Director - Governance, Risk, Compliance & Privacy (GRC)
Beacon Software - San Francisco, CA
Hiring: Director - Governance, Risk, Compliance & Privacy (GRC) Company: Beacon Software Location: San Francisco, CA Job Posted Time: 2026-09-10 10:33:33 Target Skills & Keywords : AI, Accessibility, FedRAMP, HIPAA, LLM, PCI DSS, SOC 2, SaaS, Stripe, WCAG About the job Required Skills: •Beacon. The holdco's enterprise governance program: security policy, AI governance, data governance and privacy, enterprise and third-party risk, and posture reporting. Governance-led, including any frameworks Beacon itself elects to pursue. •Portfolio companies. Taking our portfolio companies through their own audits and certifications (SOC 2, ISO 27001, accessibility conformance, and others as their customers require), delivered hands-on as a repeatable service that scales across the portfolio. •Underpinning both: a common control architecture that maps a control once to satisfy many standards, AI-first automation, and clear program reporting. Qualifications: •You have built or substantially matured a GRC program before and taken an organization through SOC 2 Type 2. Typically several years (5+) in GRC, IT governance, or security compliance, though what you have built matters more to us than the count. •A builder with a bias for action. When you see a manual process, your first instinct is how to automate it. •A strong systems thinker. You design scalable GRC architectures, not one-off fixes for the next audit. •Fluent with a compliance automation platform (Vanta, Drata, Secureframe, or similar) and current on AI tooling in practice, not just in theory. •Comfortable across both security compliance and data privacy, or able to ramp quickly on regimes you have not personally run. •An excellent cross-functional communicator who works through influence and can translate compliance requirements into terms both technical and non-technical teams can act on. •Worked in a fast paced, start-up environment. •Privacy or audit certifications (CIPP, CIPM, CISA, CISSP, or ISO 27001 Lead Auditor or Implementer). •Enough technical fluency to scope what the program needs and partner closely with engineering, even without building the tooling yourself. •Multi-entity, private-equity, or holding-company experience. Compensation: •Most private equity firms scale by adding people Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!