# GRC & Privacy Lead at Polymarket

- Company: Polymarket
- What the company does: Polymarket is the world’s largest prediction market, allowing you to stay informed and profit from your knowledge by trading on future events across various topics. Backed by General Catalyst and Founders Fund.
- Company website: https://polymarket.com/
- Type: Startups
- Level: Senior
- Location: New York
- Work setup: On-site
- Pay: $150K to $200K base salary per year (USD)
- Posted: 2026-09-16
- Apply by: 2026-10-31
- Apply: https://jobs.ashbyhq.com/polymarket/b77585e9-83fb-4538-8e51-dc3cba1e8d36
- Page: https://www.1752.vc/careers/jobs/polymarket-grc-and-privacy-lead/

## About the role

Polymarket's IT and Security team is small, senior, and expected to move fast. This role sits at the intersection of third-party risk, audit execution, and privacy operations — and the person in it will own all three. DSARs need to be processed, vendors need risk dispositions before they get access to our systems, and PIAs need to happen before engineering ships, not after.

## What they're looking for

- Hands-on SOC 2 Type II audit experience — you have personally gathered evidence, coordinated with control owners, and managed auditor requests through a full engagement cycle
- Demonstrated experience conducting third-party vendor risk assessments, including reading and interpreting SOC 2 reports, PCI AOCs, and pen test summaries, and writing risk memos with clear dispositions
- Working knowledge of GDPR, CCPA/CPRA, BIPA, and CUBI, and the ability to translate those obligations into concrete process steps that product and engineering teams can follow
- Experience building compliance or privacy processes from scratch, not just inheriting and maintaining them
- Comfort operating independently, triaging ambiguous situations, and making defensible decisions without waiting for escalation on routine assessments
- (Plus) Experience with PCI DSS scoping or self-assessment activities

Tags: IT
