GRC Lead at Replit guiding compliance and risk management across the organization. Leading team and architectural vision for automated compliance systems in software development.
Responsibilities
Act as the technical anchor for the GRC team, mentoring GRC analysts and engineers.
Own the technical vision for Replit’s GRC program, moving toward "Compliance-as-Code" and automated evidence collection.
Champion a culture of security and privacy across the company, educating teams on *why* controls exist.
Partner with Architects and Engineering Leads to incorporate compliance requirements early in the design phase.
Work closely with Legal Counsel to implement requirements for Privacy (GDPR, CCPA) and emerging AI-specific regulations.
Enable the Sales team by managing the Customer Trust Center and handling security questionnaires.
Own and cultivate the relationship with external auditors, ensuring requests are relevant to our tech stack.
Manage the Cybersecurity Risk Register, identifying, quantifying, and tracking risks.
Manage compliance posture across SOC 2, ISO 27001, and prepare for future certifications in regulated markets.
Drive the shift from manual evidence collection to continuous monitoring and assess third-party vendors.
Requirements
8+ years of experience in GRC or Information Security
Leadership Experience: Proven experience mentoring other GRC professionals or leading complex cross-functional projects.
Technical Fluency: Ability to speak the language of engineering, cloud (GCP/AWS), and security architecture. You can anticipate how architectural decisions impact risk and compliance.
Regulatory Breadth: Deep experience with SOC 2, ISO 27001, PCI, HIPPA, and Privacy laws.
Collaborative Communication: Strong ability to explain risk and tradeoffs to technical (Engineers), legal, and commercial (Sales/Execs) stakeholders.
Automation Mindset: Experience with GRC automation tools (e.g., Vanta, Drata) and a bias toward reducing manual toil.
Client Onboarding & Compliance Specialist resolving client issues within a Payment Solutions company. Supporting customer onboarding and compliance for iGaming, eSports, and eCommerce sectors.
Senior Specialist managing regional regulatory projects and supporting compliance systems for healthcare company. Implementing digital strategy initiatives and collaborating with stakeholders through process improvement.
Leitung des Vertrags - und Versicherungsmanagements bei Klinikum Bayreuth. Verantwortung für Compliance und Schadensmanagement in einer spezialisierten Einrichtung der Maximalversorgung.
Manager Datenschutz & Compliance for Stadtwerke Potsdam GmbH maintaining data protection standards and compliance processes. Ensure transparency and auditable systems in data management across services.
Chargé de conformité environnementale & RGPD pour une entreprise digitale avec une forte Human Touch. Assurer la mise en conformité environnementale et de protection des données dans l'entreprise.
Governance, Risk & Compliance Officer focusing on data protection in a renowned international trading company. Overseeing GRC structures and compliance with data protection regulations.
Director of Risk & Compliance at Futurpreneur, leading credit adjudication and compliance for young Canadian entrepreneurs. Overseeing loan processes and coaching a team of professionals in a hybrid setting.
Director of Logistics supporting Patrick Industries' logistics operations and ensuring regulatory compliance. Leading improvements in transportation efficiency and managing fleet operations across the U.S. and beyond.
Regulatory Specialist I conducting regulatory activities for health care facilities across Florida. Prepares reports, manages files and provides support for QA reviews in the agency.