About the job
Sigma Computing is hiring a Governance, Risk & Compliance (GRC) Manager. This position is based in San Francisco, CA, with the option to work from our upcoming New York office. The GRC Manager reports directly to the General Counsel and will shape and expand the company's governance, risk, and compliance programs.
This role works closely with teams across Legal, Engineering, Product, Sales, Operations, and company leadership. The GRC Manager will build and refine a company-wide GRC framework to support business growth, manage risk, and ensure compliance with regulatory requirements. The work aims to strengthen governance structures, implement scalable risk management, and foster stakeholder trust.
What You Will Do
Governance
- Design and implement governance frameworks, including reporting, policy governance, and control oversight.
- Establish and maintain enterprise policies, standards, and procedures across technology, security, privacy, and operations.
- Build and lead a governance committee structure to support oversight and decision-making.
- Create dashboards and metrics to track program maturity and effectiveness.
- Work with leadership to align governance activities with business strategy and risk appetite.
Risk Management
- Develop and manage an Enterprise Risk Management (ERM) program.
- Conduct regular risk assessments across the organization and maintain a dynamic risk register.
- Establish and support business continuity and disaster recovery programs, including testing and tabletop exercises.
- Implement third-party risk management, including vendor assessments, contract reviews, and ongoing monitoring.
- Formulate risk treatment plans and oversee remediation efforts.
- Facilitate risk-informed decision-making throughout the company.
- Coordinate with leaders across functions to ensure comprehensive risk identification and management.
Compliance
- Oversee audit and certification programs, including SOC 2, ISO 27001, HIPAA, and other relevant standards.
- Develop and maintain compliance monitoring programs to track regulatory changes and ensure ongoing adherence.

