Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
S

Information Security and GRC Manager

Scribe

. Run Scribe's SOC 2 program end to end, including control ownership, evidence collection, auditor management, and gap closure .

Posted 10/9/2026full-timeSan Francisco • California • United StatesMid-LevelSenior💰 $170,000 - $220,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in managing SOC 2 programs, including control ownership, evidence collection, and auditor management, while effectively leading security initiatives across Sales, Customer Success, and Legal teams. Proficient in translating audit findings into actionable engineering tasks and maintaining compliance with various security frameworks.

Highest-signal resume keywords
SOC 2 Type II AuditsInformation Security ManagementGRC Automation PlatformsCISSP CertificationCloud Security

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Information SecuritySecurity ComplianceRisk ManagementVulnerability ManagementIdentity And Access ManagementEndpoint SecuritySecurity PoliciesSecurity DocumentationAudit ManagementControl Requirements
Soft Skills
Strong OrganizationFollow-ThroughSound Risk Judgment
Tools & Technologies
VantaDrataSecureframe
Certifications & Qualifications
CISSPCISMCISA
Industry Keywords
ISO 27001HIPAAFERPAEU AI ActISO 42001

Tech Stack

Tools & technologies
Cloud

About the role

Key responsibilities & impact
  • Run Scribe's SOC 2 program end to end, including control ownership, evidence collection, auditor management, and gap closure
  • Support additional security and compliance frameworks as customer demand requires
  • Own enterprise customer security reviews and questionnaires
  • Maintain the trust center and security documentation
  • Lead security calls with Sales, Customer Success, and Legal
  • Provide Legal with technical input on security commitments in MSAs, DPAs, BAAs, and AI terms
  • Flag non-standard security requests for decision
  • Maintain the risk register, security policies, and vendor security review process
  • Present risks and recommendations to leadership
  • Translate audit findings, control requirements, and security issues into engineering work and track remediation to completion
  • Operate internal security programs covering access reviews, security awareness training, endpoint and device management, vulnerability management, and incident response readiness
  • Help build and mature the security and compliance program

Requirements

What you’ll need
  • 6+ years of experience in information security, GRC, or security compliance at a SaaS or technology company
  • 2+ years managing individual contributors
  • Hands-on experience running SOC 2 Type II audits
  • Experience handling enterprise customer security reviews and questionnaires alongside Sales, Customer Success, and Legal
  • Working knowledge of cloud security, identity and access management, endpoint security, and vulnerability management
  • Familiarity with GRC automation platforms such as Vanta, Drata, or Secureframe
  • Sound risk judgment and ability to prioritize remediation
  • Strong organization and follow-through
  • Experience with information security and privacy frameworks including ISO 27001, HIPAA, FERPA, public-sector requirements, and AI governance frameworks such as the EU AI Act and ISO 42001
  • CISSP, CISM, or CISA certification preferred
  • Experience scaling or executing security programs at a global SaaS or technology company
  • Experience with commercial/GTM negotiations, audits, security questionnaires, and remediation work

Benefits

Comp & perks
  • Equity in Scribe
  • Comprehensive health, dental, and vision plans
  • Two $0/month medical plan options for employees
  • 401(k) plan through Vestwell
  • $500/year flex benefit for home office equipment, productivity tools, learning and development, or fitness/wellness
  • $100/month commuter benefits for San Francisco-based employees
  • Flexible paid time off and company holidays
  • Paid parental leave
  • Free Talkspace membership
  • One Medical access (location-dependent)
  • Kindbody discounts for family planning
  • Professional growth and career development opportunities