CronJobs

security jobs

Information Security and GRC Manager

Scribe · San Francisco

hybridunknown$144,500–$220,000Posted Oct 9, 2026SOC 2ISO 27001HIPAACISSPCISMCISAVantaDrata

Apply on the employer site

About this role

## Information Security & GRC Manager **About Scribe** Scribe (https://scribe.com/) is where exceptional people do the best work of their careers. More than 94% of the Fortune 500 use Scribe to own their specialized intelligence—the unique way their teams work, decide, and get things done. Since 2019, Scribe has reached 7M users across 600K businesses. Based in San Francisco, valued at over $1B, and backed by leading investors. --- ## TL;DR — Why This Role Matters Scribe is scaling fast, and our security & compliance program needs to keep up. As **Information Security & GRC Manager**, you’ll be the hands-on owner of day-to-day security and compliance work—so audits don’t slip, questionnaires don’t pile up, enterprise deals don’t stall, and compliance becomes real engineering work. --- ## What You’ll Do - **Run our SOC 2 program end-to-end** (control ownership, evidence collection, auditor management, closing gaps). Support additional frameworks as customer demand requires. - **Own customer security reviews**: complete questionnaires, maintain the trust center & security documentation, and lead security calls with Sales, Customer Success, and Legal. - **Provide technical input for security commitments in customer contracts** (MSAs, DPAs, BAAs, AI terms) and flag non-standard requests for decision. - **Maintain the risk register, security policies, and vendor security review process**. Bring risks to leadership with clear recommendations and prioritization. - **Turn audit findings and security requirements into concrete engineering work**, and track it to completion. - **Operate and scale core internal security programs**: access reviews, security awareness training, endpoint/device management, vulnerability management, and incident response readiness. --- ## What Makes You a Great Fit - **6+ years** in information security, GRC, or security compliance at a SaaS/technology company, with **2+ years managing individual contributors**. - **Hands-on SOC 2 Type II experience**—as the person who actually did the work. - Experience with **enterprise customer security reviews and questionnaires** alongside Sales/CS/Legal. - Working knowledge of **cloud security, IAM, endpoint security, and vulnerability management** to engage engineers and drive remediation. - Familiarity with **GRC automation platforms** (e.g., Vanta, Drata, Secureframe). - Strong **risk judgment**, organization, and follow-through in a growing environment. - Experience with security/privacy frameworks such as **ISO 27001, HIPAA, FERPA**, public-sector requirements, and **AI governance frameworks** (e.g., EU AI Act, ISO 42001). - **CISSP, CISM, or CISA preferred**. --- ## This Role Is Not for You If - You haven’t scaled/executed security work at a global SaaS/technology company. - You haven’t personally run audits, answered security questionnaires, or driven remediation. - You treat every finding as requiring maximum mitigation regardless of business context. - You need a fully defined playbook—this program is still maturing. --- ## Location & Work Style - **Hybrid, based in San Francisco** - Office **3 days/week** (Mondays and Wednesdays are anchor days) --- ## Compensation & Benefits (Highlights) - Salary varies by location; **equity for all full-time employees** - **Healthcare** (medical/dental/vision) with two $0/month medical plan options - **401(k)** via Vestwell - **Flex Benefit**: $500/year - **Commuter Benefits**: $100/month (SF-based) - **PTO**: flexible p

Listing freshness

CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.

Browse all software engineering jobs →

Follow fresh jobs in Discord