<?xml version="1.0" encoding="UTF-8"?>
<source>
  <jobs>
    <job>
      <externalid>e2099e08-e30</externalid>
      <Title>GRC Lead (Governance, Risk, and Compliance)</Title>
      <Description><![CDATA[<p>We are looking for a GRC Lead to serve as the Technical Lead for our compliance and risk management ecosystem. You will architect the systems and processes that automate trust, guiding a team of GRC specialists while partnering deeply across the organization.</p>
<p>The role requires a pragmatic operator who understands that GRC exists to enable the business,balancing rigorous standards with the velocity of a high-growth startup.</p>
<p>Key responsibilities include:</p>
<ul>
<li>Technical Leadership &amp; Mentorship:</li>
<li>Act as the technical anchor for the GRC team.</li>
<li>Mentor GRC analysts and engineers, setting the standard for quality, technical depth, and operational efficiency.</li>
<li>Own the technical vision for Replit&#39;s GRC program, moving the team from manual workflows toward &#39;Compliance-as-Code&#39; and automated evidence collection.</li>
<li>Cross-Functional Collaboration:</li>
<li>Partner with Architects and Engineering Leads to &#39;bake in&#39; compliance requirements early in the design phase.</li>
<li>Work closely with Legal Counsel to interpret and implement requirements for Privacy (GDPR, CCPA) and emerging AI-specific regulations (e.g., EU AI Act).</li>
<li>Enable the Sales team by managing the Customer Trust Center and handling complex security questionnaires.</li>
<li>Risk Management &amp; Strategic Compliance:</li>
<li>Own the Cybersecurity Risk Register.</li>
<li>Identify, quantify, and track risks, distinguishing between theoretical compliance gaps and meaningful business risks.</li>
<li>Manage and evolve our compliance posture across SOC 2, ISO 27001, and prepare the organization for future certifications in regulated markets (e.g., FedRAMP, ITAR, PCI, HIPAA).</li>
<li>Automation &amp; Efficiency:</li>
<li>Drive the shift from manual evidence collection to continuous monitoring.</li>
<li>Identify opportunities to automate audit work, ensuring GRC scales with the business.</li>
<li>Architect a scalable framework for assessing third-party vendors and AI model providers, ensuring our supply chain remains secure without creating administrative bottlenecks.</li>
</ul>
<p>The ideal candidate will have:</p>
<ul>
<li>8+ years of experience in GRC or Information Security.</li>
<li>Leadership experience, proven by mentoring other GRC professionals or leading complex cross-functional projects.</li>
<li>Technical fluency, speaking the language of engineering, cloud (GCP/AWS), and security architecture.</li>
<li>Regulatory breadth, with deep experience with SOC 2, ISO 27001, PCI, HIPAA, and Privacy laws.</li>
<li>Collaborative communication skills, explaining risk and tradeoffs to technical, legal, and commercial stakeholders.</li>
<li>An automation mindset, with experience with GRC automation tools (e.g., Vanta, Drata) and a bias toward reducing manual toil.</li>
</ul>
<p>Bonus qualifications include familiarity with FedRAMP, ITAR, or AI regulation.</p>
<p>We value pragmatism, business enablement, solutions-oriented leadership, and clarity. This is a full-time role that can be held from our Foster City, CA office, with an in-office requirement of Monday, Wednesday, and Friday.</p>
<p>Full-time employee benefits include competitive salary and equity, 401(k) program with a 4% match, health, dental, vision, and life insurance, short-term and long-term disability, paid parental, medical, caregiver leave, commuter benefits, monthly wellness stipend, autonomous work environment, in-office set-up reimbursement, flexible time off (FTO) + holidays, quarterly team gatherings, and in-office amenities.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>Full time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange>$208K - $300K</Salaryrange>
      <Skills>GRC, Information Security, Engineering, Cloud (GCP/AWS), Security Architecture, SOC 2, ISO 27001, PCI, HIPAA, Privacy Laws, GRC Automation Tools (e.g., Vanta, Drata)</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Replit</Employername>
      <Employerlogo>https://logos.yubhub.co/replit.com.png</Employerlogo>
      <Employerdescription>Replit is an agentic software creation platform that enables anyone to build applications using natural language. It has millions of users worldwide.</Employerdescription>
      <Employerwebsite>https://replit.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://jobs.ashbyhq.com/replit/3475841f-c994-4443-b83d-4b8a5b1dd8f2?utm_source=yubhub.co&amp;utm_medium=jobs_feed&amp;utm_campaign=apply</Applyto>
      <Location>Foster City, CA (Hybrid) In office M,W,F</Location>
      <Country></Country>
      <Postedate>2026-04-24</Postedate>
    </job>
  </jobs>
</source>