The Role :
This is a Founder's Office role embedded in EPD (Engineering, Product & Design). Roughly 60-70% of the work is technical program management across EPD initiatives - tracking them closely and driving them to completion - and 30-40% is owning the GRC and audit program.
Because audits are calendar-driven, GRC peaks around certification cycles, leaving the rest of the year for broader program management across the organization. You'll work hand-in-hand with the Chief of Staff and the founding team.
What You'll Do :
1. Program Manage EPD Initiatives (Primary) :
- Drive and track initiatives across Engineering, Product & Design end-to-end.
- Run Agile ceremonies, sprint planning, and maintain Linear hygiene.
- Manage roadmaps, dependencies, and timelines while surfacing status, risks, and blockers to leadership.
2. Be an Extension of the Founder's Office :
- Partner closely with the Chief of Staff and founding team to translate strategy into execution, drive cross-functional programs to completion, and provide leadership with clear visibility into progress and risks.
3. Own the GRC & Audit Calendar (30-40%) :
- Lead audits end-to-end - including SOC 2 today, ISO 27001 and GDPR next - covering scoping, control testing, evidence collection, auditor coordination, remediation, and building a continuous, risk-based compliance program.
4. Control Design & Cross-Framework Mapping :
- Maintain policies, risk registers, and control narratives.
- Map controls across SOC 2, ISO 27001, ISO 42001, NIST CSF, GDPR, and emerging AI governance frameworks.
- Partner with engineering to implement practical controls across cloud infrastructure, SDLC, IAM, logging, monitoring, and incident response.
5. Customer Trust & Enterprise Enablement :
- Own security reviews, questionnaires, and trust documentation that help accelerate enterprise sales and partnerships with leading global customers.
6. Build the Operating Cadence :
- Establish the rituals, dashboards, and tooling - including Linear for delivery and Vanta, Drata, or Secureframe for continuous compliance - to ensure program delivery and compliance posture remain visible and scalable.
What It Takes :
- 5+ years of experience in Technical Program Management within an Engineering/Product organization, including hands-on ownership of a compliance or audit program (SOC 2 or similar).
- 2+ years at one organization driving cross-functional EPD programs end-to-end and/or building a compliance program from the ground up with full ownership of outcomes.
- Strong experience running Agile/Scrum ceremonies, sprint planning, and roadmap tracking using Linear (or Jira), with a proven ability to drive complex, cross-functional initiatives.
- Hands-on expertise in SOC 2 Type II and ISO 27001, with working knowledge of NIST CSF, GDPR, ISO 42001, NIST AI RMF, and continuous compliance platforms such as Vanta, Drata, or Secureframe.
- Experience partnering across Engineering, Product, and Design teams while acting as a trusted extension of the Founder's Office or Chief of Staff.
- Ability to build processes, frameworks, and operating mechanisms from the ground up in a fast-paced startup environment.
- Certifications such as CSM, PMP, CISA, CISM, CISSP, or ISO 27001 Lead Auditor are a plus.
Why Join Us?
- High Impact : Work directly with the Founder's Office to drive strategic execution while building a strong compliance foundation for enterprise growth.
- Ownership : Take end-to-end responsibility for mission-critical programs and initiatives.
- Complex Challenges : Manage a portfolio of Engineering, Product, and Design programs alongside a multi-framework compliance roadmap on modern cloud and ML infrastructure.
- Growth : Learn from a high-caliber team while expanding into broader program leadership, Founder's Office responsibilities, or advanced GRC expertise.
- Culture : Open, collaborative, and values-driven environment with high autonomy.
- Benefits : Competitive salary, equity, hybrid work setup, premium healthcare, and additional employee benefits.