SOC 2 Type II · HITRUST i1 · PCI DSS L1 · Reports available
All roles

Governance, Risk & Compliance

Head of Governance, Risk & Compliance

  • Full-Time
  • In-Office: Downtown Los Angeles, CA
  • Governance, Risk & Compliance
  • 10+ years
  • $140,000–$180,000 + equity

Summary

Own Guava's governance, risk, and compliance program end to end: our SOC 2 Type II, HITRUST i1, and PCI DSS Level 1 certifications; the enterprise risk register; our policy and controls framework; and Guava's AI governance program. You will partner closely with engineering to design and implement controls, and with sales and product to build the guardrails that keep our customers compliant with TCPA, FCC, and GDPR obligations. You own our security questionnaires and RFIs, our annual training program, and our incident tabletop exercises, and you serve as a trusted advisor to leadership on risk and regulatory questions.

What you'll do

  • Own certifications. Own the annual compliance plan and lead the SOC 2, HITRUST, and PCI DSS programs: scoping, evidence collection, control design, and gap remediation.
  • Run audits end to end. Lead and organize audit activities (evidence collection, stakeholder interviews, and remediation follow-up) and keep audit-ready artifacts maintained across frameworks.
  • Manage control deficiencies. Analyze deficiencies from reviews and audits, communicate findings clearly, and drive diligent follow-up to resolution.
  • Own the enterprise risk register. Maintain it end to end: risk intake, triage, inherent and residual risk scoring, and risk-treatment decisions with risk owners.
  • Own the controls framework. Maintain a common, harmonized controls framework mapped across SOC 2, HITRUST, PCI DSS, and related frameworks to reduce duplicate effort and scale audit readiness.
  • Run policy governance. Own the full policy lifecycle (creation, review, approval, publication, retirement) along with documentation standards and exception governance.
  • Implement controls with engineering. Translate framework requirements into real, testable technical and operational controls embedded in the SDLC.
  • Stand up AI governance. Maintain and build out Guava's AI governance program: responsible-AI policies, model and vendor risk assessment, human-oversight controls, and alignment with emerging AI regulation and customer expectations for a voice-AI platform.
  • Own RFIs and questionnaires. Own responses to security questionnaires, RFIs, and vendor due-diligence requests, and build a reusable knowledge base and trust portal to accelerate deal cycles.
  • Build customer guardrails. Partner with sales and product to design product guardrails and customer-facing guidance that help customers stay compliant with TCPA, FCC, and GDPR.
  • Lead training and tabletops. Design and deliver annual security and compliance training, and run incident-response tabletop exercises across engineering, sales, and leadership.
  • Report to leadership. Define and maintain KPIs, KRIs, and executive-ready dashboards for control maturity, audit readiness, risk, and policy exceptions.
  • Own GRC tooling. Own the GRC and compliance-automation platform, automate evidence collection, and continuously streamline GRC operations.
  • Manage vendors and data agreements. Run vendor and subprocessor reviews and own data-processing agreements.
  • Advise and influence. Serve as a trusted advisor to leadership and cross-functional partners, and influence stakeholders at all levels.
  • Build the function. Establish the processes and tooling and, over time, build and coach a GRC and compliance team.

What we're looking for

  • 10+ years in GRC, compliance, security, IT audit, or technology risk, including owning programs end to end.
  • Proven experience owning SOC 2, HITRUST, and PCI DSS programs through successful audits.
  • Experience building and maintaining an enterprise risk register and risk-management program (inherent/residual risk scoring and treatment plans).
  • Strong understanding of internal control design, testing, documentation, and framework mapping and harmonization across standards such as SOC 2, ISO 27001, HIPAA, PCI DSS, and NIST CSF.
  • Working knowledge of TCPA, FCC telephony regulations, and GDPR, ideally in a communications, telephony, or AI/voice context.
  • A track record of partnering closely with engineering to implement controls in the SDLC.
  • Experience enabling sales through security questionnaires, RFIs, and customer trust conversations.
  • Experience designing and running security training and tabletop and incident-response exercises.
  • Excellent written and verbal communication; able to translate complex risk and compliance concepts for technical and executive audiences at all levels.
  • Ability to operate hands-on in an early-stage, high-velocity environment.

Nice to haves

  • Relevant certifications (CISSP, CISA, CISM, CRISC, CIPP, CCEP, or ISO 27001 Lead Auditor).
  • Experience standing up an AI governance program or applying frameworks such as the NIST AI RMF or ISO/IEC 42001.
  • Experience with GRC and compliance-automation platforms.
  • Experience with cloud environments (Google Cloud preferred) and infrastructure-as-code controls.
  • Experience standing up a compliance program from scratch.

Why Guava

  • Build something foundational. Voice AI is moving fast, and the companies that win will be the ones customers trust. You will own a critical part of that trust.
  • Real ownership. Build and own Guava's entire GRC and compliance function as a first-class program.
  • Engineering-led culture. We value people who go deep, ship, and take end-to-end ownership, with the support of a tight, senior team.
  • In-person and collaborative. Our DTLA office is where we design, whiteboard, and build together, in a growing LA tech scene.