Director of Governance, Risk, Compliance & Trust

Everlaw
Oakland, California, United StatesPosted 5 May 2022

Job Description

<p>Everlaw is seeking a pragmatic and execution-oriented <strong>Director of GRCT</strong> to lead our Governance, Risk, Compliance, and Trust function. This role is responsible for setting the "North Star" for how we manage risk, earn customer trust, and scale compliance programs in a way that enables—rather than slows—business innovation.</p> <p>Reporting to the VP of Information Technology Security, you will own the day-to-day execution and continuous evolution of Everlaw’s risk, compliance, and trust programs, ensuring our governance posture scales with the business. This role sits at the intersection of technical rigor and commercial enablement, partnering closely with DevOps, Product Security, Corporate Security, Legal, Engineering, Sales, and Customer teams to translate complex requirements into clear controls and credible assurances that build customer confidence.</p> <h3>Getting started</h3> <ul> <li><strong>We want you to feel like part of the team early on!</strong> Our onboarding process will integrate you into the company with informative sessions on our product, policies, processes, and team structure and goals. </li> <li><strong>We’re excited for you to learn, grow, and contribute right away!</strong> We trust that you’ll bring experience and knowledge that will uplift and uplevel the team, but we don’t expect you to know everything on Day 1.</li> </ul> <h3>In your role, you'll...</h3> <p><strong>Compliance Audits</strong></p> <ul> <li><strong>Public Sector Compliance Ownership:</strong> Own Everlaw’s public sector compliance posture, including FedRAMP and GovRAMP authorization and ongoing maintenance.</li> <li><strong>Regulatory Contractual Requirements:</strong> Ensure compliance with specialized regulatory and contractual requirements (e.g., CJIS, FTI), partnering with HR, Security, and Legal to support personnel, access, and operational controls.</li> <li><strong>Global Industry Certifications:</strong> Accountable for global and industry certifications, including SOC 2, ISO 27001/27017/27018, UK CE+, GDPR, and HIPAA, enabling effective IC-led execution.</li> <li><strong>Audit Readiness Execution:</strong> Ensure sustained audit readiness through clear control ownership, effective evidence management, and scalable compliance processes.</li> <li><strong>Strategic Certifications Market Access:</strong> Own the go/no-go framework for pursuing new certifications or regulatory authorizations (e.g., ISO 42001), balancing customer demand, regulatory risk, and business priorities.</li> <li><strong>Regulatory Awareness:</strong> Continuously monitor emerging regulatory and industry requirements and advise leadership on impact, readiness, and timing.</li> </ul> <p><strong>Risk Governance Decision Enablement</strong></p> <ul> <li><strong>Security Risk Identification Management</strong>: Oversee the identification, assessment, and tracking of information security risks; partner with risk owners to remediate risks in a timely manner.</li> <li><strong>Security Impact Analysis (SIA):</strong> Partner with Security Engineering to lead the SIA process for major system, infrastructure, and product changes, where SecEng conducts technical SIA and GRCT evaluates risk, notification, and escalation requirements.</li> <li><strong>Third-Party Security Risk:</strong> Oversee the vendor security risk lifecycle, from onboarding through ongoing monitoring and renewal, ensuring risks are assessed and managed in proportion to data sensitivity and business criticality while supporting efficient procurement.</li> <li><strong>Pragmatic Governance Decision Support:</strong> Maintain security policies, standards, and exception processes aligned with how Engineering, Security and IT teams operate, and act as a trusted advisor to facilitate risk-based decisions on architectural trade-offs and control exceptions.</li> <li><strong>Emerging Technology Risk Visibility:</strong> Govern security risks related to emerging technologies, including AI/ML ... (truncated, view full listing at source)