Governance, Risk, and Compliance Manager

TensorWaveLas Vegas, NV

About The Position

As TensorWave's first dedicated Governance, Risk & Compliance Manager, you will own the GRC framework end to end. This role is crucial for transforming security from a mere compliance checkbox into a competitive advantage. You will build a continuous compliance posture that accelerates enterprise sales cycles, secures larger contracts, and prepares the company for stricter regulatory oversight and potential future liquidity events. Operating as a senior individual contributor, you will have broad ownership, including designing controls, conducting internal audits, establishing vendor risk governance, and providing leadership with clear visibility into risks. You possess the unique ability to build both scrappy, compliant processes suitable for a startup environment and mature them towards enterprise standards, understanding the nuances of each.

Requirements

  • 5–8+ years of experience in Information Security, IT Audit, or GRC.
  • Hands-on experience designing, implementing, and defending controls for SOC 2 Type II, ISO 27001, SOX, and/or PCI DSS.
  • Strong working knowledge of Sarbanes-Oxley compliance, including evidence preparation to AICPA or PCAOB standards.
  • A proven track record in both fast-paced Series B/C startups and a mature enterprise or Big 4 audit environment, demonstrating the ability to build processes from scratch and understand scaled "good" practices.
  • Ability to operate as a hands-on owner, not solely a program overseer.

Nice To Haves

  • Experience with API-driven/continuous GRC tooling (e.g., Vanta, Drata, or similar).
  • Exposure to cloud or GPU infrastructure security.
  • Relevant certifications such as CISA, CISSP, CRISC, ISO 27001 Lead Auditor/Implementer.
  • Experience embedding compliance into CI/CD pipelines.

Responsibilities

  • Own the GRC framework, including designing, implementing, and continuously testing a unified controls framework, such as IT General Controls (ITGCs), across a diverse regulatory landscape.
  • Manage and enhance SOC 2 Type II and ISO 27001 certifications by driving towards automated, continuous evidence collection to reduce manual efforts during audit cycles.
  • Develop the SOX roadmap by designing and testing internal controls over financial reporting (ICFR) and ITGCs aligned with AICPA/PCAOB standards, delivering a gap analysis and remediation plan for future readiness.
  • Establish a vendor and third-party risk program, replacing manual, ad-hoc reviews with an automated, enterprise-grade system designed for a complex SaaS ecosystem.
  • Operationalize a risk register by conducting formal, continuous internal risk assessments, mapping them to a corporate risk register, and reviewing it quarterly with leadership to guide security investments.
  • Enable the business by creating and maintaining a centralized Trust Center to reduce the time sales and engineering teams spend responding to security questionnaires.
  • Integrate compliance into the development lifecycle by partnering with engineering to embed compliance early, ensuring new features are released without compromising existing controls.
  • Optimize the policy program by maintaining a policy suite that meets legal and security requirements while minimizing the operational burden on supporting teams.

Benefits

  • Stock Options
  • 100% paid Medical, Dental, and Vision insurance for Employees
  • Company Health Savings Account Contributions
  • 100% paid Short Term and Long Term Disability Insurance for Employees
  • Life and Voluntary Supplemental Insurance Options
  • Other Insurance Options, such as Pet & Legal Insurance
  • Various Supplementary Health Benefits, such as discounted Virtual Healthcare Appointments and Serious Illness Support
  • Flexible Spending Account
  • 401(k)
  • Employee Assistance Program
  • Flexible PTO
  • Paid Holidays
  • Parental Leave
  • Other In-Office Perks
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service