About Us
At ControlSage, we help fast-growing companies turn compliance from a bottleneck into a competitive advantage. Our managed compliance platform combines AI-powered automation with hands-on expert guidance to help startups and scaleups achieve and maintain SOC 2, ISO 27001, HIPAA, PCI DSS, CMMC, and other critical certifications without slowing down engineering.
Our team includes security engineers, compliance experts, and former auditors who care about solving real problems for real businesses. Whether you're mapping controls, closing an audit, or building a governance program from scratch, your work here directly determines whether our customers can close their next enterprise deal.
The Role
We're looking for a Senior GRC Specialist to take ownership of our most complex compliance programs and mentor the broader team. You'll lead multi-framework audit strategy, advise leadership on emerging risk, and help shape how ControlSage scales governance as both our company and our customers grow. This is a senior individual contributor role for someone who wants deep ownership without a formal management track.
Key Responsibilities
Own strategy and execution for our most complex, multi-framework compliance programs (SOC 2, ISO 27001, ISO 42001, HIPAA, PCI DSS)
Serve as the senior technical escalation point for complex control design and audit questions
Advise leadership on emerging regulatory and risk trends, including AI governance requirements
Lead cross-functional risk assessments spanning Engineering, Legal, and Product
Design and continuously improve our overall GRC program architecture and control framework
Mentor and upskill junior GRC Analysts on best practices and audit methodology
Own vendor and third-party risk strategy, including high-risk vendor reviews
Represent ControlSage in high-stakes customer security reviews and enterprise due diligence
Partner with Product on compliance-by-design for new features and offerings
Requirements
6+ years of experience in GRC, information security compliance, or a related field
Proven experience leading multi-framework compliance programs at scale
Deep expertise in SOC 2 and ISO 27001; working knowledge of HIPAA, PCI DSS, or CMMC a strong plus
Track record advising senior stakeholders on risk and compliance strategy
Excellent written and verbal communication skills across technical and executive audiences
Experience mentoring or informally leading other compliance professionals
Comfortable operating with significant autonomy in a fast-paced environment
Willingness and curiosity to use modern AI tools to build simpler, faster ways to track and report data.
Preferred Qualifications
CISA, CISM, or CRISC certification
Experience building a GRC program from the ground up at an early-stage startup
Experience with AI governance frameworks such as ISO 42001
Salary Band
$130,000 - $170,000 USD. Our salary bands are structured based on a combination of geographic tiers and internal leveling. Compensation is determined by multiple factors assessed during the interview process, with the final offer reflecting these considerations.
Company Perks
Hubs in San Francisco and Texas offering regular in-person gatherings and co-working sessions
Flexible PTO with U.S. holidays observed and a week shutdown in December to rest and recharge*
Equity plan ( Launchin soon)
$500 work-from-home stipend to be used within a year of your start date*
$1,200 per year Health and Wellness Allowance to support your personal goals*
The chance to collaborate with a team at the forefront of compliance and AI-powered governance
*Certain perks and benefits are limited to full-time employees only.
ControlSage participates in E-Verify. We will provide the Social Security Administration (SSA) and, if necessary, the Department of Homeland Security (DHS) with information from each new employee's Form I-9 to confirm work authorization. We are also an inclusive, equitable, and accessible workplace. Please let us know if you require accommodation for any portion of the recruitment and hiring process.
Beware of recruiting scams: ControlSage will only contact you through official @controlsage.com email addresses and will never ask for payment or sensitive personal information during the hiring process.