NextRaiseNextRaiseFind jobs
Sign inSign up free
Jobs / Auditor in United States of America
4 days ago
Apply with autofill
Apply with autofill
Wispr-flow·4 days ago
4 days ago

Security Assurance & GRC Lead

San Francisco or New York, United States of AmericaFull-timeRemoteSenior · 6-10 years₹1.2Cr – ₹1.6Cr/yr · est.Auditor

Sign up free to see how well your resume matches this role.

Boost your chances at wispr-flow

How you compare FREE

?
Your scoreYour score: not yet known
→
52
Top 10%Top 10%: 52 out of 100

Top 10% of NextRaise users matched against Auditor roles in United States.

Must-have skills for this role

  • grc
  • security compliance
  • customer assurance
  • soc 2

PDF or DOCX · no account needed

Apply faster with autofill FREEwispr-flow uses Ashby - autofill it instead of retyping.careers.example.com/applyAutofillingFull namePriya SharmaEmailpriya.sharma@example.comPhone+49 30 1234567LocationBerlGet the extension

What you'll do

  • Own the GRC roadmap. Define priorities across SOC 2 Type II, ISO 27001, customer requirements, privacy, and risk management. Enterprise blockers come first, with everything else sequenced by business impact.
  • Lead customer assurance end-to-end. Represent Wispr Flow on calls, in security reviews, and in written responses. Own questionnaires, due-diligence requests, vendor assessments, and RFP security sections through completion, and drive cross-functional resolution on escalations. Never make claims the evidence doesn't support.
  • Get ahead of strategic deals. Engage early on major opportunities, anticipate objections, and build a security plan with Sales.
  • Make security a GTM advantage. Improve the Trust Center, standard responses, and security narratives so customers can self-serve and our posture is easy to understand.
  • Build the system, not just run it. Track turnaround times, recurring objections, and repetitive work, then standardize and automate. Keep Drata, SafeBase, and Linear accurate.
  • Develop the team. Partner with our compliance engineer to build the operating processes together, strengthening process design, prioritization, and follow-through while drawing on their technical and compliance expertise.
  • Feed reviews back into the product. Turn patterns from security reviews into structured input for Product and Engineering on SSO/SCIM, audit logs, permissions, retention, data residency, and AI/data handling.
  • Own the AI security narrative. Customers will ask about model providers, training and data usage, retention, subprocessors, and how their data moves through our system. Answer those questions and keep the answers current as the product changes. When incidents happen, coordinate clear, accurate customer-facing communication (you won't own incident response itself).
  • Keep compliance running. Coordinate audit evidence, track deadlines, maintain controls and policies, drive remediation, and keep the risk register, vendor inventory, and compliance calendar current.

What they're looking for

  • Depth in GRC, security compliance, customer assurance, IT audit, or risk management, with enough range to own both the program and the customer conversation.
  • Experience leading customer security reviews and explaining security to technical and non-technical audiences.
  • Working knowledge of SOC 2, ISO 27001, or similar frameworks, and the ability to turn them into a practical roadmap.
  • Judgment: what's a material enterprise blocker vs. what can wait, and what you can answer yourself vs. what needs escalation.
  • A track record of creating structure around manual or ambiguous work and improving the systems behind it.
  • Strong written and verbal communication on risk, posture, and technical constraints, plus the project-management discipline to drive cross-functional work to completion.
  • Comfort working across Engineering, Product, IT, Legal, Sales, Customer Success, and Support, and willingness to do operational work while reducing it over time.

Nice to have

  • Startup or growth-stage SaaS experience supporting enterprise customers.
  • Experience establishing or scaling a compliance or customer assurance program.
  • Familiarity with Drata, Vanta, SafeBase, or similar tools, and with standard questionnaires (SIG, CAIQ, HECVAT, VSAQ).
  • Working knowledge of cloud security, access control, encryption, logging, vulnerability management, incident response, and SaaS architecture.
  • Familiarity with AI security and privacy: model providers, training and data usage, retention, subprocessors, data flows, access boundaries.
  • Exposure to GDPR, CCPA, HIPAA, data residency, or vendor-risk management.
  • Experience building automations or integrations for compliance work.
  • Security+, CISA, CGRC, ISO 27001 Lead Implementer, or similar certification.

Summarised by NextRaise from the employer’s description, which follows in full below.

Full description from employer

About Wispr

Wispr is an AI research and product company building the voice interface for computing. AI can now reason, code, and act. Yet, humans still do the work of the interface. We think that’s backwards.

Our first products are Flow, which lets you speak naturally in any application, and Notetaker, which builds context across conversations. We’re building toward an interface that can perceive, understand, and take action with earned trust. That means solving hard problems across models, systems, and product - and caring about the final human experience as deeply as the technology underneath it.


We’re a talent-dense team that holds strong opinions, tests them quickly, and builds technology that sparks joy. Our goal is to build the first voice interface used every day by a billion people.

Wispr Flow is hiring a Security Assurance & GRC Lead to own our customer assurance and compliance programs and decide where they go next. You'll set the GRC roadmap across SOC 2, ISO 27001, privacy, and enterprise customer requirements, and build systems that let the program scale faster than request volume.

You'll work closely with our vCISO and with Engineering, Product, Legal, Sales, Customer Success, and Support. Much of the role is customer-facing: you'll lead security conversations with sophisticated buyers, represent our posture accurately (including being direct about gaps), and know when to pull in deeper expertise. On our largest deals you'll engage early, identify likely blockers, and have a plan before the questionnaire arrives. You're the DRI for high-priority security and assurance escalations.

The goal: security becomes a reason customers choose us.

What you'll do

  1. Own the GRC roadmap. Define priorities across SOC 2 Type II, ISO 27001, customer requirements, privacy, and risk management. Enterprise blockers come first, with everything else sequenced by business impact.

  2. Lead customer assurance end-to-end. Represent Wispr Flow on calls, in security reviews, and in written responses. Own questionnaires, due-diligence requests, vendor assessments, and RFP security sections through completion, and drive cross-functional resolution on escalations. Never make claims the evidence doesn't support.

  3. Get ahead of strategic deals. Engage early on major opportunities, anticipate objections, and build a security plan with Sales.

  4. Make security a GTM advantage. Improve the Trust Center, standard responses, and security narratives so customers can self-serve and our posture is easy to understand.

  5. Build the system, not just run it. Track turnaround times, recurring objections, and repetitive work, then standardize and automate. Keep Drata, SafeBase, and Linear accurate.

  6. Develop the team. Partner with our compliance engineer to build the operating processes together, strengthening process design, prioritization, and follow-through while drawing on their technical and compliance expertise.

  7. Feed reviews back into the product. Turn patterns from security reviews into structured input for Product and Engineering on SSO/SCIM, audit logs, permissions, retention, data residency, and AI/data handling.

  8. Own the AI security narrative. Customers will ask about model providers, training and data usage, retention, subprocessors, and how their data moves through our system. Answer those questions and keep the answers current as the product changes. When incidents happen, coordinate clear, accurate customer-facing communication (you won't own incident response itself).

  9. Keep compliance running. Coordinate audit evidence, track deadlines, maintain controls and policies, drive remediation, and keep the risk register, vendor inventory, and compliance calendar current.

What we're looking for

  • Depth in GRC, security compliance, customer assurance, IT audit, or risk management, with enough range to own both the program and the customer conversation.

  • Experience leading customer security reviews and explaining security to technical and non-technical audiences.

  • Working knowledge of SOC 2, ISO 27001, or similar frameworks, and the ability to turn them into a practical roadmap.

  • Judgment: what's a material enterprise blocker vs. what can wait, and what you can answer yourself vs. what needs escalation.

  • A track record of creating structure around manual or ambiguous work and improving the systems behind it.

  • Strong written and verbal communication on risk, posture, and technical constraints, plus the project-management discipline to drive cross-functional work to completion.

  • Comfort working across Engineering, Product, IT, Legal, Sales, Customer Success, and Support, and willingness to do operational work while reducing it over time.

Nice to have

  • Startup or growth-stage SaaS experience supporting enterprise customers.

  • Experience establishing or scaling a compliance or customer assurance program.

  • Familiarity with Drata, Vanta, SafeBase, or similar tools, and with standard questionnaires (SIG, CAIQ, HECVAT, VSAQ).

  • Working knowledge of cloud security, access control, encryption, logging, vulnerability management, incident response, and SaaS architecture.

  • Familiarity with AI security and privacy: model providers, training and data usage, retention, subprocessors, data flows, access boundaries.

  • Exposure to GDPR, CCPA, HIPAA, data residency, or vendor-risk management.

  • Experience building automations or integrations for compliance work.

  • Security+, CISA, CGRC, ISO 27001 Lead Implementer, or similar certification.

What success looks like in the first six months

  • You own the customer assurance motion end-to-end: strategic reviews, customer calls, questionnaires, escalations, and follow-through.

  • There's a clear GRC roadmap that leadership has signed off on and you're driving.

  • Security-review turnaround time has dropped materially, with more work standardized, automated, or self-served through the Trust Center.

  • Leadership has a current view of our biggest security risks and enterprise blockers, with owners and plans for the ones that matter most.

Logistics

We sponsor H1B, O1, EB1, L1, STEM OPT, and more. We can't guarantee sponsorship for every role, but if we make you an offer we'll make every reasonable effort, with help from our immigration law firm.

We strongly encourage you to apply even if you don't meet every qualification. The strongest candidates we meet rarely do, so don't exclude yourself prematurely. We're rethinking how humans interact with AI, and doing that well demands diversity of perspective and experience.

We're committed to a fair and accessible interview process. If you need any accommodations or adjustments, please let us know.

Company

Wispr-flow
San Francisco or New York, United States of America

Company facts come from this company's own listings. We only show what the postings themselves carry.

Sourced from Wispr Flow's careers site·first seen 17 Sept 2026·last verified 17 Sept 2026·How we source jobs

Similar jobs

  • 2027 Internal Audit - Information Technology & Cybersecurity Summer Internship at bbhNew York, United States of America–match not yet calculated
  • Order Checker Auditor at onelineageLa Porte, United States of America–match not yet calculated
  • Tax Auditor I at ncMecklenburg County, United States of America–match not yet calculated
  • Inventory Control & Quality Assurance Manager at genptLebanon, TN, USA–match not yet calculated
  • Auditor/a de Taller - Seguros (Hermosillo, Son) at bbvaSonora, United States of America–match not yet calculated

Browse more jobs

  • Auditor jobs in United States
  • Accountant jobs in United States
  • Bookkeeper jobs in United States
  • Accounts Receivable Specialist jobs in United States
  • Auditor jobs in India
  • Auditor jobs in United Kingdom