About Us
At ControlSage, we help fast-growing companies turn compliance from a bottleneck into a competitive advantage. Our managed compliance platform combines AI-powered automation with hands-on expert guidance to help startups and scaleups achieve and maintain SOC 2, ISO 27001, HIPAA, PCI DSS, CMMC, and other critical certifications without slowing down engineering.
Our team includes security engineers, compliance experts, and former auditors who care about solving real problems for real businesses. Whether you're mapping controls, closing an audit, or building a governance program from scratch, your work here directly determines whether our customers can close their next enterprise deal.
The Role
We're looking for a GRC Analyst to join our growing Security and Compliance function. You'll be the backbone of compliance work at the intersection of Engineering, Legal, and Product. This role builds and maintains compliance programs as part of our security team. Our goal is simple: earn and keep the trust of our customers. The right person translates security and risk into terms that the business and product teams can act on.
Key Responsibilities
Own and manage compliance programs across SOC 2, ISO 27001, GDPR, HIPAA, and FedRAMP
Coordinate audit activities end-to-end: evidence collection, documentation, auditor responses, and remediation tracking
Leverage AI and other tools to deliver metrics that stakeholders can consume and understand
Conduct vendor and third-party risk assessments; manage due diligence for new and existing partners
Build and maintain compliance policies, procedures, and supporting documentation
Translate regulatory and contractual requirements into actionable controls and processes
Monitor the evolving regulatory landscape (especially AI-specific regulations) and flag relevant obligations
Support Privacy-by-Design reviews for new product features and data practices
Track open compliance items and proactively drive them to closure across stakeholders
Requirements
3-5 years of experience in GRC, Information Security compliance, or a related field
Hands-on experience with SOC 2 or ISO 27001 audits, including evidence collection and gap assessments
Familiarity with privacy regulations: GDPR, CCPA, and ideally emerging AI regulatory frameworks (EU AI Act, etc.)
Experience managing vendor risk assessments and third-party due diligence processes
Strong written and verbal communication skills — you can explain compliance to engineers and legal concepts to product managers
Highly organized, able to manage multiple workstreams and deadlines without dropping the ball
Comfortable working independently in a fast-paced environment with limited process overhead
Willingness and curiosity to use modern AI tools to build simpler, faster ways to track and report data.
Preferred Qualifications
Experience at a fast-growing SaaS, AI, or search company
Bachelor’s degree or equivalent in Information Systems, Accounting, Business or related field
CISA, CISM, or CRISC certification
Salary Band
$90,000 - $140,000 USD. Our salary bands are structured based on a combination of geographic tiers and internal leveling. Compensation is determined by multiple factors assessed during the interview process, with the final offer reflecting these considerations.
Company Perks
Hubs in San Francisco and Texas offering regular in-person gatherings and co-working sessions
Flexible PTO with U.S. holidays observed and a week shutdown in December to rest and recharge*
Equity plan ( Launchin soon)
$500 work-from-home stipend to be used within a year of your start date*
$1,200 per year Health and Wellness Allowance to support your personal goals*
The chance to collaborate with a team at the forefront of compliance and AI-powered governance
*Certain perks and benefits are limited to full-time employees only.
ControlSage participates in E-Verify. We will provide the Social Security Administration (SSA) and, if necessary, the Department of Homeland Security (DHS) with information from each new employee's Form I-9 to confirm work authorization. We are also an inclusive, equitable, and accessible workplace. Please let us know if you require accommodation for any portion of the recruitment and hiring process.
Beware of recruiting scams: ControlSage will only contact you through official @controlsage.com email addresses and will never ask for payment or sensitive personal information during the hiring process.