NextRaiseNextRaiseFind jobs
Sign inSign up free
Jobs / Compliance Officer in United States of America
11 days ago
Apply with autofill
Apply with autofill
Beaconsoftware·11 days ago
11 days ago

Director - Governance, Risk, Compliance & Privacy (GRC)

San Francisco, United States of AmericaFull-timeRemoteSenior · 10-15 yearsCompliance Officer

Sign up free to see how well your resume matches this role.

Boost your chances at beaconsoftware

How you compare FREE

?
Your scoreYour score: not yet known
→
51
Top 10%Top 10%: 51 out of 100

Top 10% of NextRaise users matched against Compliance Officer roles in United States.

Must-have skills for this role

  • soc 2
  • data privacy
  • risk management
  • vanta

PDF or DOCX · no account needed

Apply faster with autofill FREEbeaconsoftware uses Ashby - autofill it instead of retyping.careers.example.com/applyAutofillingFull namePriya SharmaEmailpriya.sharma@example.comPhone+49 30 1234567LocationBerlGet the extension

What you'll do

  • Beacon. The holdco's enterprise governance program: security policy, AI governance, data governance and privacy, enterprise and third-party risk, and posture reporting.
  • Portfolio companies. Taking our portfolio companies through their own audits and certifications (SOC 2, ISO 27001, accessibility conformance, and others as their customers require), delivered hands-on as a repeatable service that scales across the portfolio.

What they're looking for

  • You have built or substantially matured a GRC program before and taken an organization through SOC 2 Type 2.
  • Typically several years (5+) in GRC, IT governance, or security compliance, though what you have built matters more to us than the count.
  • A builder with a bias for action. When you see a manual process, your first instinct is how to automate it.
  • A strong systems thinker. You design scalable GRC architectures, not one-off fixes for the next audit.
  • Fluent with a compliance automation platform (Vanta, Drata, Secureframe, or similar) and current on AI tooling in practice, not just in theory.
  • Comfortable across both security compliance and data privacy, or able to ramp quickly on regimes you have not personally run.
  • An excellent cross-functional communicator who works through influence and can translate compliance requirements into terms both technical and non-technical teams can act on.
  • A clear writer.

Nice to have

  • Privacy or audit certifications (CIPP, CIPM, CISA, CISSP, or ISO 27001 Lead Auditor or Implementer).
  • Experience with regimes beyond SOC 2 (ISO 27001, PCI DSS, HIPAA, FedRAMP, StateRAMP) and accessibility conformance (WCAG, VPAT).
  • Enough technical fluency to scope what the program needs and partner closely with engineering, even without building the tooling yourself.
  • Multi-entity, private-equity, or holding-company experience.
  • M&A security and privacy diligence experience.

Summarised by NextRaise from the employer’s description, which follows in full below.

Full description from employer

About Beacon Software

Beacon is acquiring and operating a portfolio of vertical SaaS companies. Most private equity firms scale by adding people. We are building Beacon to scale by adding software. The thesis is simple: portfolio operations, value creation, and deal sourcing are bottlenecked by human attention, and an agentic operating system can lift that ceiling by an order of magnitude.

We are looking for a GRC leader to build and scale the governance, risk, compliance, and privacy function for a growing portfolio of software companies. This is a founding, high-ownership role for someone who has built before and treats automation and modern AI tooling as the default way to operate.

Beacon has raised $550M+ from investors including General Catalyst, Lightspeed, D1 Capital, CPMG, and the family offices of the founders of Stripe, DoorDash, and Ramp.

 

About the Role

Our GRC function is at an early, formative stage. You would shape it from the foundations and scale it across the portfolio, working directly with our portfolio companies to take them through their own audits and certifications, and designing a program that grows with the business rather than one built for a single audit. The mandate spans security compliance, data privacy, risk, and AI governance. We expect it to be built AI-first: modern automation platforms and LLM-assisted workflows over manual process.

What You'll Do

The role spans two scopes:

  • Beacon. The holdco's enterprise governance program: security policy, AI governance, data governance and privacy, enterprise and third-party risk, and posture reporting. Governance-led, including any frameworks Beacon itself elects to pursue.

  • Portfolio companies. Taking our portfolio companies through their own audits and certifications (SOC 2, ISO 27001, accessibility conformance, and others as their customers require), delivered hands-on as a repeatable service that scales across the portfolio.

Underpinning both: a common control architecture that maps a control once to satisfy many standards, AI-first automation, and clear program reporting.

Who You Are

  • You have built or substantially matured a GRC program before and taken an organization through SOC 2 Type 2. Typically several years (5+) in GRC, IT governance, or security compliance, though what you have built matters more to us than the count.

  • A builder with a bias for action. When you see a manual process, your first instinct is how to automate it.

  • A strong systems thinker. You design scalable GRC architectures, not one-off fixes for the next audit.

  • Fluent with a compliance automation platform (Vanta, Drata, Secureframe, or similar) and current on AI tooling in practice, not just in theory.

  • Comfortable across both security compliance and data privacy, or able to ramp quickly on regimes you have not personally run.

  • An excellent cross-functional communicator who works through influence and can translate compliance requirements into terms both technical and non-technical teams can act on.

  • A clear writer.

  • Worked in a fast paced, start-up environment.

Bonus Points

  • Privacy or audit certifications (CIPP, CIPM, CISA, CISSP, or ISO 27001 Lead Auditor or Implementer).

  • Experience with regimes beyond SOC 2 (ISO 27001, PCI DSS, HIPAA, FedRAMP, StateRAMP) and accessibility conformance (WCAG, VPAT).

  • Enough technical fluency to scope what the program needs and partner closely with engineering, even without building the tooling yourself.

  • Multi-entity, private-equity, or holding-company experience.

  • M&A security and privacy diligence experience.


Our Values at Beacon Software

  • Humility: We acknowledge that the path to getting to the right answer involves being wrong along the way. We have strong beliefs which are weakly held. We actively seek new ideas and believe we can learn from anyone at any time.

  • Honesty: We are truth seeking in our approach to business problems. Business is a repeat game and we believe that human relationships generate alpha. We understand that trust is earned over a lifetime and can be lost in an instant.

  • Hunger: We play to win. We hold ourselves to high standards and will not be outworked. We take pride in having a deep sense of responsibility to ourselves, each other, our partners, and our customers. We believe to whom much is given much is expected.

  • Horizon: We seek to build a generational software company. This will take decades. We manage our expectations and those of our partners to take advantage of the 8th wonder of the world - compounding growth.


How We Use AI in Our Hiring Process: To ensure transparency, we want candidates to know that Beacon Software uses Artificial Intelligence and AI-enabled tools to assist with screening, reviewing, organizing and highlighting profiles and applications that match the key requirements for each role.

 

AI does not make hiring decisions: Every application is reviewed by a member of our team, and all decisions throughout the process are made by humans. We use AI to support efficiency and consistency, not to replace human judgment. We are committed to a fair, thoughtful, and equitable experience for every candidate.

Company

Beaconsoftware
San Francisco, United States of America

Company facts come from this company's own listings. We only show what the postings themselves carry.

Sourced from Beaconsoftware's careers site·first seen 9 Sept 2026·last verified 11 Sept 2026·How we source jobs

Similar jobs

  • AML Quality Control Analyst at BarclaysWhippany, United States of America–match not yet calculated
  • Senior Director, Healthcare Disputes / Compliance at ankuraSouth Carolina–match not yet calculated
  • Sr. Manager, QA Compliance at sareptaAndover, United States of America–match not yet calculated
  • Sr. Clinical Compliance Consultant at massgeneralbrighamBoston, United States of America–match not yet calculated
  • Hybrid Compliance Coordinator - Greenville, SC at crossroadstreatmentcentersGreenville, United States of America–match not yet calculated

Browse more jobs

  • Compliance Officer jobs in United States
  • Insurance Agent jobs in United States
  • Risk Analyst jobs in United States
  • Insurance Claims Adjuster jobs in United States
  • Compliance Officer jobs in India
  • Compliance Officer jobs in United Kingdom