Staff GRC Specialist

ForeFlightAustin, TX
Remote

About The Position

Jeppesen ForeFlight is seeking a Security Assurance & Operations leader to own two critical functions within our Governance, Risk, and Compliance organization. This role serves as the single point of contact for all customer-facing security inquiries (including HECVAT, SIG, CAIQ, customer audits, and agency-specific questionnaires) while also supporting the operational governance of our compliance program to ensure documentation remains current and audit-ready between cycles. As Jeppesen ForeFlight continues to grow its enterprise and public-sector customer base, the volume and complexity of security-related requests from customers, procurement teams, and government agencies has grown with it. This role is purpose-built to ensure those requests are handled with speed, consistency, and accuracy to protect both our customer relationships and our ability to compete in security-sensitive markets. This role reports directly to the Director of GRC with dotted-line working relationships across the Proposals Team, Sales, Engineering, Legal, and Product Security. This position is 100% remote, US-based. Limited travel may be required; not estimated to exceed 10% of the employee's time.

Requirements

  • Bachelor's degree or equivalent experience in a technical, business, or compliance-adjacent field
  • 4+ years in a proposal management, GRC, security compliance, or combined assurance function with hands-on operational ownership of both process and content
  • Direct, hands-on experience completing SIG, CAIQ, HECVAT or comparable vendor security questionnaires at volume in a B2B SaaS or enterprise technology environment
  • Advanced working experience with an enterprise RFP or questionnaire management platform
  • Strong system thinking with the ability to establish and run security intake and tracking cross-functionally without formal authority
  • Experience with AI-assisted workflows or platform integrations that accelerate response cycles and reduce manual effort
  • Strong written and verbal communication skills along with the ability to translate technical security concepts into clear, accurate, customer language
  • Strong organizational discipline is required to manage a high volume of concurrent requests, review cycles, and deadlines with precision
  • Comfortable producing metrics and status reporting for leadership on inquiry performance and program health

Nice To Haves

  • Experience in a high-growth B2B SaaS or technology company where security questionnaires are high-volume, time-sensitive, and directly tied to revenue and renewal outcomes
  • Experience building or scaling a centralized security Q&A knowledge base across cross-functional subject matter experts
  • Background supporting government or public-sector customers with procurement, renewal, or compliance documentation requirements
  • Security, compliance, or industry certification relevant to the role (e.g., Responsive platform certification, Fortinet NES, cloud networking, or similar)
  • Responsive or equivalent RFP platform certification or advanced administration experience
  • Familiarity with security and compliance frameworks (ISO 27001, SOC2, NIST, etc.) to interpret control questions and coordinate accurate responses
  • Familiarity to aviation, aerospace, or defense-adjacent compliance frameworks including EASA, CASA, or CMMC.

Responsibilities

  • Serve as the single named point of contact for all inbound customer security questionnaires, assessment requests, customer audits, and agency-specific security inquiries routed to the Security Team
  • Establish and own a structured intake, tracking, and response process for all customer-facing security requests to ensure consistent turnaround timeframes, clear ownership, and a single escalation path to support Sales.
  • Lead completion of standard and custom security questionnaires including HECVAT, SIG, CAIQ, and customer-specific DDQs with appropriate SME input, owning each request through to delivery
  • Own the security Q&A content within the organization's enterprise questionnaire management platform to ensure responses remain accurate and aligned with current security posture
  • Manage Trust Center operational updates to reflect current certifications, policies, and security posture; handle customer requests for security documentation through appropriate NDA-gated channels
  • Partner with the Proposals Team to embed security intake steps within existing proposal workflows, ensuring a seamless and consistent experience for Sales and customers
  • Produce quarterly metrics on inquiry volume, response time, content reuse rates, and document review completion status for GRC leadership review
  • Communicate effectively across Sales, Proposals, Engineering, Legal, and Product Security; represent GRC in cross-functional meetings and serve as an informal mentor to colleagues navigating customer security requests
  • Coordinate with control owners and GRC team members to ensure policy documentation, procedures, and framework evidence remain current between audit cycles

Benefits

  • Medical, dental, vision insurance with Employer paid health premiums
  • Open PTO Policy
  • 401(k) with up to 10% company matching and immediate vesting
  • 12 Weeks Paid Paternal Leave
  • Flight Training Rewards
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service