Responsibilities
- Design and implement Gong’s Common Controls Framework, mapping controls across SOC 2, ISO 27001, 27017, 27701, 27018, HIPAA, PCI, and other applicable frameworks.
- Rationalize overlapping requirements across frameworks to reduce compliance burden and create a single source of truth for control ownership.
- Partner with Engineering, Infrastructure, and Product Security to embed controls at the architecture level, not just as audit checkboxes.
- Establish control testing methodology, evidence collection standards, and continuous control monitoring processes.
- Serve as the subject-matter expert on control mapping during customer and external audits, RFPs, and enterprise sales engagements.
- Build Gong’s product & enterprise risk register from the ground up — defining risk taxonomy, scoring methodology, risk appetite thresholds, and ownership models.
- Implementation of a GRC platform and system of record, and ability to build executive level dashboards to track vulnerability, risk, and control remediation.
- Create and maintain risk treatment plans in partnership with risk owners across the business, tracking remediation milestones and escalating blockers.
- Develop executive-level risk reporting cadences and dashboards for the Head of GRC and senior leadership.
- Own the complete lifecycle of Gong’s information security policy suite — creation, review cycles, version control, and employee acknowledgment tracking.
- Establish and operate a formal exceptions management program, including intake, risk assessment, approval workflows, compensating controls, and periodic review.
- Ensure policies remain aligned with evolving regulatory requirements, industry frameworks, and Gong’s rapidly changing technology environment.
- Drive policy adoption through clear communication, training support, and cross-functional partnership.
- Liaise with external auditors and certification bodies for SOC 2, ISO, and other certifications
Requirements
- 7+ years of progressive experience in GRC, Information Security, or a closely related function — with meaningful time spent building or scaling programs, not just running them.
- Demonstrated hands-on experience building a GRC program at scale — ideally in a high-growth SaaS or technology company.
- Deep expertise across multiple compliance and security frameworks, including SOC 2 Type II, ISO 27001, NIST CSF, and at least one regulatory framework (GDPR, CCPA, HIPAA, or equivalent).
- Experience creating and implementing GRC Record of Truth/Tooling.
- Strong policy and standards writing ability — capable of translating complex regulatory language into clear, actionable documentation.
- Experience conducting and managing product & enterprise risk assessments, with a working knowledge of risk quantification methodologies.
- Proven ability to manage and communicate with senior stakeholders, including Legal, Engineering, and executive audiences.
- Bachelor’s degree in Information Security, Computer Science, Business, or a related field; equivalent practical experience considered.
Nice to Have
- Relevant certifications strongly preferred: CISSP, CISM, CRISC, CISA, CCSP, or comparable credentials.
Benefits
- We offer Gongsters a variety of medical, dental, and vision plans, designed to fit you and your family’s needs.
- Wellbeing Fund - flexible wellness stipend to support a healthy lifestyle.
- Mental Health benefits with covered therapy and coaching.
- 401(k) program to help you invest in your future.
- Education & learning stipend for personal growth and development.
- Flexible vacation time to promote a healthy work-life blend.
- Paid parental leave to support you and your family.
- Company-wide recharge days each quarter.
- Work from home stipend to help you succeed in a remote environment.