Security Compliance Lead
2 weeks ago
Faire is an online wholesale marketplace built on the belief that the future is local - independent retailers around the globe are doing more revenue than Walmart and Amazon combined, but individually, they are small compared to these massive entities. At Faire, we're using the power of tech, data, and machine learning to connect this thriving community of entrepreneurs across the globe. Picture your favorite boutique in town - we help them discover the best products from around the world to sell in their stores. With the right tools and insights, we believe that we can level the playing field so that small businesses everywhere can compete with these big box and e-commerce giants.
By supporting the growth of independent businesses, Faire is driving positive economic impact in local communities, globally. We're looking for smart, resourceful and passionate people to join us as we power the shop local movement. If you believe in community, come join ours.
About the role
As Faire's inaugural GRC Lead, you will be responsible for designing, implementing, and scaling our governance, risk, and compliance program from the ground up. This role blends strategic planning with hands-on execution to establish the frameworks, processes, and controls that strengthen our security, privacy, and compliance posture.
You will work closely with teams across engineering, IT, legal, and finance to integrate risk management into everyday operations, ensure alignment with regulatory and industry standards, and support Faire's evolving business and product needs.
In addition to building the core GRC program, you will lead our preparation for SOX ITGC readiness by collaborating with internal partners and external auditors to define scope, document controls, and enhance our audit processes. This role is ideal for someone who enjoys building programs from the ground up, can navigate both technical and compliance challenges, and is eager to shape how Faire manages risk at scale.
What You'll Do:
- Formulate and drive GRC roadmap, policies, vendor security reviews, and employee awareness training.
- An opportunity to expand into the SOX ITGC program
- Develop and maintain a robust governance framework to support Faire's strategic objectives and ensure alignment with industry best practices.
- Ensure adherence to applicable laws, regulations, and standards (e.g. CCPA / GDPR).
- Develop and deliver GRC training programs for employees to promote a culture of accountability and awareness.
- Partner with external auditors to achieve security compliance certifications and reports.
- Regularly report on status, operational metrics and KPI's, providing transparency to company leadership and internal stakeholder teams.
- Drive compliance certifications including ISO 27001, CCPA, GDPR, and SOC2 Type II.
- 8+ years in the Security & IT Governance, Risk, and Compliance space
- Big 4 experience with security risk and compliance audits, or equivalent experience leading security compliance teams in financial services, technology firms, or other regulated industries.
- Hungry to expand outside typical GRC scope, assisting with SOX ITGCs.
- Experience in building policies and processes, and completing audits within following frameworks: ISO 27001, SOC2 Type II
- Proficiency with GRC tools and technologies used to manage risk and compliance programs
- Ability to collaborate cross-functionally, including engineering, sales, legal, finance, and other teams.
- Strong oral and written communication skills.
- Strong analytical and result-driven mindset.
California: the pay range for this role is $178,000 to $245,000 per year.
This role will also be eligible for equity and benefits. Actual base pay will be determined based on permissible factors such as transferable skills, work experience, market demands, and primary work location. The base pay range provided is subject to change and may be modified in the future.
Hybrid Faire employees currently go into the office 2 days per week on Tuesdays and Thursdays. Effective starting in January 2026, employees will be expected to go into the office on a third flex day of their choosing (Monday, Wednesday, or Friday). Additionally, hybrid in-office roles will have the flexibility to work remotely up to 4 weeks per year. Specific Workplace and Information Technology positions may require onsite attendance 5 days per week as will be indicated in the job posting.
Applications for this position will be accepted for a minimum of 30 days from the posting date.
Why you'll love working at Faire
- We are entrepreneurs: Faire is being built for entrepreneurs, by entrepreneurs. We believe entrepreneurship is a calling and our mission is to empower entrepreneurs to chase their dreams. Every member of our team is taking part in the founding process.
- We are using technology and data to level the playing field: We are leveraging the power of product innovation and machine learning to connect brands and boutiques from all over the world, building a growing community of more than 350,000 small business owners.
- We build products our customers love: Everything we do is ultimately in the service of helping our customers grow their business because our goal is to grow the pie - not steal a piece from it. Running a small business is hard work, but using Faire makes it easy.
- We are curious and resourceful: Inquisitive by default, we explore every possibility, test every assumption, and develop creative solutions to the challenges at hand. We lead with curiosity and data in our decision making, and reason from a first principles mentality.
Faire was founded in 2017 by a team of early product and engineering leads from Square. We're backed by some of the top investors in retail and tech including: Y Combinator, Lightspeed Venture Partners, Forerunner Ventures, Khosla Ventures, Sequoia Capital, Founders Fund, and DST Global. We have headquarters in San Francisco and Kitchener-Waterloo, and a global employee presence across offices in Toronto, London, and New York. To learn more about Faire and our customers, you can read more on our blog.
Faire provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability, genetics, sexual orientation, gender identity or gender expression.
Faire is committed to providing access, equal opportunity and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. Accommodations are available throughout the recruitment process and applicants with a disability may request to be accommodated throughout the recruitment process. We will work with all applicants to accommodate their individual accessibility needs. To request reasonable accommodation, please fill out our Accommodation Request Form (https://bit.ly/faire-form)
Privacy
For information about the type of personal data Faire collects from applicants, as well as your choices regarding the data collected about you, please visit Faire's Privacy Notice (https://www.faire.com/privacy)
-
Information Security Compliance Lead
3 days ago
San Francisco, CA, United States IVO Inc Full timeWhy Ivo? Contract negotiation is the most time-consuming, costly, and difficult component of the contract lifecycle-and it hasn't gotten much easier since the days of fax machines. Large language models have unlocked the ability to solve many contract negotiation problems at scale. Our product is best-in-market (we have an 85%+ h2h trial win rate) and used...
-
Information Security Compliance Lead
2 weeks ago
San Francisco, CA, United States IVO Inc Full timeWhy Ivo? Contract negotiation is the most time-consuming, costly, and difficult component of the contract lifecycle-and it hasn't gotten much easier since the days of fax machines. Large language models have unlocked the ability to solve many contract negotiation problems at scale. Our product is best-in-market (we have an 85%+ h2h trial win rate) and used...
-
Information Security Compliance Lead
2 days ago
San Francisco, CA, United States IVO Inc Full timeWhy Ivo? Contract negotiation is the most time-consuming, costly, and difficult component of the contract lifecycle-and it hasn't gotten much easier since the days of fax machines. Large language models have unlocked the ability to solve many contract negotiation problems at scale. Our product is best-in-market (we have an 85%+ h2h trial win rate) and used...
-
Senior IT Security
5 days ago
San Francisco, CA, United States Network Right LLC Full timeA leading cybersecurity consulting firm is seeking a Senior IT Security & Compliance Consultant in San Francisco. In this hybrid role, you will guide clients through compliance readiness and risk management, leveraging your extensive experience in SOC 2 and ISO 27001. The ideal candidate has a strong understanding of information security principles and...
-
Security Account Manager
2 weeks ago
San Francisco, CA, United States Command Security Full timeSecurity Account / Multi-Site Manager Location: Multiple client sites within 50 miles of Mountain View, CA (including regular work in San Francisco, CA) Position Type: Full-Time, Exempt / Salaried About Us Command Security Services (CSS) LP is a premier California-based security company headquartered in Mountain View, dedicated to delivering top-tier safety...
-
Security Risk and Compliance Analyst
2 weeks ago
San Francisco, CA, United States Asana Full timeAt Asana, security is foundational to our mission of helping teams work together effortlessly. Our security team protects Asana's employees, users, and customers by proactively addressing threats, ensuring compliance with legal and regulatory requirements, and fostering a culture of security throughout our product and operations. We are a team of security...
-
Security Risk and Compliance Analyst
2 weeks ago
San Francisco, CA, United States Asana Full timeAt Asana, security is foundational to our mission of helping teams work together effortlessly. Our security team protects Asana's employees, users, and customers by proactively addressing threats, ensuring compliance with legal and regulatory requirements, and fostering a culture of security throughout our product and operations. We are a team of security...
-
Security Risk and Compliance Analyst
5 days ago
San Francisco, CA, United States Asana Full timeAt Asana, security is foundational to our mission of helping teams work together effortlessly. Our security team protects Asana's employees, users, and customers by proactively addressing threats, ensuring compliance with legal and regulatory requirements, and fostering a culture of security throughout our product and operations. We are a team of security...
-
Lead - Governance, Risk & Compliance
2 weeks ago
San Francisco, CA, United States TEPHRA Full timeDescription: Location: San Francisco, CA Responsibilities: 1. Develop Data Privacy and Ethics Strategies: •Lead the development, implementation, and enforcement of data privacy and ethics compliance strategies across the organization. •Align the company's operations with global data protection regulations (e.g., GDPR, CCPA, HIPAA, etc.) and ethical...
-
Founding Security Engineer
3 days ago
San Francisco, CA, United States Sift Science Full timeAbout Sift At Sift, we're redefining how modern machines are built, tested, and operated. Our platform provides engineers with real-time observability over high-frequency telemetry, eliminating bottlenecks and enabling faster, more reliable development. Sift was born from our work at SpaceX on Dragon, Falcon, Starlink, and Starship-where scaling telemetry,...