logo inner

Governance, Risk and Compliance Manager

CrestaUsa Timezones | Remote, Hybrid
This job is no longer open
Interested in defining how AI shapes the future of work? Cresta is on a mission to make every knowledge worker 100x as effective, 10x faster and 10x better. Cresta is focused on using AI to help the workforce, not replace them. Cresta uses our patented Expertise AI to uncover expert insights from every conversation and put those insights into action with real-time coaching during customer conversations.
We’re growing fast! Spun out of the Stanford AI lab and chaired by Google-X founder Sebastian Thrun, Cresta launched in 2020. Since then, we’ve grown revenue and our team by 300%! We’ve assembled a world-class team of AI and ML experts, go-to-market leaders, and top-tier investors and advisors including Andreessen Horowitz, Greylock Partners, Sequoia, and former AT&T CEO John Donovan. Our valued customers include brands like Intuit, Porsche, Adobe, and Dropbox and we have been recognized as a startup to watch by Business Insider, Forbes, and Gartner to name a few.

We have huge ambitions and are looking for stellar candidates who have an entrepreneurial mindset and are excited to use cutting-edge AI to solve real-world business problems.Cresta is seeking a passionate individual with solid compliance experience to drive the GRC function and support growing global data protection and cybersecurity efforts.

What you'll be doing:


  • Perform risk assessments to identify gaps, come up with recommendations, and drive the gaps to remediation.
  • Streamline SOC 2 Type II, ISO 27001 & 27701, PCI-DSS, TISAX and HIPAA audit processes.
  • Perform internal audits and keep the necessary documentation updated as required for audits.
  • Perform gap assessments against new regions and target industry markets to comply with compliance regulations as the company expands.
  • Conduct new-hire and annual security awareness training to educate personnel and re-iterate security and compliance requirements.
  • Establish metrics to track compliance program effectiveness and to report risk.
  • Interface with both technical (Engineering/Product) and non-technical (Sales/Marketing/Customer Success) teams.
  • Respond to customer RFIs, questions, and technical documentation requests (i.e. SOC 2 Type II report).
  • Help build our common control framework and drive adoption of the framework within the organization.
  • Build and automate processes to achieve continuous compliance over the technology control environment.
  • Assist with sales and marketing materials representing product security and compliance.

What we're looking for:


  • 5+ years of experience in security governance, IT audit, or security compliance management
  • 3+ years of program management, with experience in affecting technology decisions
  • End-to-end experience going through SOC 2 Type 2, HITRUST, HIPAA, TISAX, ISO 27001 & 27701, and PCI-DSS external audits
  • Experience in a hands-on technical role, with basic understanding of software implementation and integration
  • Experience with cloud environments on AWS, GCP, Azure
  • A track record of building relationships and credibility with business leads, external partners, and regulators through collaborative and independent programs
  • Experience managing competing efforts and requirements
  • Experience with fast-growing cloud native SaaS start-ups

If you want to make an impact with an amazing product, want to improve your tech skills by working with other exceptional engineers, and like to be part of an amazing international team, then you should join us. We pay an attractive salary and with the Cresta stock options, you can benefit from the company's growth.Apply for this job

This job is no longer open

Life at Cresta

Cresta uses AI to turn sales and service agents into experts on day one, elevating the customer experience and growing the business. Cresta brings together industry-leading AI experts, proven leadership and top tier investors including Andreessen Horowitz, Greylock Partners, Andy Bechtolsheim, Mark Leslie and Vivi Nevo.
Thrive Here & What We Value1. Collaborative Environment2. Innovative Team and Company3. WorldClass AI and ML Experts4. TopTier Investors and Advisors5. Valued Customers (Intuit, Porsche, Verizon)6. Mission to enhance knowledge workers' effectiveness by 10x7. Focus on using AI for workforce improvement8. Recognized as a startup to watch9. Attractive salary and stock options1e. International team
Your tracker settings

We use cookies and similar methods to recognize visitors and remember their preferences. We also use them to measure ad campaign effectiveness, target ads and analyze site traffic. To learn more about these methods, including how to disable them, view our Cookie Policy or Privacy Policy.

By tapping `Accept`, you consent to the use of these methods by us and third parties. You can always change your tracker preferences by visiting our Cookie Policy.

logo innerThatStartupJob
Discover the best startup and their job positions, all in one place.
Copyright © 2024