Director of GRC

Posted Yesterday
Be an Early Applicant
San Francisco, CA, USA
In-Office
180K-250K Annually
Expert/Leader
Artificial Intelligence • Cloud • Information Technology • Infrastructure as a Service (IaaS)
The Role
Own and build SFCompute’s governance, risk, and compliance function. Lead the SOC 2 Type 2 program, drive first-time ISO 27001 certification, establish enterprise risk management, design policies and controls, manage third-party risk, operate Vanta, oversee auditors, and hire and develop the GRC team.
Summary Generated by Built In

We're building the company which will de-risk the largest infrastructure build-out in history.

When people finance GPU clusters, the datacenters housing them, and the infrastructure powering them, they need "offtake" - meaning someone has signed a contract to lease the cluster for a period of time before its even built.

Financing a GPU cluster is inherently risky, since margins are thin and volumes are huge. Lenders don't want to take on the risk that cluster developers can't repay their loan, and cluster developers really don't want to risk not selling their cluster. As a result, risk is offloaded to the customer using fixed-price long-term contracts.

If you don't mitigate this customer risk, there's a bubble. This isn't SaaS anymore - application layer companies sign multi-year contracts for computer and inference, but sell to customers on monthly subscriptions. If you mess up a purchase, it's game over: a minor shift in your revenue growth rate might mean the difference between profit or bankruptcy. But what if companies could exit their contract by selling it back to the market?

Otherwise, as AI scales, compute only becomes available to folks who can effectively take on that risk. A 2-person startup in a San Francisco Victorian can't realistically sign a 5-year take or pay contract on $100m supercomputers. But they may be able to buy the month of liquidity that someone else sold back.

So that's what we make: a liquid market for GPU offtake.

About the Role

As Director of GRC, you'll own governance, risk, and compliance at SFCompute and build the team that runs it - starting with you as the first hire. We've completed our first SOC 2 audit and are pursuing ISO 27001 next. These two - maintaining SOC 2 and obtaining ISO 27001 - are the committed mandate.

Reporting to engineering leadership, you'll set the function's strategy and operating cadence, hire and manage a small GRC team, and personally build and drive the program of work from day one - designing controls, running the tooling, and managing auditors yourself until the team is in place to take it on. Much of what your team will run doesn't exist yet - the mandate is to design new functions and processes, not inherit them.

This is a build role. You should have prior startup experience in a high-impact, senior capacity, and you should have personally taken a company through an ISO 27001 certification for the first time - not just maintained one that was already in place.

About You
  • Prior experience in a senior, high-impact GRC or security compliance role at a startup - you've built programs under resource constraints, not just operated within an already-mature function.

  • Hands-on experience driving a company through its first ISO 27001 certification, from readiness through audit - standing up the program, not inheriting one already in place.

  • Experience owning or running a SOC 2 program.

  • Proven people leadership - you've hired, managed, and developed a team before.

  • Comfortable working cross-functionally with engineering on controls, tooling, and technical remediation.

Responsibilities
  • Team Leadership: Hire, manage, and develop the GRC team from day one - set its structure, priorities, and operating cadence, and own its results.

  • Compliance Program Ownership: Own our SOC 2 Type 2 program and lead ISO 27001 certification end to end - readiness, gap remediation, control implementation, auditor management, and continuous monitoring.

  • Risk Management: Stand up enterprise risk management - risk assessments, the risk register, treatment plans, and reporting to leadership.

  • Policy & Process Design: Author and operationalize the policies and functions a maturing company needs: access reviews, business continuity, security awareness, and vendor management. Collaborate with departments to ensure change management and incident response policies are sensible and meet compliance obligations.

  • GRC Tooling: Own our compliance automation platform, Vanta, and drive selection and integration of GRC-related tooling.

  • Third-Party Risk: Own vendor security reviews and third-party risk assessments.

Nice to Haves
  • Hold relevant certifications such as CISA, CISM, CISSP, CRISC, or ISO 27001 Lead Implementer/Auditor.

  • Have operated compliance automation platforms (Vanta or similar).

  • Have privacy program experience (GDPR/CCPA).

BenefitsGenerous equity grant

Team members are offered a competitive salary along with equity in the company

Visa Sponsorships

Yes, we sponsor visas and work permits

Retirement matching

We match 401(k) plans up to 4%

Medical, dental & vision

We offer competitive medical, dental, vision insurance for employees and dependents and cover 100% of premiums

Time off

We offer unlimited paid time off as well as 10+ observed holidays

Parental leave

We offer biological, adoptive, and foster parents paid time off to spend quality time with family

Daily lunch

We cover lunch daily for employees

Unlimited office book budget

You can buy as many books for the office as you want

The San Francisco Compute Company is committed to maintaining a workplace free from discrimination and harassment.

We make employment decisions based on business needs, job requirements, and individual qualifications, without regard to race, color, religion, belief, national origin, social or ethical origin, age, physical, mental, or sensory disability, sexual orientation, gender identity or expression, marital status, civil union or domestic partnership status, past or present military service, HIV status, family medical history or genetic information, family or parental status including pregnancy, or any other status protected by law.

We welcome the opportunity to consider qualified applicants with prior arrest or conviction records. Our commitment to diversity includes hiring talented individuals regardless of their criminal history, in accordance with local, state, and federal laws, including San Francisco’s Fair Chance Ordinance and California’s ban-the-box laws.

Skills Required

  • Senior, high-impact GRC or security compliance experience at a startup
  • Hands-on experience leading a company through its first ISO 27001 certification from readiness through audit
  • Experience owning or running a SOC 2 program
  • Experience hiring, managing, and developing a team
  • Ability to work cross-functionally with engineering on controls, tooling, and technical remediation
  • CISA, CISM, CISSP, CRISC, or ISO 27001 Lead Implementer/Auditor certification
  • Experience operating Vanta or a similar compliance automation platform
  • Privacy program experience with GDPR or CCPA
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
30 Employees
Year Founded: 2023

What We Do

San Francisco Compute Company operates a marketplace for large-scale GPU clusters, enabling users to buy and sell compute contracts with flexible terms. They aim to make AI compute more accessible and affordable by creating a liquid market for GPU offtake.

Similar Jobs

In-Office
San Francisco, CA, USA
6000 Employees
264K-363K Annually

CSC Logo CSC

Client Service Representative

Fintech • Legal Tech • Software • Financial Services • Cybersecurity • Data Privacy
Remote or Hybrid
2 Locations
8500 Employees
50K-55K Annually

Affirm Logo Affirm

Workplace Specialist II

Big Data • Fintech • Mobile • Payments • Financial Services
Easy Apply
In-Office
San Francisco, CA, USA
2200 Employees
100K-120K Annually

LogicMonitor Logo LogicMonitor

AI Growth Strategist

Artificial Intelligence • Cloud • Information Technology • Machine Learning • Software
Easy Apply
Hybrid
San Francisco, CA, USA
1100 Employees
90K-124K Annually

Similar Companies Hiring

Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software • Productivity
US
15 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account