Remote Jobs RockRemote Jobs Rock

Senior GRC Lead

🕒 13 days ago
GovernanceRisk ManagementComplianceSOC 2

📜 Description

  • Own and drive Jasper's compliance audits (SOC 2, ISO 27001, and similar frameworks) from readiness through certification.
  • Support GDPR and broader privacy compliance alongside the Legal team.
  • Rationalize overlapping requirements across frameworks to reduce compliance burden.
  • Serve as the subject-matter expert on control mapping during customer and external audits.
  • Maintain and continuously improve the risk register, including risk identification and remediation tracking.
  • Manage vendor and third-party risk assessments and the vendor security review process.

🛠️ Requirements

  • 8+ years of experience in Governance, Risk & Compliance, ideally at a SaaS company.
  • Deep expertise across multiple compliance and security frameworks, including SOC 2 Type II and ISO 27001.
  • Expertise in modern cloud-native web application development practices and related security best practices.
  • Experience with GRC tooling (e.g., Vanta, Drata, OneTrust, or similar).
  • Strong cross-functional communication skills, comfortable working with Security, Legal, Product, and Engineering.
  • CISA, CISSP, CRISC, or similar certification.

Benefits

  • Dental
  • Vision coverage beginning on the first day for employees and their families
  • Equity grant participation
  • Flexible PTO with a FlexExperience budget ($900 annually) to help you make the most of your time away from work
  • Generous budget for home office set up
  • $1,500 annual learning and development stipend
  • 16 weeks of paid parental leave
Full job description

Jasper is the marketing agents platform, built to help enterprises orchestrate AI agents that execute marketing work at scale. Purpose-built for marketing teams, Jasper enables faster, more consistent execution across campaigns, personalization, localization, and compliance—while maintaining enterprise-grade control and governance.

Jasper is trusted by hundreds of enterprises worldwide, including Prudential, Cushman & Wakefield, and nearly 20% of the Fortune 500. Founded in 2021, Jasper has team members across the U.S., Australia, and France.

About The Role

As a Senior GRC Lead at Jasper, you will own our Governance, Risk, and Compliance program end-to-end—building a program that scales with our AI-native products. You will step in to rebuild and maintain momentum on audits, risk management, and vendor security, partnering closely with Security, Legal, and Engineering to keep Jasper compliant and trustworthy as we grow.

Day-to-day, you will work alongside the Security team, while collaborating cross-functionally with Legal, GTM, People, and Engineering to embed compliance requirements into how the company builds and operates. You will serve as the subject-matter expert on control mapping during customer and external audits, RFPs, and enterprise sales engagements—making trust a competitive advantage for Jasper.

This fully remote role reports to the Director, Security and is open to candidates located anywhere in the continental US.

What you will do at Jasper

  • Own and drive Jasper’s compliance audits (SOC 2, ISO 27001, and similar frameworks) from readiness through certification, with a path toward ISO 42001.

  • Support GDPR and broader privacy compliance alongside the Legal team, without owning the legal interpretation of requirements.

  • Rationalize overlapping requirements across frameworks to reduce compliance burden and create a single source of truth for control ownership.

  • Serve as the subject-matter expert on control mapping during customer and external audits, RFPs, and enterprise sales engagements.

  • Respond to customer security questionnaires and support the sales and legal teams during due diligence.

  • Maintain and continuously improve the risk register, including risk identification, scoring, and remediation tracking.

  • Manage vendor and third-party risk assessments and the vendor security review process.

  • Own policy management—drafting, reviewing, and keeping security and compliance policies current.

  • Partner cross-functionally with Security, Legal, Product, Engineering, etc to embed compliance and governance requirements into how the company builds and operates.

  • Automate compliance workflows, including artifact collection for external audits, internal security compliance reviews, and continuous monitoring tasks.

  • Drive, improve, and help implement AI governance across the company and product

What you will bring to Jasper

  • AI fluency — a working understanding of core AI concepts (LLMs, agents, copilots, tokens, credits, context windows, RAG, data governance, etc.), applied in the context of governance, risk, and compliance for AI-native products.

  • 8+ years of experience in Governance, Risk & Compliance, ideally at a SaaS company.

  • Deep expertise across multiple compliance and security frameworks, including SOC 2 Type II, ISO 27001, NIST CSF, and at least one regulatory framework (GDPR, CCPA, HIPAA, or equivalent).

  • Expertise in modern cloud-native web application development practices and related security best practices, especially in the context of GCP and frontier AI platforms.

  • Experience with GRC tooling (e.g., Vanta, Drata, OneTrust, or similar).

  • Experience managing a risk register and vendor risk program.

  • Strong cross-functional communication — comfortable working with Security, Legal, Product, and Engineering, and able to translate technical issues for non-technical teams.

  • Experience using AI agents, tools, and platforms to automate workflows and build tools, with sound judgment in applying AI responsibly to improve efficiency and impact.

  • Prior experience at a startup or fast-growing SaaS company.

  • CISA, CISSP, CRISC, or similar certification.

  • Experience scoping or pursuing ISO 42001 or other AI governance frameworks.

  • Hands-on experience using agentic coding tools (Cursor, Claude Code, Copilot, etc.) and a working knowledge of Python — you don’t need to be a software engineer, but you should be fluent enough to use AI platforms to modify and run scripts, build automations, and ship small tools end-to-end.

Compensation Range

At Jasper, we believe in pay transparency and are committed to providing our employees and candidates with access to information about our compensation practices. The expected base salary range offered for this role is $174,250 - $205,000. Compensation may vary based on relevant experience, skills, competencies, and certifications.

Benefits & Perks

  • Comprehensive Health, Dental, and Vision coverage beginning on the first day for employees and their families

  • 401(k) program with up to 2% company matching

  • Equity grant participation

  • Flexible PTO with a FlexExperience budget ($900 annually) to help you make the most of your time away from work

  • FlexWellness program ($1,800 annually) to help support your personal health goals

  • Generous budget for home office set up

  • $1,500 annual learning and development stipend

  • 16 weeks of paid parental leave

Our goal is to be a diverse workforce that is representative at all job levels as we know the more inclusive we are, the better our product will be. We are committed to celebrating and supporting our differences and that diversity is essential to innovation and makes us better able to serve our customers. We hire people of all levels and backgrounds who are excited to learn and develop their skills. 

We are an equal opportunity employer. Applicants will not be discriminated against because of race, color, creed, sex, sexual orientation, gender identity or expression, age, religion, national origin, citizenship status, disability, ancestry, marital status, veteran status, medical condition, or any protected category prohibited by local, state or federal laws.

By submitting this application, you acknowledge that you have reviewed and agree to Jasper's CCPA Notice to Candidates, available at legal.jasper.ai/#ccpa.

Versant3

Anti-Piracy & Media Trust Lead

Versant3👥 1001 - 5000 employees🏢 Media And Entertainment
🕒 7 days ago

Lead the design and operationalization of Versant Media's anti-piracy ecosystem, focusing on strategy development, enforcement operations, and cross-functional collaboration to protect content globally.

Anti-piracyContent ProtectionDigital Rights ManagementProgram Management
Instacart

Principal Supply Chain Partner Manager

Instacart👥 10,000+ employees🏢 E-commerce
🕒 6 days ago

As a Principal Supply Chain Partner Manager, you will lead strategic relationships with Instacart's largest supply chain partners, driving growth and influencing cross-functional initiatives.

Strategic Account ManagementBusiness DevelopmentCross-functional LeadershipPartnership Strategies
Instacart

Principal Supply Chain Partner Manager

Instacart👥 10,000+ employees🏢 E-commerce
🕒 6 days ago

The Principal Supply Chain Partner Manager will drive strategic relationships with Instacart's largest supply chain partners, shaping engagement and growth strategies while influencing cross-functional initiatives.

Strategic Account ManagementBusiness DevelopmentCross-functional LeadershipSupply Chain Dynamics
Stripe

Data Excellence Manager

Stripe👥 10,000+ employees🏢 Technology, Information And Internet🤝 B2B
🕒 7 days ago

Build and lead a team of Sales Operations experts to enhance customer data quality, partnering with leadership to address gaps through effective processes and workflows.

Sales OperationsData QualitySystems ThinkingContinuous Improvement

Trusted by Remote Workers