About Us

At ControlSage, we help fast-growing companies turn compliance from a bottleneck into a competitive advantage. Our managed compliance platform combines AI-powered automation with hands-on expert guidance to help startups and scaleups achieve and maintain SOC 2, ISO 27001, HIPAA, PCI DSS, CMMC, and other critical certifications without slowing down engineering.

Our team includes security engineers, compliance experts, and former auditors who care about solving real problems for real businesses. Whether you're mapping controls, closing an audit, or building a governance program from scratch, your work here directly determines whether our customers can close their next enterprise deal.

The Role

We're looking for a Senior GRC Specialist to take ownership of our most complex compliance programs and mentor the broader team. You'll lead multi-framework audit strategy, advise leadership on emerging risk, and help shape how ControlSage scales governance as both our company and our customers grow. This is a senior individual contributor role for someone who wants deep ownership without a formal management track.

Key Responsibilities

Own strategy and execution for our most complex, multi-framework compliance programs (SOC 2, ISO 27001, ISO 42001, HIPAA, PCI DSS)

Serve as the senior technical escalation point for complex control design and audit questions

Advise leadership on emerging regulatory and risk trends, including AI governance requirements

Lead cross-functional risk assessments spanning Engineering, Legal, and Product

Design and continuously improve our overall GRC program architecture and control framework

Mentor and upskill junior GRC Analysts on best practices and audit methodology

Own vendor and third-party risk strategy, including high-risk vendor reviews

Represent ControlSage in high-stakes customer security reviews and enterprise due diligence

Partner with Product on compliance-by-design for new features and offerings

Requirements

6+ years of experience in GRC, information security compliance, or a related field

Proven experience leading multi-framework compliance programs at scale

Deep expertise in SOC 2 and ISO 27001; working knowledge of HIPAA, PCI DSS, or CMMC a strong plus

Track record advising senior stakeholders on risk and compliance strategy

Excellent written and verbal communication skills across technical and executive audiences

Experience mentoring or informally leading other compliance professionals

Comfortable operating with significant autonomy in a fast-paced environment

Willingness and curiosity to use modern AI tools to build simpler, faster ways to track and report data.

Preferred Qualifications

CISA, CISM, or CRISC certification

Experience building a GRC program from the ground up at an early-stage startup

Experience with AI governance frameworks such as ISO 42001

Salary Band

$130,000 - $170,000 USD. Our salary bands are structured based on a combination of geographic tiers and internal leveling. Compensation is determined by multiple factors assessed during the interview process, with the final offer reflecting these considerations.

Company Perks

Hubs in San Francisco and Texas offering regular in-person gatherings and co-working sessions

Flexible PTO with U.S. holidays observed and a week shutdown in December to rest and recharge*

Equity plan ( Launchin soon)

$500 work-from-home stipend to be used within a year of your start date*

$1,200 per year Health and Wellness Allowance to support your personal goals*

The chance to collaborate with a team at the forefront of compliance and AI-powered governance

*Certain perks and benefits are limited to full-time employees only.

ControlSage participates in E-Verify. We will provide the Social Security Administration (SSA) and, if necessary, the Department of Homeland Security (DHS) with information from each new employee's Form I-9 to confirm work authorization. We are also an inclusive, equitable, and accessible workplace. Please let us know if you require accommodation for any portion of the recruitment and hiring process.
Beware of recruiting scams: ControlSage will only contact you through official @controlsage.com email addresses and will never ask for payment or sensitive personal information during the hiring process.

Apply for this role

Applying for: Sr. GRC Specialist

PDF or Word, up to 5MB. Your resume is saved directly to our Drive folder.