Compliance Manager, Tech GRC

San Francisco, CA

Apply now Apply later

About us

  • At Sierra, we’re building a platform to enable every company in the world to build their own autonomous AI agents for everything from customer service to commerce. We are primarily an in-person company based in San Francisco, with growing offices in Atlanta and London.

  • We are guided by a set of values that are at the core of our actions and define our culture: Trust, Customer Obsession, Craftsmanship, Intensity, and Family. These values are the foundation of our work, and we are committed to upholding them in everything we do.

  • Our co-founders are Bret Taylor and Clay Bavor. Bret was most recently co-CEO of Salesforce, which had previously acquired the company he founded, Quip. Before founding Quip, Bret was the CTO of Facebook. Bret was one of Google's earliest product managers and one of the co-creators of Google Maps. Bret currently serves as Board Chair of OpenAI. Before founding Sierra, Clay spent 18 years at Google, where he most recently led Google Labs. Earlier, he started and led Google’s AR/VR effort, Project Starline, and Google Lens. Before that, Clay led the product and design teams for Google Workspace. 

What You’ll Do:

  • Operate at the intersection of technology, compliance, and AI innovation, helping to shape security standards in a rapidly evolving field.

  • Collaborate with Product, Platform, Legal, Agent Engineering, Operations, Finance, Sales and GTM, ensuring compliance is embedded seamlessly while maintaining agility.

  • Lead audits such as SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR, DORA including readiness, auditor engagement and reporting.

  • Deeply understand the AI tech stack and partner with engineering and product teams to integrate controls into the architecture, CI/CD, and roadmaps. 

  • Automate and optimize workflows, reduce complexity, and enhance efficiency through AI, automation and scalable GRC processes.

  • Maintain a scalable security controls library, assess gaps, and drive remediation to strengthen compliance posture.

  • Drive security awareness programs and policy management that foster a strong security culture and enable innovation.

What You’ll Bring:

  • Deep expertise in security and privacy frameworks (SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR, CCPA, etc.).

  • 5-9+ years in security, compliance, or risk management in fast-moving, high-growth tech environments.

  • A tech-forward, adaptable GRC approach that prioritizes security and business impact.

  • Ability to own audits, assess risk, and implement scalable, pragmatic security solutions that support business objectives.

  • Strong communicator who educates rather than enforces, making security approachable.

  • Relevant certifications (CISSP, CISA, PCI ISA, ISO 27001 Lead Auditor, etc.) demonstrating technology compliance and security expertise.

Even Better...

  • You thrive in fast-moving environments, are solution-oriented, and believe that compliance should be an enabler.

  • Experience in tech, fintech, healthcare, AI or other regulated industries.

  • Hands-on cloud security expertise (AWS, Azure, GCP) and experience automating compliance with GRC tools.

  • Knowledge of Identity & Access Management, Data Security, and Infrastructure Security.

  • Familiarity with GDPR, DORA, EU AI Act, and evolving global security and privacy regulations.

Our values

  • Trust: We build trust with our customers with our accountability, empathy, quality, and responsiveness. We build trust in AI by making it more accessible, safe, and useful. We build trust with each other by showing up for each other professionally and personally, creating an environment that enables all of us to do our best work.

  • Customer Obsession: We deeply understand our customers’ business goals and relentlessly focus on driving outcomes, not just technical milestones. Everyone at the company knows and spends time with our customers. When our customer is having an issue, we drop everything and fix it.

  • Craftsmanship: We get the details right, from the words on the page to the system architecture. We have good taste. When we notice something isn’t right, we take the time to fix it. We are proud of the products we produce. We continuously self-reflect to continuously self-improve.

  • Intensity: We know we don’t have the luxury of patience. We play to win. We care about our product being the best, and when it isn’t, we fix it. When we fail, we talk about it openly and without blame so we succeed the next time.

  • Family: We know that balance and intensity are compatible, and we model it in our actions and processes. We are the best technology company for parents. We support and respect each other and celebrate each other’s personal and professional achievements.

What we offer

We want our benefits to reflect our values and offer the following to full-time employees in the United States:

  • Flexible (Unlimited) Paid Time Off

  • Medical, Dental, and Vision benefits for you and your family

  • Life Insurance and Disability Benefits

  • 401(k) Plan with Sierra match

  • Parental Leave

  • Fertility and Family Building Benefits through Carrot

  • Lunch, as well as delicious snacks and coffee to keep you energized 

  • Discretionary Benefit Stipend giving people the ability to spend where it matters most

  • Free alphorn lessons

These benefits are further detailed in Sierra's policies and are subject to change at any time, consistent with the terms of any applicable compensation or benefits plans. Eligible full-time employees can participate in Sierra's equity plans subject to the terms of the applicable plans and policies.

Be you, with us

We're working to bring the transformative power of AI to every organization in the world. To do so, it is important to us that the diversity of our employees represents the diversity of our customers. We believe that our work and culture are better when we encourage, support, and respect different skills and experiences represented within our team. We encourage you to apply even if your experience doesn't precisely match the job description. We strive to evaluate all applicants consistently without regard to race, color, religion, gender, national origin, age, disability, veteran status, pregnancy, gender expression or identity, sexual orientation, citizenship, or any other legally protected class.

Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  1  1  0

Tags: Audits Automation AWS Azure CCPA CI/CD CISA CISSP Cloud Compliance Finance FinTech GCP GDPR HIPAA ISO 27001 OpenAI PCI DSS Privacy Risk management SOC SOC 2

Perks/benefits: 401(k) matching Career development Equity / stock options Fertility benefits Flex hours Flex vacation Health care Insurance Medical leave Parental leave Startup environment Unlimited paid time off

Region: North America
Country: United States

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.