GRC Leader
Core
Lead the external audit lifecycle and compliance program for an AI customer experience platform, ensuring adherence to global standards like SOC 2, PCI DSS, and HIPAA.
Role type
Senior GRC Leader (Audit & Compliance)
Builds
Compliance posture and audit readiness for an AI SaaS platform serving financial services, healthcare, and contact center industries.
Domain
Information Security / Regulatory Compliance / AI SaaS
Deliverable
client delivery
Required skills
External audit management, multi-framework compliance strategy (SOC 2, PCI DSS, ISO 27001, HITRUST, HIPAA, GDPR), risk assessment, vendor risk management, GRC tooling proficiency, DPA negotiation, cross-functional stakeholder coordination
Preferred skills
CISA, CISSP, CISM, CRISC, ISO 27001 Lead Auditor/Implementer, PCI QSA/ISA certifications
Technologies
Vanta, Drata, OneTrust
Responsibilities
Own end-to-end external audit lifecycle from scoping to remediation; develop and maintain GRC strategy and control library; lead enterprise risk assessments and gap analyses; manage third-party and vendor risk including DPAs; respond to customer security questionnaires and support sales deal cycles; maintain Trust Center accuracy.
Seniority
Senior, hands-on IC