This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Everlaw is seeking a pragmatic and execution-oriented Director of GRCT to lead our Governance, Risk, Compliance, and Trust function. This role is responsible for setting the "North Star" for how we manage risk, earn customer trust, and scale compliance programs in a way that enables—rather than slows—business innovation. Reporting to the VP of Information Technology & Security, you will own the day-to-day execution and continuous evolution of Everlaw’s risk, compliance, and trust programs, ensuring our governance posture scales with the business. This role sits at the intersection of technical rigor and commercial enablement, partnering closely with DevOps, Product Security, Corporate Security, Legal, Engineering, Sales, and Customer teams to translate complex requirements into clear controls and credible assurances that build customer confidence.
Job Responsibility:
Public Sector Compliance Ownership: Own Everlaw’s public sector compliance posture, including FedRAMP and GovRAMP authorization and ongoing maintenance
Regulatory & Contractual Requirements: Ensure compliance with specialized regulatory and contractual requirements (e.g., CJIS, FTI)
Global & Industry Certifications: Accountable for global and industry certifications, including SOC 2, ISO 27001/27017/27018, UK CE+, GDPR, and HIPAA
Audit Readiness & Execution: Ensure sustained audit readiness through clear control ownership, effective evidence management, and scalable compliance processes
Strategic Certifications & Market Access: Own the go/no-go framework for pursuing new certifications or regulatory authorizations (e.g., ISO 42001)
Regulatory Awareness: Continuously monitor emerging regulatory and industry requirements and advise leadership on impact, readiness, and timing
Security Risk Identification & Management: Oversee the identification, assessment, and tracking of information security risks
Security Impact Analysis (SIA): Partner with Security Engineering to lead the SIA process for major system, infrastructure, and product changes
Third-Party Security Risk: Oversee the vendor security risk lifecycle, from onboarding through ongoing monitoring and renewal
Emerging Technology & Risk Visibility: Govern security risks related to emerging technologies, including AI/ML
Customer Trust Ownership: Own Everlaw’s customer-facing trust posture
Trust Center & Artifacts: Set direction and provide oversight for Everlaw’s Trust Center and related trust artifacts
Customer Assurance Model: Partner with Sales, Customer Success, and Legal to support customer security questions, reviews, and audits
Strategic Engagement: Act as a subject matter expert in executive-level customer conversations on trust and security compliance topics
Feedback Loop: Ensure customer trust insights and recurring assurance themes inform risk governance and compliance priorities
Program Operations & Scalability: Drive operational excellence across GRCT programs by improving core processes, reducing manual effort, and ensuring programs scale efficiently
Systems, Automation & Tooling: Own the evolution of the GRCT tech stack
Metrics & Execution Rigor: Establish clear program metrics and operating rhythms to track effectiveness, surface bottlenecks, and drive predictable execution
People & Team Leadership: Lead, coach, and develop GRCT team members
Continuous Improvement & Resourcing: Champion continuous improvement by incorporating lessons learned from audits and customer feedback into program enhancements
Requirements:
10+ years of experience in Information Security, Risk, or Compliance
Senior ownership of FedRAMP Moderate/High programs from authorization through steady-state operations
Hands-on experience implementing modern GRC automation platforms
Experience driving a shift from manual compliance processes toward Continuous Control Monitoring
Strong risk judgment, evaluating control gaps, exception requests, and architectural trade-offs pragmatically
Technical literacy to lead Security Impact Analyses (SIA) and embed compliance into DevOps and CI/CD workflows
Experience supporting customer assurance and GTM efforts—from complex security questionnaires to executive-level conversations
Operational and people leadership skills, skilled at establishing operating rhythms, defining meaningful program metrics, driving predictable execution, and coaching high-ownership teams
Clear and credible communicator, able to distill complex technical and regulatory topics
Bachelor’s degree in Information Security, Computer Science, Engineering, Information Systems, or a related field (or equivalent practical experience)
Possess relevant security certifications such as CISM, CISSP, or CISA
What we offer:
Equity program
401(k) retirement plan with company matching
Health, dental, and vision
Flexible Spending Accounts for health and dependent care expenses
Paid parental leave and approximately 10 days (80 hours) per year of sick leave
Seventeen paid vacation days plus 11 federal holidays
Membership to Modern Health to help employees prioritize mental health and wellness
Annual allocation for Learning & Development opportunities and applicable professional membership dues
Company-sponsored life and disability insurance
Work in Uptown Oakland, just steps from the BART line and dozens of restaurants and walking distance to Lake Merritt
Flexible work-from-home days on Tuesdays and Fridays
Monthly home internet reimbursement
Select your preference of hardware (Mac or PC) and customize your desk setup
Enjoy a wide variety of snacks and beverages in the office
Bond over company-wide out-of-the-box events and fun activities with your team
Time off for company-sponsored volunteer events and 4 paid hours per quarter to volunteer at a charitable organization of your choice
Take advantage of learning and career development opportunities