bluedoor data·Job Postings API·bluedoor.sh ↗

HomeCompaniesCloudZeroGRC Manager

GRC Manager

CloudZero · Boston, Boston, Massachusetts · Hybrid · Deleted · Ashby

Job facts

FieldValue
CompanyCloudZero
TitleGRC Manager
Normalized title-
Department / teamOffice of CTO / Office of CTO, Information Technology (IT)
LocationSan Francisco, CA, United States
Work modelHybrid / Hybrid
Employment typeFull Time
Salary-
Statusdeleted
ATS providerAshby
Posted / first seen / 2026-05-29
Changed / last seen2026-06-11 / 2026-06-09

Related slices

PageWhat it containsOpen
Company jobsActive postings from CloudZero.Open
Company breakdownsRole, location, ATS, and work model facets for this company.Open
ATS provider jobsActive postings observed through Ashby.Open
Provider filtered searchThe same provider as a filtered job collection.Open
City jobsActive postings in San Francisco.Open
Department jobsActive postings in Office of CTO.Open
Work model jobsActive Hybrid postings.Open
Lifecycle eventsOpen, update, close, and reopen events for this posting.Open
Original postingCanonical source or apply URL captured from the ATS.Open

Linked records

CompanyCloudZero
Source7e09d45b-8f74-487a-8189-b686758f67c8
ATS providerAshby

Description

About the Role CloudZero is growing fast. Our customer base is expanding, the regulatory and risk landscape is getting more complex, and the business needs a GRC function that can keep pace. As the GRC Manager at CloudZero, you’ll own and scale our governance, risk, and compliance programs across the organization. Reporting to the Sr. Director of IT & Security within the Office of the CTO organization, you’ll partner closely with Legal, Engineering, Product, Sales, and G&A to build a GRC function that protects CloudZero’s interests, earns customer trust, and gives the business the confidence to move quickly. This is a high-impact, highly cross-functional role. You’ll be as comfortable presenting a risk register to leadership as you are helping a sales team close a deal with the right compliance documentation. This is a hybrid role with an expectation of in-office presence 2–3 days per week. What You’ll Do Design and Operate the GRC Framework Design and operate a comprehensive GRC framework spanning governance structures, enterprise risk management, and compliance programs that grows alongside CloudZero’s business Own audit and certification programs including SOC 2 and other relevant standards, coordinating across internal teams and third-party auditors to drive successful outcomes Own the development, maintenance, and ongoing improvement of CloudZero’s security and privacy policies and procedures, ensuring they’re current, practical, and embedded into how teams actually operate Lead regular enterprise risk assessments, maintain a living risk register, and create an environment where risk-informed decision-making happens at every level of the organization Governance, Risk & Business Continuity Serve as a key stakeholder in building CloudZero’s AI Governance & Strategic Risk strategy Take full ownership of business continuity and disaster recovery programs, including program design, documentation, regular testing cycles, and tabletop exercises — ensuring operational preparedness when it matters most Build and manage third-party risk management processes, including vendor due diligence, contract reviews, and ongoing monitoring throughout the vendor lifecycle Track regulatory developments alongside the Legal team, ensuring CloudZero meets its obligations under GDPR, CCPA, and other applicable requirements Manage the company’s security awareness training program and run internal audits to validate that controls are working as intended Sales and Revenue Enablement Own the security questionnaire and assessment process — including VSAs, SIGs, and custom customer requests — with a primary focus on building and scaling tooling and automation that makes high-quality responses fast and repeatable Review and redline security and data privacy language in customer and prospect contracts, working closely with Legal to protect CloudZero’s interests while keeping deals on track Build and maintain a library of pre-approved security responses, compliance artifacts, and contract language so the team isn’t starting from scratch on every deal Actively identify and implement tooling to automate questionnaire responses and security review workflows, reducing manual effort and accelerating deal cycles without sacrificing quality Maintain and continuously improve CloudZero’s trust center, ensuring prospective customers have ready access to up-to-date security and compliance documentation Partner with Sales Engineering and Solutions teams to address security and compliance requirements early in the sales cycle, removing friction before it becomes a blocker What You Bring Governance, Risk & Compliance 5+ years of experience in governance, risk, and/or compliance roles, ideally within a SaaS or cloud technology company Proven experience building or significantly maturing a GRC program, with direct, hands-on involvement in SOC 2 or similar certification audits Working knowledge of established risk management frameworks such as COSO, ISO 31000, or NIST RMF Solid understanding of GDPR, CCPA, and how data privacy obligations translate into practical controls and policies Communication & Leadership Strong communicator who can make risk and compliance topics accessible and actionable for technical teams, business partners, and senior leadership alike Ability to drive initiatives from scoping through completion while keeping multiple workstreams moving in a fast-paced environment A business-enabling mindset — you treat compliance as something that creates competitive advantage, not just something that checks boxes Bonus If You Have… Prior experience at a SaaS technology startup Hands-on technical experience with GCP, AWS, or Azure from a security and compliance lens Experience working with Vanta or Drata for continuous compliance monitoring and automation Experience with security questionnaire automation tools such as Loopio, Iris, or similar solutions Professional certifications such as CRISC, CISA, CISM, CISSP, or CIPP Familiarity with security frameworks including NIST CSF, CIS Controls, or OWASP Proven ability to partner cross-functionally across departments to drive compliance goals and outcomes Curiosity and enthusiasm for leveraging AI tools (such as Claude, Claude Code, or similar) to work smarter, automate repetitive tasks, and continuously find new ways to drive efficiency across the GRC function About CloudZero Cloud cost management is one of the biggest challenges organizations face today. As cloud adoption continues to accelerate, so do the complexities and costs associated with it, and macroeconomic conditions only increase pressure to prove cloud efficiency. CloudZero is a SaaS platform at the intersection of next-generation cloud cost management and FinOps. We ingest billing and usage data from all cloud, SaaS, and PaaS providers, organize it in real time according to our customers’ business structures, and empower organizations to make more informed business decisions. Since our founding in 2016, our mission has been to make efficient innovation a reality for every cloud-driven organization. We believe every engineering decision is a buying decision, and we’re applying proven reliability engineering principles to financial efficiency. We believe the best AI empowers users with clear insights and confident decisions, transforming complex cloud cost data into actionable intelligence that drives meaningful business outcomes. To date, we’ve raised over $56 million from leading venture capital firms. We’re solving problems of massive scale, business importance, and complexity in a space that needs it more than ever. Equal Opportunity Employer CloudZero is an equal opportunity employer and values diversity. We do not discriminate on the basis of race, religion, color, national origin, sex, gender, gender expression, sexual orientation, age, marital status, veteran status or disability status. All job offers are contingent upon the candidate passing background and reference checks.

Full job record

Job ID64b5c2b0cc9c4568a988b9d228379fd4406f456e
Org IDd8cf743f-9803-4774-bcda-c45a1d61f80c
Source ID7e09d45b-8f74-487a-8189-b686758f67c8
Board ID7e09d45b-8f74-487a-8189-b686758f67c8
Providerashby
Provider Job Key930e560d-279e-4ca1-959c-37f279a093c4
TitleGRC Manager
Normalized Title
Statusdeleted
Activeno
Location TextBoston, Boston, Massachusetts
DepartmentOffice of CTO
TeamOffice of CTO, Information Technology (IT)
Employment Typefull_time
Workplace Typehybrid
Remote Policyhybrid
CountryUnited States
RegionCA
CitySan Francisco
Salary Raw
Salary Min
Salary Max
Salary Currency
Salary Period
Source URLhttps://jobs.ashbyhq.com/CloudZero/930e560d-279e-4ca1-959c-37f279a093c4
Apply URLhttps://jobs.ashbyhq.com/CloudZero/930e560d-279e-4ca1-959c-37f279a093c4/application
First Seen At2026-05-29 06:44:18Z
Last Seen At2026-06-09 09:12:47Z
Last Checked At2026-06-11 09:27:54Z
Last Changed At2026-06-11 09:27:54Z
Inactive At2026-06-11 09:27:54Z
Source Posted At
Source Updated At
Raw Payload Uris3://job-postings-prod-raw-590183727216/raw/provider=ashby/board=CloudZero/date=2026-06-09/2026-06-09T09-12-34-622Z-36b5d92ce4d99951914388faa7e8890ed44bb7930a816449bbf5f574d203ab24.json
Event Fields
{
  "content_hash": "5ba3948277207d7167a24b6e9c8f703b59ac5dac480c73bf3231ccbdebcddc9b",
  "source_hash": "fc118df6a4d6eb4d8c5d4ceec954513ecd00034a7802c93c2cf34eea814b350f",
  "last_changed_at": "2026-06-11T09:27:54.405Z",
  "active_status": "deleted"
}
Parsed Structured
{
  "language": "en",
  "location": {
    "raw": "San Francisco",
    "city": "San Francisco",
    "region": "CA",
    "country": "United States",
    "is_remote": false,
    "confidence": 0.75
  },
  "salary_max": null,
  "salary_min": null,
  "inferred_at": "2026-06-09T09:12:47.162Z",
  "launch_scope": {
    "reason": "english_us_canada",
    "included": true,
    "language": "en",
    "location": {
      "raw": "San Francisco",
      "city": "San Francisco",
      "region": "CA",
      "country": "United States",
      "is_remote": false,
      "confidence": 0.75
    },
    "countries": [
      "United States"
    ]
  },
  "remote_policy": "hybrid",
  "salary_period": null,
  "workplace_type": "hybrid",
  "salary_currency": null
}
Extensions
{}
Native Structured
{
  "id": "930e560d-279e-4ca1-959c-37f279a093c4",
  "team": "Office of CTO, Information Technology (IT)",
  "title": "GRC Manager ",
  "jobUrl": "https://jobs.ashbyhq.com/CloudZero/930e560d-279e-4ca1-959c-37f279a093c4",
  "address": null,
  "applyUrl": "https://jobs.ashbyhq.com/CloudZero/930e560d-279e-4ca1-959c-37f279a093c4/application",
  "isListed": true,
  "isRemote": false,
  "location": "Boston, Boston, Massachusetts",
  "updatedAt": null,
  "apiVersion": "ashby-non-user-graphql-v1",
  "department": "Office of CTO",
  "publishedAt": null,
  "workplaceType": null,
  "employmentType": "FullTime",
  "secondaryLocations": [
    {
      "location": "San Francisco"
    }
  ]
}
Get this page with API

Rendered from the bluedoor Job Postings API. Reproduce it:

GET https://api.bluedoor.sh/job-postings/v1/jobs/64b5c2b0cc9c4568a988b9d228379fd4406f456e?include=descriptionJSON
GET https://api.bluedoor.sh/job-postings/v1/orgs/d8cf743f-9803-4774-bcda-c45a1d61f80cJSON
GET https://api.bluedoor.sh/job-postings/v1/sources/7e09d45b-8f74-487a-8189-b686758f67c8JSON
GET https://api.bluedoor.sh/job-postings/v1/jobs/64b5c2b0cc9c4568a988b9d228379fd4406f456e/eventsJSON