Information Security and GRC Manager

Scribe•San Francisco, CA
•$144,500 - $220,000•Hybrid

About The Position

Scribe is scaling fast, and our security and compliance program needs to keep up. As Information Security & GRC Manager, you'll be the hands-on owner of day-to-day security and compliance work. That means running our SOC 2 program, handling enterprise security reviews, driving remediation with Engineering, and operating our core internal controls. If this seat is empty, audits slip, security questionnaires pile up, enterprise deals wait on answers, and compliance requirements never become real engineering work. As Information Security & GRC Manager, you'll execute and operate Scribe's security and compliance program across assurance, customer security, risk management, and internal security operations. Concretely, you'll: Run our SOC 2 program end to end. This covers control ownership, evidence collection, auditor management, and closing gaps, so that our compliance reflects real security practice rather than paperwork. You'll also support additional frameworks as customer demand requires. Own customer security reviews. You'll complete questionnaires, maintain our trust center and security documentation, and lead security calls alongside Sales, Customer Success, and Legal. Give Legal technical input on the security commitments in customer contracts (MSAs, DPAs, BAAs, AI terms), and flag non-standard requests for a decision. Maintain the risk register, security policies, and vendor security review process. When you see risks, bring them to leadership with clear recommendations, and say what needs fixing now and what can reasonably wait. Turn audit findings, control requirements, and security issues into concrete engineering work, and track that work to completion. Operate and scale core internal security programs: access reviews, security awareness training, endpoint and device management, vulnerability management, and incident response readiness.

Requirements

  • 6+ years of experience in information security, GRC, or security compliance at a SaaS or technology company.
  • 2+ years managing individual contributors.
  • Hands-on experience running SOC 2 Type II audits.
  • Experience handling enterprise customer security reviews and questionnaires alongside Sales, Customer Success, and Legal.
  • Working knowledge of cloud security, identity and access management, endpoint security, and vulnerability management.
  • Familiarity with GRC automation platforms (e.g., Vanta, Drata, Secureframe).
  • Sound judgment about risk, with the ability to prioritize and escalate appropriately.
  • Strong organization and follow-through.
  • Comfort working without a large team around you.
  • Experience with information security and privacy frameworks like ISO 27001, HIPAA, FERPA, public-sector requirements, and AI governance frameworks (e.g., EU AI Act, ISO 42001).

Nice To Haves

  • CISSP, CISM, or CISA certification

Responsibilities

  • Run our SOC 2 program end to end, including control ownership, evidence collection, auditor management, and closing gaps.
  • Support additional compliance frameworks as customer demand requires.
  • Complete enterprise customer security reviews and questionnaires.
  • Maintain Scribe's trust center and security documentation.
  • Lead security calls alongside Sales, Customer Success, and Legal.
  • Provide Legal with technical input on security commitments in customer contracts (MSAs, DPAs, BAAs, AI terms) and flag non-standard requests.
  • Maintain the risk register, security policies, and vendor security review process.
  • Present risks to leadership with clear recommendations for immediate and future action.
  • Translate audit findings, control requirements, and security issues into actionable engineering tasks and track their completion.
  • Operate and scale core internal security programs including access reviews, security awareness training, endpoint and device management, vulnerability management, and incident response readiness.

Benefits

  • Equity in Scribe
  • Comprehensive health, dental, and vision plans
  • Two $0/month medical plan options
  • 401(k) Plan
  • $500/year Flex Benefit for home office equipment, productivity tools, learning & development or fitness/wellness
  • $100/month Commuter Benefits for SF based employees
  • Flexible paid time off
  • Company holidays
  • Paid Parental Leave
  • Free Talkspace membership
  • One Medical access (location-dependent)
  • Kindbody discounts for family planning
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service