Governance, Risk, and Compliance Manager - Privacy
San Francisco, United States · Full-time
- Posted 1mo ago
- From Decagon’s careers page
- Location
- San Francisco, United States
- Type
- Full-time
- Experience
- 5+ years
- Department
- Legal and Compliance
Opens the listing on jobs.ashbyhq.com
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.
About the role
About the Role
Join Decagon as a Governance, Risk, and Compliance Manager and play a critical role in securing customer trust as we scale to serve Fortune 500 and international enterprises. Working closely with the head of security and compliance, you'll be responsible for the day-to-day execution of our compliance program and customer security engagements. This is a high-impact role where you'll directly contribute to closing enterprise deals by efficiently managing security communications with customers, supporting compliance audits, and improving our security documentation. Perfect for someone who thrives in a high impact organization with attention to detail, excellent writing skills, and who wants to build expertise in enterprise AI compliance.
In this role, you will
- Improve and maintain the privacy program against ISO 27701, ISO 27018, HIPAA, GDPR, CCPA/CPRA and the wider set of US state laws.
- Own Decagon's privacy program operations end to end: data inventory, DSAR intake and fulfillment, DPAs and cross-border transfer mechanisms, data retention schedule, subprocessor onboarding and our public subprocessor list, breach notification readiness, and company-wide privacy training.
- Partner with legal team to improve existing programs on data residency, subprocessor flow-downs, retention by data class, DPIAs and transfer impact assessments, while owning and driving day-to-day decision.
Your background looks something like this
- 5+ years of GRC experience in high-growth SaaS or technology companies, with direct responsibility for privacy compliance programs
- Proven track record successfully contributing to SOC 2, ISO 27001, or similar enterprise compliance certifications
- Experience in data privacy regulations including CCPA, GDPR, and emerging AI governance frameworks
- Strong project management skills with ability to coordinate cross-functional teams under tight deadlines
- Excellent written and verbal communication skills to translate complex security concepts for diverse audiences
- Working knowledge of technical security controls and ability to collaborate effectively with engineering teams
Even better if you have
- Experience with AI/ML compliance frameworks and understanding of unique risks in conversational AI systems
- Background in healthcare or financial services with knowledge of HIPAA or PCI requirements
- Track record of building GRC programs at companies scaling from startup to enterprise
- Experience with GRC platforms like Vanta, Drata, or SecureFrame to automate compliance workflows
- Understanding of cloud security particularly Google Cloud Platform compliance and security features
Skills they ask for
Pick one to see other roles that ask for it.
About Decagon
AI concierge for customer serviceDecagon provides AI agents for customer interactions across voice, chat, and email.
See all 39 roles at DecagonMore roles at Decagon
See all 39- Talent, Strategic Projects AssociateSan Francisco · HybridHuman Resources · HybridSan Francisco, United States1d
- Software Engineer, Enterprise ProductSan FranciscoEngineeringSan Francisco, United States2d
- Director, Strategic Accounts - TorontoUnited States · Director · RemoteSales · Director · RemoteUnited States3d
- Strategic FinanceNew York · On-siteFinance and Accounting · On-siteNew York, United States1w
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.