About the job
Hex Technologies is hiring a Security GRC Manager to build and lead our security and privacy compliance programs. This position shapes the framework that keeps Hex aligned with regulatory, customer, and industry standards. The scope includes SOC 2, ISO 27001, ISO 27701, HIPAA, GDPR, CCPA, PCI DSS, and other evolving compliance needs important to our clients.
What You Will Do
- Design, implement, and scale security and privacy compliance systems from the ground up as Hex’s first GRC hire
- Develop processes and foster a culture that prioritizes integrity, customer trust, and ongoing audit readiness
- Work closely with engineering, business operations, and go-to-market teams to embed GRC best practices throughout the company
- Use automation and proactive risk management to streamline compliance efforts
- Communicate transparently about security and compliance with both internal teams and external stakeholders
- Balance strategic planning (long-term program roadmaps) with hands-on tasks, such as leading audits, conducting risk assessments, and responding to customer security questions
- Translate technical product knowledge into clear compliance documentation and trust-building materials for clients
Location
This role can be based in San Francisco, New York City, or remote within the United States.

