate security responses and evidence, coordinate remediation, assess external partners, and automate compliance workflows. Partner closely with engineering, security, IT, legal, and customer-facing teams to improve controls, documentation, and product security outcomes.
The summary above was generated by AI
About Hightouch

Hightouch is an Agentic Marketing Platform powered by the industry-leading Composable CDP. With complete brand context, customer data, and performance history in one place, every marketer finally has the power to build and ship end-to-end campaigns themselves. Teams move faster, stay on brand, and get AI marketing that actually works.

Founded in 2019 and headquartered in San Francisco, Hightouch enables marketing teams to analyze performance, brainstorm ideas, and generate creative at a speed and quality that wasn't previously possible.

Named a Leader in the 2026 Gartner® Magic Quadrant™ for Customer Data Platforms, Hightouch is trusted by leading enterprises like Domino's, Spotify, Aritzia, Cars.com, Ramp, and PetSmart.

At Hightouch, our mission is to help our customers leverage data and AI to grow their businesses. The team is ambitious, impact-driven, efficient — and we believe humility, kindness, and compassion are essential to our success. If you're energized by velocity, obsessed with raising the bar, and want to build alongside people who care deeply about each other and our customers, we'd love to meet you.

About the Role

We’re hiring our first dedicated GRC Lead to own customer security assurance and our compliance program. Your first priority will be making customer security reviews fast and accurate, alongside ownership of audits, compliance obligations, and risk follow-through.

We build quickly, and this role requires someone who can keep pace. You’ll understand the risks behind customer requirements, make practical recommendations, and drive decisions through to completion. You’ll have substantial autonomy and work directly with engineering, security, IT, legal, and our customer-facing teams.

We’re open to experienced individual contributors, managers who enjoy hands-on work, and people looking to grow into management. You’ll initially handle questionnaires, customer conversations, and audits directly, using AI and automation to increase what a small team can accomplish. As the function grows you’ll be able to grow with it.

What You’ll Own
  • Customer security reviews. Own questionnaires, due diligence, and customer security calls. Use AI to accelerate research and drafting, apply your own judgment to ensure precision, and resolve unfamiliar questions with the right technical experts.

  • Practical risk decisions. Help teams work through customer security requirements, vendor concerns, and compliance gaps. Understand what’s at stake, bring the right people together, and make sure decisions have clear owners and follow-through.

  • Reliable security answers. Maintain approved responses and supporting evidence. Use AI to surface inconsistencies and outdated information, and ensure answers accurately reflect differences across products, configurations, and planned capabilities.

  • Compliance strategy and audits. Own our SOC 2 and ISO 27001 programs, set priorities for external partners, assess their work, and close gaps. Ensure controls remain effective between audits, reuse controls across frameworks, and automate evidence collection. Evaluate new programs based on customer demand, the markets we want to enter, and the cost to implement and maintain them.

  • Execution and follow-through. Track commitments and remediation with clear owners and deadlines. Build automation and self-service resources that reduce repetitive work, and turn recurring customer questions into improvements to documentation, controls, and product.

About You

You’ve personally owned a compliance program or major audit cycle, and have hands-on experience with customer security reviews.

You bring:

  • Judgment. You can describe tradeoffs you’ve made, the risks you accepted or escalated, and why those decisions were reasonable.

  • Technical curiosity. You dig into how systems work and can discuss data flows, access controls, cloud infrastructure, and data storage with engineers.

  • AI fluency and attention to detail. You build AI-assisted workflows and catch convincing but unsupported answers. You know which details materially change a claim and how to verify them.

  • Clear writing and credible customer communication. You explain our security posture accurately, including when the answer is complicated or a capability doesn’t yet exist.

  • Ownership and urgency. You make progress with incomplete information, communicate clearly, and close loops without repeated prompting.

  • A builder’s approach. You’ve simplified a process, automated recurring work, or found a faster way to satisfy a requirement—and can explain the result.

Similar Jobs

10 Days Ago
Remote
USA
165K-223K Annually
Senior level
165K-223K Annually
Senior level
Artificial Intelligence • Machine Learning • Natural Language Processing • Software • Conversational AI
Own Deepgram’s privacy operations, security compliance, audit evidence, control mapping, security questionnaires, policies, and public trust documentation. Lead DPIAs, data-flow mapping, DSAR and deletion workflows, vendor reviews, SOC 2, ISO 27001, and PCI DSS audits. Partner with Engineering, Legal, Research, and Sales Engineering to verify technical claims, automate evidence collection, maintain accurate documentation, and translate privacy and AI regulations into practical requirements and enablement.
Top Skills: Ccpa/CpraDrataEu Ai ActGdprIso 27001Iso/Iec 42001Nist Ai RmfPci DssSoc 2SQLUk GdprVanta
3 Days Ago
Remote
United States
174K-224K Annually
Senior level
174K-224K Annually
Senior level
Fintech
Build and operate Dave’s technology governance program covering cyber risk, IT controls, change and incident management, business continuity, policies, and audit readiness. Own control inventories, risk registers, exceptions, assurance programs, and remediation accountability across SOX ITGC, PCI, SOC 2, and related frameworks. Partner with Security, IT, Engineering, Data, Internal Audit, Legal, and external assessors to establish practical controls, escalate material risks, and improve governance through automation and AI while maintaining appropriate oversight.
Top Skills: Ci/CdCloudData PlatformsDrataEndpoint SecurityIdentity And Access ManagementIso 27001NetworksNistPci DssSoc 2 Type IiSource ControlSox ItgcVanta
23 Days Ago
Remote
Georgia, USA
Entry level
Entry level
Fintech • Financial Services
Owns information security risk management, control assurance, and ISO 27001 ISMS governance across a regulated fintech group. Responsibilities include maintaining risk and control registers, assessing control design and effectiveness, testing evidence, tracking remediation, defining security metrics, and preparing governance reporting. The role partners closely with the Group CISO and control owners to challenge risk assessments, manage residual risk, and maintain security policies, exceptions, and compliance documentation.
Top Skills: Cloud SecurityData ProtectionEndpoint SecurityGrc PlatformsIamIsmsIso 27001Secure DevelopmentSecurity MonitoringVulnerability Management

What you need to know about the Seattle Tech Scene

Home to tech titans like Microsoft and Amazon, Seattle punches far above its weight in innovation. But its surrounding mountains, sprinkled with world-famous hiking trails and climbing routes, make the city a destination for outdoorsy types as well. Established as a logging town before shifting to shipbuilding and logistics, the Emerald City is now known for its contributions to aerospace, software, biotech and cloud computing. And its status as a thriving tech ecosystem is attracting out-of-town companies looking to establish new tech and engineering hubs.

Key Facts About Seattle Tech

  • Number of Tech Workers: 287,000; 13% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Amazon, Microsoft, Meta, Google
  • Key Industries: Artificial intelligence, cloud computing, software, biotechnology, game development
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Madrona, Fuse, Tola, Maveron
  • Research Centers and Universities: University of Washington, Seattle University, Seattle Pacific University, Allen Institute for Brain Science, Bill & Melinda Gates Foundation, Seattle Children’s Research Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account