Job Opportunities API

The Public Ledger of Openings

← Back to the ledger

Director, Trust & Assurance

Sigma Computing
CompanySigma Computing
CategorySecurity
LocationSan francisco
RemoteOn-site (inferred)
EmploymentNot stated
LevelDirector
SalaryNot stated by the employer
Posted10 Jun 2026
Last verified9 Aug 2026
SourceEmployer ATS (greenhouse)
Applications are handled by the employer, not by us.Apply on the employer's site →
Description
    Director, Trust & Assurance Reports to: General Counsel Location: San Francisco office or New York office Type: Full-time About the Role Sigma is looking for a Director of Trust & Assurance to build and run our compliance and enterprise risk function, and to lead the team behind it. You will own our GRC program end-to-end (SOC 2/ISO audits, policies, vendor risk) while positioning the team and the function to grow into an enterprise risk function as the company matures. This is a builder-and-leader role for someone who has run a similar successful program. You will take ownership of compliance, contractual, vendor, and enterprise/business risk, reporting directly to the General Counsel, with a team reporting to you. You will also work closely with Security, HR, Sales, and other members of leadership. What You'll Do Compliance & Controls Own our SOC 2 (and/or ISO 27001) program — including PCI DSS and other relevant standards as applicable — covering control implementation, evidence collection, audit management, and remediation tracking Maintain and evolve our internal policy library and employee attestation process Monitor regulatory requirements relevant to our business (data privacy, industry-specific regulations) and work with the Legal team to assess impact and translate requirements into practical controls Conduct internal audits and assessments to validate control effectiveness Manage security awareness training programs enterprise-wide Vendor & Third-Party Risk Run vendor risk assessments and maintain a vendor risk inventory, including contract reviews and ongoing monitoring Manage subprocessor tracking and disclosures Partner with Legal on risk-related contract terms for vendors Customer Trust Own the security questionnaire response process (VSAs, SIGs, and custom questionnaires) and our customer-facing trust documentation Maintain ready-to-use compliance artifacts and trust center content to support efficient deal cycles Act as a trusted resource for Sales, Sales Engineering, and Solutions teams on security-related deal questions Business Continuity & Incident Response Maintain our business continuity/disaster recovery plan, including regular testing Together with the Security team, own the incident response plan, including running periodic tabletop exercises Lead post-incident reviews and track remediation Growth into Enterprise Risk  Mature and maintain a enterprise risk register  Create risk treatment plans and track remediation activities across the organization Run quarterly risk reviews  Scan for emerging risks (regulatory, market, operational) and flag material developments to the GC  Insurance Manage the company's insurance program (cyber, E&O, D&O) including renewals and coverage review Serve as primary point of contact with brokers and carriers Team Leadership Manage and develop a team of 3+ direct reports covering compliance analysts, vendor risk, and/or a GRC coordinator Set goals, run performance reviews, and build career paths for direct reports What We're Looking For 8+ years of experience in GRC, compliance, audit, or risk management, ideally in a SaaS or technology company, including at least 2–3 years directly managing people Has personally owned a SOC 2 or ISO 27001 program through at least one full audit cycle, including managing the auditor relationship end-to-end — not just executing tasks within someone else's program Track record of building a function or program from the ground up, not just maintaining an established one Experience with vendor/third-party risk assessment processes Experience implementing risk management frameworks (COSO, ISO 31000, NIST RMF, or similar) Ability to translate technical/security concepts into risk language for executives and business language for