Skip to content

Open nowPosted yesterday

Information Security and GRC Manager — Scribe

First Round portfolio570 open roles

Pay
$144,500 – $220,000 a year
Where
San Francisco, California, United States; San Francisco; United States
Work mode
Hybrid
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowInformation Security and GRC Manager — ScribeFirst Round portfolio · San Francisco, California, United States; San Francisco; United States
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on First Round portfolio's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.3% of postings close within 7 days. Measured by our own scanner across the market. First Round portfolio postings stay open a median of 36 days.

Share of postings closed within
  1. 1.9%1 day
  2. 4.0%3 days
  3. 8.3%7 days
  4. 15.3%14 days
  5. 34.2%30 days
This job: posted yesterday

First Round portfolio median: 36 days open

The posting

Howdy, I'm JJ, Scribe's Head of Legal! I spend my days making sure the promises Scribe makes to customers are ones we can keep, and I'm looking for the person who makes sure our security team keeps them too. We take the work seriously but not ourselves, and I think the best colleagues still have time for hobbies and families (and the occasional unread Slack!).

I'm invested in making sure you grow your expertise and your career with the function the whole way. Come do the best work of your career with me!

About Scribe

Scribe is where exceptional people come to do the best work of their careers. More than 94% of the Fortune 500 use Scribe to own their specialized intelligence: the unique way their teams work, decide, and get things done. Our Specialized Intelligence platform automatically captures how work happens and turns it into a living asset for people and AI agents.

We're growing fast. Since our founding in 2019, we've reached 7 million users across 600,000 businesses. Based in San Francisco, we're a LinkedIn Top Startup, valued at over $1B, and backed by leading investors. Join us in our mission to transform how people work.

✨ TL;DR - Why This Role Matters Scribe is scaling fast, and our security and compliance program needs to keep up. As Information Security & GRC Manager, you'll be the hands-on owner of day-to-day security and compliance work. That means running our SOC 2 program, handling enterprise security reviews, driving remediation with Engineering, and operating our core internal controls. If this seat is empty, audits slip, security questionnaires pile up, enterprise deals wait on answers, and compliance requirements never become real engineering work.

📌 About the Role As Information Security & GRC Manager, you'll execute and operate Scribe's security and compliance program across assurance, customer security, risk management, and internal security operations. Concretely, you'll:

  • Run our SOC 2 program end to end. This covers control ownership, evidence collection, auditor management, and closing gaps, so that our compliance reflects real security practice rather than paperwork. You'll also support additional frameworks as customer demand requires.
  • Own customer security reviews. You'll complete questionnaires, maintain our trust center and security documentation, and lead security calls alongside Sales, Customer Success, and Legal.
  • Give Legal technical input on the security commitments in customer contracts (MSAs, DPAs, BAAs, AI terms), and flag non-standard requests for a decision.
  • Maintain the risk register, security policies, and vendor security review process. When you see risks, bring them to leadership with clear recommendations, and say what needs fixing now and what can reasonably wait.
  • Turn audit findings, control requirements, and security issues into concrete engineering work, and track that work to completion.
  • Operate and scale core internal security programs: access reviews, security awareness training, endpoint and device management, vulnerability management, and incident response readiness.

🧩 What Makes You a Great Fit

  • 6+ years of experience in information security, GRC, or security compliance at a SaaS or technology company with 2+ years managing individual contributors.
  • Hands-on experience running SOC 2 Type II audits, as the person who actually did the work rather than an occasional contributor.
  • Experience handling enterprise customer security reviews and questionnaires alongside Sales, Customer Success, and Legal.
  • Enough working knowledge of cloud security, identity and access management, endpoint security, and vulnerability management to engage credibly with engineers and push remediation forward.
  • Familiarity with GRC automation platforms (e.g., Vanta, Drata, Secureframe).
  • Sound judgment about risk: you can tell what needs immediate attention from what can wait, and you escalate the right things.
  • Strong organization and follow-through, and comfort working without a large team around you.
  • Experience with information security and privacy frameworks like ISO 27001, HIPAA, FERPA, public-sector requirements, and AI governance frameworks (e.g., EU AI Act, ISO 42001).
  • CISSP, CISM, or CISA certification preferred.

If you're reading this thinking "that's me!", we want to meet you!

🚫 This Role Is Not for You If

  • You don't have experience scaling or executing on a security team at a global SaaS or technology company.
  • You haven't personally engaged in commercial/GTM negotiations and other processes, or run audits, answered security questionnaires, or driven remediation work.
  • You treat every finding as requiring maximum mitigation regardless of business context.
  • You need a fully defined playbook. The program is still maturing, and you'll help build the processes you run.

Why you'll love working here

  • The reach of a unicorn, the headcount of a startup. We went from $1M to $100M ARR in under four years, with fewer than 200 people. That means more pie than people: scope grows with your impact. Customers like T-Mobile, LinkedIn, HubSpot, New York Life and Northern Trust run on Scribe, so what you own reaches some of the biggest names in business.
  • Hard problems, real impact. Capturing how work actually gets done, at scale, is the foundation AI needs, and it's hard to get right. You'll build the layer other products and agents run on, in a category we're still defining.
  • Smart is the floor. Kind is the bar. Low ego, high standards. We compete as a collective and love to see each other win, and One Team, One Dream is one of the most shouted-out values in #values.

Compensation & Location

Salary and office requirements vary by location. All full-time employees receive equity in Scribe. Final offers depend on experience and scope.

Hybrid, based in San Francisco. We work from the office 3 days per week, with Mondays and Wednesdays being anchor days.

Benefits

  • Healthcare Coverage – Comprehensive health, dental, and vision plans, including two $0/month medical plan options for employees
  • Equity – Ownership in what we're building
  • 401(k) Plan – through Vestwell
  • Flex Benefit – $500/year for home office equipment, productivity tools, learning & development or fitness/wellness
  • Commuter Benefits – $100/month for SF based employees
  • PTO – Flexible paid time off and company holidays
  • Parental Leave – Paid leave to support growing families
  • Wellness & Family Support – Free Talkspace membership, One Medical access (location-dependent), and Kindbody discounts for family planning

At Scribe, we celebrate our differences and are committed to creating a workplace where all employees feel supported and empowered to do their best work. Scribe is proud to be an Equal Opportunity Employer.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against First Round portfolio's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on First Round portfolio's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    First Round portfolio's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.