Governance, Risk & Compliance (GRC) Manager

Posted Yesterday
Be an Early Applicant
San Francisco, CA, USA
In-Office
190K-215K Annually
Mid level
Cloud • Information Technology • Analytics
The Role
Lead design and scaling of enterprise GRC: build governance frameworks, run ERM and risk assessments, manage BCDR and third-party risk, own audits/certifications (SOC 2/ISO/HIPAA), maintain compliance monitoring, conduct internal/external audits, and support sales with security questionnaires and compliance materials.
Summary Generated by Built In


Governance, Risk & Compliance (GRC) Manager

Sigma is seeking an experienced GRC Manager to lead and scale our governance, risk, and compliance programs. This role is based in our San Francisco office or upcoming New York office and reports to the General Counsel. You'll have the opportunity to build a strategic, enterprise-wide GRC function that enables business growth while managing organizational risk.

As our GRC Manager, you'll partner with Legal, Engineering, Product, Sales, Operations, and leadership to develop a comprehensive GRC framework that protects Sigma's interests, supports our strategic objectives, and builds stakeholder trust. You'll mature our governance structures, implement scalable risk management processes, and ensure compliance with applicable regulatory requirements—all while enabling the business to move quickly and confidently.

What You'll Do

Governance

  • Design and implement governance frameworks, including reporting, policy governance, and control oversight
  • Establish and maintain enterprise policies, standards, and procedures across technology, security, privacy, and operational functions
  • Build and lead a governance committee structure that provides appropriate oversight and decision-making
  • Create governance dashboards and metrics to provide visibility into program maturity and effectiveness
  • Partner with leadership to align governance activities with business strategy and risk appetite

Risk Management

  • Develop and operate a comprehensive Enterprise Risk Management (ERM) program
  • Conduct regular enterprise-wide risk assessments and maintain a dynamic risk register
  • Build and maintain business continuity and disaster recovery programs, including regular testing and tabletop exercises
  • Implement third-party risk management processes, including vendor risk assessments, contract reviews, and ongoing monitoring
  • Create risk treatment plans and track remediation activities across the organization
  • Facilitate risk-informed decision-making at all levels of the organization
  • Coordinate with functional leaders to ensure risks across all business areas are identified and managed appropriately

Compliance

  • Own audit and certification programs including SOC 2, ISO 27001, HIPAA, and other relevant standards
  • Develop and maintain compliance monitoring programs to track regulatory changes and work with the legal team to assess impact
  • Partner with HR and Legal to support labor & employment compliance programs, including workplace safety, anti-discrimination, wage and hour requirements, and multi-jurisdictional employment regulations
  • Monitor and ensure adherence to industry-specific regulatory requirements relevant to Sigma's business operations
  • Manage security awareness training programs enterprise-wide
  • Conduct internal audits and assessments to validate control effectiveness
  • Coordinate external audits and assessments with third-party auditors

Business Enablement

  • Support sales and customer success teams with compliance documentation and security inquiries
  • Develop customer-facing materials that articulate Sigma's risk management and compliance posture
  • Complete and manage responses to customer security questionnaires and assessments (VSAs, SIGs, custom questionnaires)
  • Enable efficient deal cycles by maintaining ready-to-use compliance artifacts, trust center content, and documentation
  • Partner with Sales Engineering and Solutions teams to address prospect security and compliance requirements

What You Bring

Required

  • 4+ years of experience in governance, risk management, and/or compliance roles, preferably in SaaS or technology companies
  • Demonstrated experience building or significantly maturing a GRC program from the ground up
  • Track record of successfully leading certification audits (SOC 2, ISO 27001, HIPAA, or similar)
  • Experience implementing risk management frameworks (COSO, ISO 31000, NIST RMF, or similar)
  • Strong knowledge of data privacy regulations and their practical application (GDPR, CCPA, etc.)
  • Experience developing and maintaining information security and privacy policies, procedures, and control frameworks
  • Strong business acumen with ability to translate risk and compliance requirements into business value
  • Excellent communication skills with ability to influence stakeholders at all levels, including leadership
  • Proven ability to manage multiple priorities and stakeholders in a fast-paced, high-growth environment
  • Collaborative mindset and commitment to enabling business success while managing risk

Preferred

  • Experience with GRC platforms (ServiceNow GRC, Archer, LogicGate, or similar)
  • Hands-on experience with cloud environments (GCP, AWS, Azure) from a compliance and security perspective
  • Experience with labor & employment compliance or cross-functional collaboration with HR on regulatory matters
  • Familiarity with multi-state or international employment regulations
  • Experience with continuous compliance automation tools (Vanta, Drata, Secureframe, Tugboat, or similar)
  • Professional certifications such as CRISC, CISA, CISM, CGEIT, CISSP, or CIPP
  • Experience in high-growth SaaS or technology companies
  • Background in both technical and operational risk management
  • Experience working in organizations with distributed or remote teams
  • Familiarity with security frameworks such as NIST CSF, CIS Controls, or OWASP

Why Join Sigma

This is an opportunity to build a world-class GRC program that doesn't just check boxes but genuinely enables the business to pursue opportunities with confidence. You'll work across the entire organization, have direct access to the General Counsel, and make a tangible impact on how Sigma manages risk and creates value for customers.

Additional Job details

The base salary range for this position is $190k - $215k annually.

Compensation may vary outside of this range depending on a number of factors, including a candidate’s qualifications, skills, competencies and experience. Base pay is one part of the Total Package that is provided to compensate and recognize employees for their work at Sigma Computing. This role is eligible for stock options, as well as a comprehensive benefits package.

About us: 

Sigma is the AI Apps and agentic analytics platform built on the cloud data warehouse. Business and technical teams use Sigma to explore live data, build intelligent applications, and automate critical workflows all without moving data or breaking governance. Sigma supports a spreadsheet interface, SQL, Python, and native AI in a single governed workspace, giving every team the speed to act and IT the control to scale. Sigma is trusted by more than 2,000 customers, including AMD, Duolingo, Colgate-Palmolive, and JPMorgan Chase. 

Sigma announced its $80M in Series E financing in May 2026. The round was led by Princeville Capital, with new strategic investors Databricks Ventures, ServiceNow Ventures, and Workday Ventures participating alongside returning investors Altimeter Capital, Avenir Growth Capital, D1 Capital Partners, K5 Global, NewView Capital, Spark Capital, Sutter Hill Ventures, and XN. This milestone follows Sigma reaching $200M in annual recurring revenue in April 2026, with more than 100% year-over-year growth and 1.1 million new active users added in the latest fiscal year.

Come join us!

Benefits For Our Full-Time Employees:
  • Equity                                                                                                 
  • Generous health benefits
  • Flexible time off policy. Take the time off you need!
  • Paid bonding time for all new parents
  • Traditional and Roth 401k
  • Commuter and FSA benefits
  • Lunch Program
  • Dog friendly office

Sigma is an equal opportunity employer. We are committed to building a smart and strong team regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender, gender identity or expression, veteran, or any other protected status. We look forward to learning how your experience can enable all of us to grow.

Note: We have an in-office work environment in all our offices in SF, NYC, London and Sydney.

Our Privacy Practices

When you submit a job application on this site, Sigma processes your personal data for the purposes of evaluating your candidacy for employment at Sigma and as otherwise needed throughout the recruitment and hiring process. Please review Sigma’s Candidate Privacy Notice for more details. Please note that your personal data may be transferred to a country other than the one in which it was provided (including to the USA, the UK, and Canada, Australia). 

Sigma’s use of AI

This hiring process utilizes artificial intelligence tools to assist in candidate screening and assessment. Our AI tools are designed to complement, not replace, human decision-making. 

Skills Required

  • 4+ years of experience in governance, risk management, and/or compliance roles
  • Demonstrated experience building or significantly maturing a GRC program
  • Track record of leading certification audits (SOC 2, ISO 27001, HIPAA, or similar)
  • Experience implementing risk management frameworks (COSO, ISO 31000, NIST RMF, or similar)
  • Strong knowledge of data privacy regulations and practical application (GDPR, CCPA)
  • Experience developing and maintaining information security and privacy policies, procedures, and control frameworks
  • Strong business acumen with ability to translate risk and compliance requirements into business value
  • Excellent communication skills with ability to influence stakeholders at all levels, including leadership
  • Proven ability to manage multiple priorities and stakeholders in a fast-paced, high-growth environment
  • Collaborative mindset and commitment to enabling business success while managing risk
  • Experience with GRC platforms (ServiceNow GRC, Archer, LogicGate, or similar)
  • Hands-on experience with cloud environments (GCP, AWS, Azure) from a compliance and security perspective
  • Experience with labor & employment compliance or cross-functional collaboration with HR
  • Familiarity with multi-state or international employment regulations
  • Experience with continuous compliance automation tools (Vanta, Drata, Secureframe, Tugboat, or similar)
  • Professional certifications such as CRISC, CISA, CISM, CGEIT, CISSP, or CIPP
  • Experience in high-growth SaaS or technology companies
  • Background in both technical and operational risk management
  • Experience working in organizations with distributed or remote teams
  • Familiarity with security frameworks such as NIST CSF, CIS Controls, or OWASP
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Francisco, CA
329 Employees
Year Founded: 2014

What We Do

Sigma is not another Business Intelligence tool. Sigma is the only Cloud Analytics solution with a spreadsheet-like interface that enables anyone to explore data at cloud scale and speed. Discover what happened, why it happened, and what will happen.

Similar Jobs

Northwood Space Corp Logo Northwood Space Corp

Governance, Risk & Compliance (GRC) Manager

Aerospace • Hardware • Software • Database • Defense • Industrial
In-Office
Torrance, CA, USA
40 Employees

TigerConnect Logo TigerConnect

Governance, Risk, and Compliance (GRC) Manager

Cloud • Enterprise Web • Healthtech • Mobile • Software
Remote or Hybrid
2 Locations
329 Employees
120K-140K Annually

Toast Logo Toast

Senior Analyst, Product & Pricing (Finance & Strategy)

Cloud • Fintech • Food • Information Technology • Software • Hospitality
In-Office
San Francisco, CA, USA
5000 Employees
102K-163K Annually

Toast Logo Toast

Data Analyst

Cloud • Fintech • Food • Information Technology • Software • Hospitality
In-Office
San Francisco, CA, USA
5000 Employees
125K-200K Annually

Similar Companies Hiring

Standard Template Labs Thumbnail
Artificial Intelligence • Information Technology • Software
New York, NY
25 Employees
Scotch Thumbnail
Artificial Intelligence • eCommerce • Fintech • Payments • Retail • Software • Analytics
US
35 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account