Director - Governance, Risk, Compliance & Privacy (GRC)

Beacon SoftwareSan Francisco, CA

About The Position

Beacon Software is building a portfolio of vertical SaaS companies, focusing on scaling through software rather than just adding people. They are seeking a founding GRC leader to establish and grow the governance, risk, compliance, and privacy function across their portfolio. This role emphasizes automation and modern AI tooling as the primary operating method. Beacon has secured significant funding from prominent investors. The GRC function is in its early stages, and the Director will be responsible for building it from the ground up and scaling it across the portfolio. This involves working directly with portfolio companies to guide them through audits and certifications, and designing a program that can evolve with the business. The scope includes security compliance, data privacy, risk management, and AI governance, with an AI-first approach utilizing automation platforms and LLM-assisted workflows.

Requirements

  • Experience building or substantially maturing a GRC program.
  • Experience taking an organization through SOC 2 Type 2.
  • Typically 5+ years in GRC, IT governance, or security compliance.
  • A builder with a bias for action and a focus on automation.
  • Strong systems thinking to design scalable GRC architectures.
  • Fluent with a compliance automation platform (e.g., Vanta, Drata, Secureframe).
  • Current knowledge of AI tooling in practice.
  • Comfortable across both security compliance and data privacy, or able to ramp quickly.
  • Excellent cross-functional communication skills, working through influence.
  • Clear writing ability.

Nice To Haves

  • Privacy or audit certifications (CIPP, CIPM, CISA, CISSP, or ISO 27001 Lead Auditor or Implementer).
  • Experience with regimes beyond SOC 2 (ISO 27001, PCI DSS, HIPAA, FedRAMP, StateRAMP).
  • Experience with accessibility conformance (WCAG, VPAT).
  • Sufficient technical fluency to scope program needs and partner with engineering.
  • Multi-entity, private-equity, or holding-company experience.
  • M&A security and privacy diligence experience.

Responsibilities

  • Build and scale the governance, risk, compliance, and privacy function for Beacon Software and its portfolio companies.
  • Develop and implement the holdco's enterprise governance program, including security policy, AI governance, data governance and privacy, enterprise and third-party risk, and posture reporting.
  • Lead the GRC function with a governance-led approach, pursuing relevant frameworks for Beacon itself.
  • Guide portfolio companies through their audits and certifications (e.g., SOC 2, ISO 27001, accessibility conformance) as a repeatable, scalable service.
  • Establish a common control architecture that maps controls to satisfy multiple standards.
  • Implement AI-first automation within the GRC function.
  • Develop and maintain clear program reporting for both Beacon and its portfolio companies.
  • Translate compliance requirements into actionable terms for technical and non-technical teams.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service