Senior Security GRC Lead
$121k - $185kGong.io
Senior Security GRC Lead
Austin | Chicago | New York City | Salt Lake City | San Francisco
Gong harnesses the power of AI to transform how revenue teams win. The Gong Revenue AI Operating System unifies data, insights, and workflows into a single, trusted system that observes, guides, and acts alongside the world's most successful revenue teams. Powered by the Gong Revenue Graph, AI-powered intelligence, specialized agents, and trusted applications, Gong helps more than 5,000 companies around the world deeply understand their teams and customers, automate critical sales workflows, and close more deals with less effort.
At Gong, you will join a company built on innovative products, ambitious goals, and passionate people. We are shaping the future of revenue intelligence and we want people who are excited to build what comes next. You will work with a team that dreams big, moves fast, and cares deeply about the craft and about each other. Here, transparency and trust are core to how we operate, and every person has the opportunity to make a visible impact. If you want to grow, stretch, and do work that truly matters, Gong is the place to do the best work of your career.
This is a high-visibility, high-impact role at the center of Gong's security and compliance story. As our Senior GRC Security Lead, you will be the architect of foundational programs we are building — Gong's first-ever Common Controls Framework, standing up a formal risk process and register, implementing a GRC tooling ecosystem, and owning the full policy, standards, and exceptions management lifecycle.
This is not a role for someone looking to inherit a mature program. It's a role for a builder — someone who thrives in ambiguity, operates with urgency, and finds energy in creating order from complexity. You will work directly with Legal, Sales, Engineering, Customer Audit teams, and executive stakeholders, and your fingerprints will be visible across everything Gong builds for compliance and trust for years to come.
Responsibilities
- Design and implement Gong's Common Controls Framework, mapping controls across SOC 2, ISO 27001, 27017, 27701, 27018, HIPAA, PCI, and other applicable frameworks.
- Rationalize overlapping requirements across frameworks to reduce compliance burden and create a single source of truth for control ownership.
- Partner with Engineering, Infrastructure, and Product Security to embed controls at the architecture level, not just as audit checkboxes.
- Establish control testing methodology, evidence collection standards, and continuous control monitoring processes.
- Serve as the subject-matter expert on control mapping during customer and external audits, RFPs, and enterprise sales engagements.
- Build Gong's product & enterprise risk register from the ground up — defining risk taxonomy, scoring methodology, risk appetite thresholds, and ownership models.
- Implementation of a GRC platform and system of record, and ability to build executive level dashboards to track vulnerability, risk, and control remediation.
- Create and maintain risk treatment plans in partnership with risk owners across the business, tracking remediation milestones and escalating blockers.
- Develop executive-level risk reporting cadences and dashboards for the Head of GRC and senior leadership.
- Own the complete lifecycle of Gong's information security policy suite — creation, review cycles, version control, and employee acknowledgment tracking.
- Establish and operate a formal exceptions management program, including intake, risk assessment, approval workflows, compensating controls, and periodic review.
- Ensure policies remain aligned with evolving regulatory requirements, industry frameworks, and Gong's rapidly changing technology environment.
- Drive policy adoption through clear communication, training support, and cross-functional partnership.
- Liaise with external auditors and certification bodies for SOC 2, ISO, and other certifications
Qualifications
- 7+ years of progressive experience in GRC, Information Security, or a closely related function — with meaningful time spent building or scaling programs, not just running them.
- Demonstrated hands-on experience building a GRC program at scale — ideally in a high-growth SaaS or technology company.
- Deep expertise across multiple compliance and security frameworks, including SOC 2 Type II, ISO 27001, NIST CSF, and at least one regulatory framework (GDPR, CCPA, HIPAA, or equivalent).
- Experience creating and implementing GRC Record of Truth/Tooling.
- Strong policy and standards writing ability — capable of translating complex regulatory language into clear, actionable documentation.
- Experience conducting and managing product & enterprise risk assessments, with a working knowledge of risk quantification methodologies.
- Proven ability to manage and communicate with senior stakeholders, including Legal, Engineering, and executive audiences.
- Bachelor's degree in Information Security, Computer Science, Business, or a related field; equivalent practical experience considered.
- Relevant certifications strongly preferred: CISSP, CISM, CRISC, CISA, CCSP, or comparable credentials.
Perks & Benefits
- We offer Gongsters a variety of medical, dental, and vision plans, designed to fit you and your family's needs.
- Wellbeing Fund - flexible wellness stipend to support a healthy lifestyle.
- Mental Health benefits with covered therapy and coaching.
- 401(k) program to help you invest in your future.
- Education & learning stipend for personal growth and development.
- Flexible vacation time to promote a healthy work-life blend.
- Paid parental leave to support you and your family.
- Company-wide recharge days each quarter.
- Work from home stipend to help you succeed in a remote environment.
The annual salary hiring range for this position is $121,000 - $185,000 USD.
Compensation is based on factors unique to each candidate, including, but not limited to, job-related skills, qualification, education, experience, and location. At Gong, we have a location-based compensation structure, which means there may be a different range for candidates in other locations. The total compensation package for this position, in addition to base compensation, may include incentive compensation, bonus, equity, and benefits. Some of our sales compensation programs also offer the potential to achieve above targeted earnings for those who exceed their sales targets.
We are always looking for outstanding Gongsters! So if this sounds like something that interests you regardless of compensation, please reach out. We may have more roles for you to consider and would love to connect.
We have noticed a rise in recruiting impersonations across the industry, where scammers attempt to access candidates' personal and financial information through fake interviews and offers. All Gong recruiting email communications will always come from the @gong.io domain. Any outreach claiming to be from Gong via other sources should be ignored.
Gong is an equal-opportunity employer. We believe that diversity is integral to our success, and do not discriminate based on race, color, religion, age, sex, sexual orientation, gender identity, national origin, disability, military status, genetic information, or any other basis protected by applicable law.
To review Gong's privacy policy, visit for more details.
$160k - $190k
...Applied Intuition is seeking a Risk and Compliance Lead in Sunnyvale, CA. This role involves leading security compliance initiatives and managing the security GRC program. The ideal candidate has over 6 years of experience in risk management and must be comfortable presenting...Senior- ...community of associates with a strong sense of belonging.Learn more about Inclusion & Diversity at PVH here.About the Role:The Senior Lead, SAP Security, GRC & Compliance will act as a Subject Matter Expert (SME) for SAP Security & GRC including managing multiple SAP GRC...SeniorFull timeContract workSeasonal workLocal areaFlexible hours
- Anomali is seeking a hands-on GRC leader to own and drive the multi-jurisdiction certification portfolio, including FedRAMP, ISO 27001, SOC 2, and regional cloud security frameworks. You will coordinate with sales, product, and leadership to sequence efforts for market...Senior
- ...maintaining enterprise-grade control and governance. As a Senior GRC Lead at Jasper, you will own our Governance, Risk, and Compliance... ...and maintain momentum on audits, risk management, and vendor security, partnering closely with Security, Legal, and Engineering to...SeniorFull timeRemote work
- United States Digital Space LLC is seeking a Senior InfoSec GRC Analyst for a fully remote, international role. You will own governance, risk... ...ISMS, drive ISO 27001 and SOC 2 audits, and review customer security requirements to enable safe production deployments. You will...SeniorRemote job
- Peregrine Technologies, Inc. in Washington, DC, is seeking a senior Governance, Risk, and Compliance leader to own FedRAMP High and establish security foundations for DoD IL4-IL6 deployments. This role requires translating federal requirements into implementable controls...Senior
- Gusto is seeking a Security, Governance, Risk & Compliance professional to advance governance, risk, and compliance initiatives across the company. You will guide maturity from foundational to steady-state operations while embedding security-minded practices. The role...Senior
- Latham & Watkins, located in Downtown Los Angeles, seeks an Enterprise Security Compliance Manager to join the Global Security & Risk Management team. This role leads security compliance activities, responses to client questionnaires, assessments, and RFPs, coordinating...SeniorWork at officeFlexible hours
- Zermount, Inc is seeking an ISSO Program Manager to lead security governance and RMF activities for a federal client. This role combines project management with cybersecurity expertise to ensure secure, compliant operations across enterprise systems. The role requires strong...Senior
- ...A leading consulting firm seeks a Governance, Risk, and Compliance (GRC) leader to advance their programs. This remote role requires 5–7 years of experience in GRC with relevant certifications like CISSP or CISM. The successful candidate will lead policy development, perform...SeniorRemote work
$90.3k - $189.6k
Job Title: Lead Senior Information System Security OfficerJob Category: Information TechnologyTime Type: Full timeMinimum Clearance Required to Start: NoneEmployee... ...- Experience with CSAM, RegScale, eMASS, or similar GRC tools- Experience supporting emergency operations or...SeniorContract workWork experience placementWork at officeFlexible hours- Entrust seeks a Senior Security Compliance Analyst to lead PCI DSS and NIST 800-53 programs across cloud, on-prem, and hybrid environments. You will design... ...DSS expertise, risk framework knowledge, and modern GRC capabilities to automate evidence-driven compliance operations...SeniorRemote job
$75 - $80 per hour
Dexian is looking for an experienced professional to integrate an AI risk tool into the GRC ecosystem. This role involves managing system integrations and aligning various teams to ensure compliance. The interview will be in-person, and the position is hybrid based in Bellevue...SeniorHourly payContract work- Data Analysis Inc in Plano, Texas is seeking a Senior Manager, Governance, Risk, Compliance & Privacy to lead enterprise GRCP initiatives, align with laws, regulations... ..., and contracts, and partner with Information Security, IT, Legal, HR and external partners to mature...Senior
- HistoSonics in Plymouth, MN is seeking a Principal Security Analyst, Governance, Risk, and Compliance to lead the policy, risk, and third‑party programs in a hybrid... ...and a multi-year improvement roadmap. This senior individual contributor partners with Legal on privacy...Senior
- PwC in Tampa, FL seeks a Senior Manager for GRC/IRM ServiceNow implementations, guiding clients through complex regulatory landscapes and enhancing internal controls to mitigate risk. You will lead diverse teams, communicate clearly, and elevate issues as needed to deliver...Senior
- Industrious Ventures is seeking a Governance, Risk & Compliance (GRC) Lead to oversee compliance programs like CMMC, FedRAMP, and SOC 2. In this senior role, you'll work closely with various teams to ensure the implementation of technical controls and compliance requirements...SeniorPermanent employment
- PwC in New York is seeking a Senior Manager for GRC/IRM ServiceNow Technology Implementation Solutions. You will help clients maintain regulatory compliance and manage risks within our Cyber, Data & Tech Risk practice. You will coach and motivate teams, apply systems thinking...Senior
- ...Manager for Governance, Risk & Compliance solutions. The ideal candidate will have over 6 years of experience with Workiva GRC implementations, lead project delivery, and manage client communications effectively. Responsibilities include requirement gathering, system...SeniorRemote jobFlexible hours
$114.5k - $188.9k
...building capabilities that make Information Security easier to understand, adopt, and... ...across the enterprise. As the Lead, Information Security GRC (Governance, Risk, and Compliance) Automation... ...topics such as parenting, housing, senior care, finances, pets, legal matters,...Full timePart timeWork at officeRemote work3 days per week$100k - $180k
A leading FinTech company in New York is looking for a Senior GRC Analyst to strengthen their Governance, Risk, and Compliance function. The successful candidate... ...years of experience in GRC, expertise in federal security frameworks, and a proactive approach to compliance...Senior$153.6k - $192k
...intention. Our teams span Software, Data, Security, and IT, and operate with high autonomy... ...with technical execution. As a Senior GRC Engineer, you will drive critical GRC processes... ...partners by producing documentation and leading training sessions Evangelize best practices...SeniorWork at officeImmediate startRemote workWork from home- A leading technology firm is seeking a Governance, Risk, and Compliance (GRC) Analyst to enhance compliance posture across various standards. Based in Schaumburg, IL or Phoenix, AZ, the ideal candidate will have 2+ years' experience in risk and compliance, managing audits...SeniorFull time
- Procore is seeking a Senior Cybersecurity Risk Analyst for its GRC organization to manage risks across cloud, SaaS, and information assets. You will map risks, coordinate with architects and engineers, and apply AI tools to accelerate risk statements and reporting. The...Senior
- ...Owner.com is seeking a GRC Specialist to navigate complex Risk, Compliance, and Vulnerability Management as we grow. You will drive compliance efforts, secure systems, and advise senior leadership in security risks. Requires 3+ years in compliance frameworks and 5+ years...Remote work
- Huntington is seeking a Senior GRC Programmer/Analyst to modify and develop software within the GRC space across multiple corporate offices... ..., debugging, documenting, and supporting production systems; leading projects; mentoring teammates; and balancing development with...SeniorWork at office
- ...Apogee Global RMS is seeking a Senior Cybersecurity Engineer / Offensive Security Lead to support high‑visibility federal and IC programs. This role is designed for operators who bring hands‑on offensive tradecraft, current certifications, and recent red‑team experience...SeniorFull time
- Adobe is seeking a GRC Strategy & Security Insights Lead to drive a data-driven shift in its GRC program. This pivotal role combines the excellence in strategy and communication necessary to influence and engage executives, while overseeing critical security metrics and...Shift work
- Litehouse is seeking a Security & Compliance Lead to own the compliance program across SOC 2 and GDPR. You will verify security controls, manage... ...controls meet requirements. Ideal candidates have 4+ years in GRC, relevant certifications, and hands-on IaC review...Remote work
- Emburse is seeking a Manager, Security Governance & Risk to lead the GRC function, mentor a team of professionals, and own platform strategy, controls architecture, data quality, and reporting. You will own enterprise information security risk management end to end, oversee...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Security GRC Lead. Be the first to apply!
- senior human resources associate United States
- senior network engineer remote United States
- senior education consultant United States
- senior benefits manager United States
- senior app developer United States
- senior personal assistant United States
- senior manager legal United States
- senior geologist United States
- senior internal tool engineer United States
- senior export manager United States



