Startups

Director - Governance, Risk, Compliance & Privacy (GRC)

Beacon · San Francisco, CA · Remote

← All jobs
About Beacon

Beacon acquires and grows essential businesses. With our centralized platform, we empower founders with the technology and expertise to better serve their customers. Backed by General Catalyst.

About the role

Our GRC function is at an early, formative stage. You would shape it from the foundations and scale it across the portfolio, working directly with our portfolio companies to take them through their own audits and certifications, and designing a program that grows with the business rather than one built for a single audit. The mandate spans security compliance, data privacy, risk, and AI governance. We expect it to be built AI-first: modern automation platforms and LLM-assisted workflows over manual process.

What they're looking for

  • You have built or substantially matured a GRC program before and taken an organization through SOC 2 Type 2. Typically several years (5+) in GRC, IT governance, or security compliance, though what you have built matters more to us than the count
  • A builder with a bias for action. When you see a manual process, your first instinct is how to automate it
  • A strong systems thinker. You design scalable GRC architectures, not one-off fixes for the next audit
  • Fluent with a compliance automation platform (Vanta, Drata, Secureframe, or similar) and current on AI tooling in practice, not just in theory
  • Comfortable across both security compliance and data privacy, or able to ramp quickly on regimes you have not personally run
  • An excellent cross-functional communicator who works through influence and can translate compliance requirements into terms both technical and non-technical teams can act on
More about this role

Beacon is acquiring and operating a portfolio of vertical SaaS companies. Most private equity firms scale by adding people. We are building Beacon to scale by adding software. The thesis is simple: portfolio operations, value creation, and deal sourcing are bottlenecked by human attention, and an agentic operating system can lift that ceiling by an order of magnitude.

We are looking for a GRC leader to build and scale the governance, risk, compliance, and privacy function for a growing portfolio of software companies. This is a founding, high-ownership role for someone who has built before and treats automation and modern AI tooling as the default way to operate.

Beacon has raised $550M+ from investors including General Catalyst, Lightspeed, D1 Capital, CPMG, and the family offices of the founders of Stripe, DoorDash, and Ramp.

Our GRC function is at an early, formative stage. You would shape it from the foundations and scale it across the portfolio, working directly with our portfolio companies to take them through their own audits and certifications, and designing a program that grows with the business rather than one built for a single audit. The mandate spans security...

Read the full posting on Beacon's site ↗

GRC / IT / Security

Build your edge while you search

Free tools for founders and investors, plus VC Unfiltered, our take on startups, venture and the people who build them.