RefolkCandidates
Open nowLegalEngineering

Head of GRC (Governance, Risk, & Compliance)

Blitzy · Cambridge, Massachusetts

Location
Cambridge, Massachusetts, United States
Employment
Full time
Level
Manager
Posted
2 months ago

About this role

About Blitzy

Blitzy is a Cambridge, MA based AI software development platform on a mission to revolutionize the software development life cycle by autonomously building custom software to unlock the next industrial revolution. We're transforming how enterprises build software, turning enterprise requirements into production-ready code with an agentic software development platform that can autonomously execute 80% of the quantum of software development work. We're backed by multiple tier 1 investors, and have proven success as founders of previous start-ups.

Location: 1 Kendall Square, Cambridge, MA (On-site)

Compensation: $220,000 - $260,000 plus bonus and equity, commensurate with experience

The Role

Security and compliance at Blitzy currently run on a patchwork: a Security Delegate managing our frameworks with help from an external compliance vendor, backend engineers pulled off their real jobs to answer security questions, and audit evidence assembled after the fact instead of built in from the start.

We're hiring one person to fix that. As Head of GRC, you'll own a compliance program that's audit-ready by design, not by scramble.

To be clear about scope, this role is not:

  • A paperwork-only compliance role with no rigor.

  • A job where you escalate every auditor question to engineering or to the Security Delegate.

  • A way to move our current reactive compliance model in-house unchanged - the point is to make it proactive.

What Success Looks Like

  • You spot the gap - like SSO being “available” but not “enforced” - before an auditor finds it, not after.

  • You've personally run a SOC 2 Type II or ISO 27001:2022 cycle and know exactly what auditors sample.

  • You own Vanta (or an equivalent GRC platform) as the single source of truth, not a reference tool.

  • You manage auditors and compliance partners directly, without needing anyone to run interference for you.

  • Engineers stop getting pulled into compliance busywork because you've taken security scope questions and screenshot requests off their plate.

  • You write clearly - policies, audit narratives, and questionnaire responses that hold up under scrutiny.

Areas of Ownership

Proactive Compliance & GRC Ownership

  • Own Vanta (or equivalent) as the system of record - configuring tests and keeping evidence current, not just checking a dashboard.

  • Run SOC 2 Type II and ISO 27001:2022 compliance building continuously toward what auditors actually sample, rather than scrambling before the audit window opens.

  • Manage auditor and partner relationships directly, including firms like Insight Assurance and FedRAMP platform partners such as Second Front Systems/Game Warden - without routing every conversation through the Security Delegate.

  • Build the compliance processes that don't exist yet, starting with a formal sub-processor change communication process, which is already coming up as a contractual requirement in enterprise deals.

  • Evaluate evidence critically rather than take it at face value, confirming, for example, that SSO is enforced via admin panel configuration - not just available in a settings screen.

Required Experience

  • Personal, hands-on ownership of at least one full SOC 2 Type II or ISO 27001:2022 audit cycle - not just adjacent to one.

  • Direct experience running a GRC/compliance platform (Vanta or equivalent) as the system-of-record owner.

  • A track record of managing vendor and auditor relationships independently, without hand-holding.

  • The seniority and judgment to reduce engineering interrupt load, not add to it - engineers should be comfortable handing things off to you, not double-checking your work.

What Makes You Stand Out

  • FedRAMP exposure, even at Moderate - we're targeting FedRAMP High.

  • A track record of building a compliance process from scratch, not just running an existing playbook.

  • Experience managing multiple frameworks concurrently - SOC 2, ISO 27001, and GDPR at the same time.

  • Familiarity with Google Workspace as an identity provider.

  • GDPR/data privacy program experience - cookie consent, Article 27 representative coordination, DPA review.

What Makes This Role Different

You'll have direct ownership of a function that's currently split across engineering, a Security Delegate, and an external vendor - with full autonomy to build it right from day one. That includes a seat at the table on FedRAMP, one of the most demanding compliance programs a company can pursue.

Our interview process reflects the role itself: an audit walkthrough round where you'll talk through a real SOC 2 or ISO 27001 cycle you've run and how you handled your findings.

Our Culture

Who we are:

Led by two pioneering co-founders we are one of the fastest growing companies in the U.S., creating our own category of enterprise autonomous software development. We automate thousands of hours of software development for our customers, which includes strong representation within the Fortune 500.

How we work:

We move Blitzy Fast: Time is both our company's and our clients' most precious asset. We move quickly and decisively to innovate internally and deliver exceptional software externally.

Championship Mindset: We operate like a professional sports team. We win as a team by holding ourselves and each other to high standards, collaborating in-person, and remaining focused on the mission.

Passion for Invention: We're pushing the frontier of what's possible, requiring constant innovation and iteration.

We Work for the Customer: We focus on delivering outsized value to the customers we work with and expanding those relationships into deep, meaningful partnerships.

We believe in being 'everyday athletes' - taking care of ourselves so we can bring our best minds to work. We promote great sleep, movement, and restorative activities for optimal mental performance. It makes for a happier and more productive team.

Blitzy is an equal opportunity employer committed to building a diverse and inclusive team. We believe different perspectives make us stronger.

As published by Blitzy. Applications are handled on their site.

Skills this posting mentions

GRCArtificial IntelligenceCompliance

About Blitzy

Meet Blitzy, the only autonomous code generation platform with infinite code context, purpose built for large, complex enterprise-scale codebases. While other AI coding tools provide snippets of code and struggle with context, Blitzy ingests millions of lines of code and orchestrates thousands of agents that reason for hours to map every line-level dependency. With a complete contextual understanding of your codebase, Blitzy is ready to be deployed at the beginning of every sprint, creating a bespoke agent plan, then autonomously generating enterprise-grade, premium quality code, grounded in a deep understanding of your existing codebase, services, and standards. Blitzy’s orchestration layer of cooperative agents thinks for hours to days, autonomously planning, building, improving, and validating code. It executes spec and test driven development, done at the speed of compute. The platform completes more than 80% of the work autonomously, typically weeks to months of work, while providing a clear action plan for the remaining human development. Used for both large scale feature additions and modernization work, Blitzy is the secret weapon for Fortune 500 companies globally, unlocking 5x engineering velocity and delivering months of engineering work in a matter of days. Blitzy was co-founded by Brian Elliott, a serial entrepreneur, and Sid Pardeshi, an ex-NVIDIA software architect with 27 Generative AI patents to his name.

All 45 openings at Blitzy

One click, then it is written

Apply to Blitzy with a resume written for this role.

Queue Head of GRC (Governance, Risk, & Compliance) and I read the posting, rewrite your resume against it, draft the cover letter, and score the fit. Then you press send, or press one button and I fill in Blitzy’s form for you.

  1. 01Drop your resume

    A PDF or a LinkedIn URL. About a minute, once.

  2. 02I rank the openings

    Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.

  3. 03Each one is written up

    Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.

  • 25 sent a week, free
  • No card
  • Nothing sent until you say so

More roles at Blitzy

See all

Similar roles elsewhere

See more
  • Contracts Manager

    BlitzyCambridge, Massachusetts

    $80k - $130k/yrManagerLegal
    2 months ago
  • General Counsel

    TetraScienceCambridge, Massachusetts

    $280k - $400k/yrSeniorLegal
    5 months ago

Put this to work

Paste your career in once. Every application after that is written for you.

Drop a resume or a LinkedIn URL. I rank the live openings against it, rewrite the resume and write a cover letter for the best of them, and fill in the employer's form when you press the button. You read, you decide what goes out.

  1. 01Drop your resume

    A PDF or a LinkedIn URL. About a minute, once.

  2. 02I rank the openings

    Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.

  3. 03Each one is written up

    Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.

  • New matches ranked and written before you are up.
  • Every bullet stays inside what your history supports. Nothing invented.
  • Queued, submitted, interviewing, offer: one screen, not a spreadsheet.

500 free credits on sign-up. No card. Nothing is sent until you say so.

Listed from the job board Blitzy publishes. Refolk is not the employer and does not handle their hiring. Applications go to Blitzy directly.