{"schemaVersion":"jobsearcher.job.v1","id":"aed8ecee1e0695e1bcdc44a4","url":"https://jobsearcher.com/jobs/aed8ecee1e0695e1bcdc44a4","canonicalUrl":"https://jobsearcher.com/jobs/aed8ecee1e0695e1bcdc44a4","title":"Director, Trust & Assurance","description":"Director, Trust & Assurance\nReports to: General Counsel\nLocation: San Francisco office or New York office\nType: Full-time\nAbout the Role\nSigma is looking for a Director of Trust & Assurance to build and run our compliance and enterprise risk function, and to lead the team behind it. You will own our GRC program end-to-end (SOC 2/ISO audits, policies, vendor risk) while positioning the team and the function to grow into an enterprise risk function as the company matures. This is a builder-and-leader role for someone who has run a similar successful program.\nYou will take ownership of compliance, contractual, vendor, and enterprise/business risk, reporting directly to the General Counsel, with a team reporting to you.\nYou will also work closely with Security, HR, Sales, and other members of leadership.\nWhat You'll Do\nCompliance & Controls\nOwn our SOC 2 (and/or ISO 27001) program — including PCI DSS and other relevant standards as applicable — covering control implementation, evidence collection, audit management, and remediation tracking\nMaintain and evolve our internal policy library and employee attestation process\nMonitor regulatory requirements relevant to our business (data privacy, industry-specific regulations) and work with the Legal team to assess impact and translate requirements into practical controls\nConduct internal audits and assessments to validate control effectiveness\nManage security awareness training programs enterprise-wide\nVendor & Third-Party Risk\nRun vendor risk assessments and maintain a vendor risk inventory, including contract reviews and ongoing monitoring\nManage subprocessor tracking and disclosures\nPartner with Legal on risk-related contract terms for vendors\nCustomer Trust\nOwn the security questionnaire response process (VSAs, SIGs, and custom questionnaires) and our customer-facing trust documentation\nMaintain ready-to-use compliance artifacts and trust center content to support efficient deal cycles\nAct as a trusted resource for Sales, Sales Engineering, and Solutions teams on security-related deal questions\nBusiness Continuity & Incident Response\nMaintain our business continuity/disaster recovery plan, including regular testing\nTogether with the Security team, own the incident response plan, including running periodic tabletop exercises\nLead post-incident reviews and track remediation\nGrowth into Enterprise Risk\nMature and maintain a enterprise risk register\nCreate risk treatment plans and track remediation activities across the organization\nRun quarterly risk reviews\nScan for emerging risks (regulatory, market, operational) and flag material developments to the GC\nInsurance\nManage the company's insurance program (cyber, E&O, D&O) including renewals and coverage review\nServe as primary point of contact with brokers and carriers\nTeam Leadership\nManage and develop a team of 3+ direct reports covering compliance analysts, vendor risk, and/or a GRC coordinator\nSet goals, run performance reviews, and build career paths for direct reports\nWhat We're Looking For\n8+ years of experience in GRC, compliance, audit, or risk management, ideally in a SaaS or technology company, including at least 2–3 years directly managing people\nHas personally owned a SOC 2 or ISO 27001 program through at least one full audit cycle, including managing the auditor relationship end-to-end — not just executing tasks within someone else's program\nTrack record of building a function or program from the ground up, not just maintaining an established one\nExperience with vendor/third-party risk assessment processes\nExperience implementing risk management frameworks (COSO, ISO 31000, NIST RMF, or similar)\nAbility to translate technical/security concepts into risk language for executives and business language for engineers, with excellent communication skills to influence stakeholders at all levels\nStrong project management skills; comfortable juggling audits, questionnaires, and quarterly reporting simultaneously\nBonus: experience with GRC tooling (Vanta, Drata, Secureframe, ServiceNow GRC, Archer, LogicGate, or similar)\nBonus: hands-on experience with cloud environments (GCP, AWS, Azure) from a compliance and security perspective\nBonus: familiarity with security frameworks such as NIST CSF, CIS Controls, or OWASP\nBonus: relevant certifications (CISA, CRISC, CISSP, CGRC, CRM, CISM, CGEIT, or CIPP)\nWhat Success Looks Like in Year One\nSOC 2 Type II achieved/maintained with no material findings\nVendor risk assessment process in place and adopted before contract signing\nEnterprise risk register matured and reviewed quarterly\nIncident response plan tested via tabletop exercise\nInsurance program reviewed for adequacy with no coverage gaps\nSecurity questionnaire turnaround time meets sales cycle needs\nWhy Join Sigma\nThis is an opportunity to build and lead a world-class Trust & Assurance function — not just checking boxes, but genuinely enabling the business to pursue opportunities with confidence. You'll have direct access to the General Counsel and executive team, build and grow your own team from the ground up, and make a tangible impact on how Sigma manages risk and earns customer trust as we scale.\nAdditional Job details\nThe base salary range for this position is $225k to $265k annually.\nCompensation may vary outside of this range depending on a number of factors, including a candidate's qualifications, skills, competencies and experience. Base pay is one part of the Total Package that is provided to compensate and recognize employees for their work at Sigma Computing. This role is eligible for stock options, as well as a comprehensive benefits package.\nAbout us:\nSigma is the AI Apps and agentic analytics platform built on the cloud data warehouse. Business and technical teams use Sigma to explore live data, build intelligent applications, and automate critical workflows all without moving data or breaking governance. Sigma supports a spreadsheet interface, SQL, Python, and native AI in a single governed workspace, giving every team the speed to act and IT the control to scale. Sigma is trusted by more than 2,000 customers, including AMD, Duolingo, Colgate-Palmolive, and JPMorgan Chase.\nSigma announced its $80M in Series E financing in May 2026. The round was led by Princeville Capital, with new strategic investors Databricks Ventures, ServiceNow Ventures, and Workday Ventures participating alongside returning investors Altimeter Capital, Avenir Growth Capital, D1 Capital Partners, K5 Global, NewView Capital, Spark Capital, Sutter Hill Ventures, and XN. This milestone follows Sigma reaching $200M in annual recurring revenue in April 2026, with more than 100% year-over-year growth and 1.1 million new active users added in the latest fiscal year.\nCome join us!\nBenefits For Our Full-Time Employees:\nEquity\nGenerous health benefits\nFlexible time off policy. Take the time off you need!\nPaid bonding time for all new parents\nTraditional and Roth 401k\nCommuter and FSA benefits\nLunch Program\nDog friendly office\nSigma is an equal opportunity employer. We are committed to building a smart and strong team regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender, gender identity or expression, veteran, or any other protected status. We look forward to learning how your experience can enable all of us to grow.\nNote: We have an in-office work environment in all our offices in SF, NYC, London and Sydney.\nOur Privacy Practices\nWhen you submit a job application on this site, Sigma processes your personal data for the purposes of evaluating your candidacy for employment at Sigma and as otherwise needed throughout the recruitment and hiring process. Please review Sigma's Candidate Privacy Notice for more details. Please note that your personal data may be transferred to a country other than the one in which it was provided (including to the USA, the UK, and Canada, Australia).\nSigma's use of AI\nThis hiring process utilizes artificial intelligence tools to assist in candidate screening and assessment. Our AI tools are designed to complement, not replace, human decision-making.","company":"Sigma Computing","rawCompany":"sigma computing","city":"Millbrae","state":"CA","isRemote":false,"isActive":false,"createdAt":"2026-08-06T16:25:15.036Z","occupations":[{"code":"11-9199.02","title":"Compliance Managers","slug":"compliance-managers"},{"code":"13-1041.00","title":"Compliance Officers","slug":"compliance-officers"},{"code":"11-9199.01","title":"Regulatory Affairs Managers","slug":"regulatory-affairs-managers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541618","title":"Other Management Consulting Services","slug":"other-management-consulting-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Director, Trust & Assurance","description":"Director, Trust & Assurance\nReports to: General Counsel\nLocation: San Francisco office or New York office\nType: Full-time\nAbout the Role\nSigma is looking for a Director of Trust & Assurance to build and run our compliance and enterprise risk function, and to lead the team behind it. You will own our GRC program end-to-end (SOC 2/ISO audits, policies, vendor risk) while positioning the team and the function to grow into an enterprise risk function as the company matures. This is a builder-and-leader role for someone who has run a similar successful program.\nYou will take ownership of compliance, contractual, vendor, and enterprise/business risk, reporting directly to the General Counsel, with a team reporting to you.\nYou will also work closely with Security, HR, Sales, and other members of leadership.\nWhat You'll Do\nCompliance & Controls\nOwn our SOC 2 (and/or ISO 27001) program — including PCI DSS and other relevant standards as applicable — covering control implementation, evidence collection, audit management, and remediation tracking\nMaintain and evolve our internal policy library and employee attestation process\nMonitor regulatory requirements relevant to our business (data privacy, industry-specific regulations) and work with the Legal team to assess impact and translate requirements into practical controls\nConduct internal audits and assessments to validate control effectiveness\nManage security awareness training programs enterprise-wide\nVendor & Third-Party Risk\nRun vendor risk assessments and maintain a vendor risk inventory, including contract reviews and ongoing monitoring\nManage subprocessor tracking and disclosures\nPartner with Legal on risk-related contract terms for vendors\nCustomer Trust\nOwn the security questionnaire response process (VSAs, SIGs, and custom questionnaires) and our customer-facing trust documentation\nMaintain ready-to-use compliance artifacts and trust center content to support efficient deal cycles\nAct as a trusted resource for Sales, Sales Engineering, and Solutions teams on security-related deal questions\nBusiness Continuity & Incident Response\nMaintain our business continuity/disaster recovery plan, including regular testing\nTogether with the Security team, own the incident response plan, including running periodic tabletop exercises\nLead post-incident reviews and track remediation\nGrowth into Enterprise Risk\nMature and maintain a enterprise risk register\nCreate risk treatment plans and track remediation activities across the organization\nRun quarterly risk reviews\nScan for emerging risks (regulatory, market, operational) and flag material developments to the GC\nInsurance\nManage the company's insurance program (cyber, E&O, D&O) including renewals and coverage review\nServe as primary point of contact with brokers and carriers\nTeam Leadership\nManage and develop a team of 3+ direct reports covering compliance analysts, vendor risk, and/or a GRC coordinator\nSet goals, run performance reviews, and build career paths for direct reports\nWhat We're Looking For\n8+ years of experience in GRC, compliance, audit, or risk management, ideally in a SaaS or technology company, including at least 2–3 years directly managing people\nHas personally owned a SOC 2 or ISO 27001 program through at least one full audit cycle, including managing the auditor relationship end-to-end — not just executing tasks within someone else's program\nTrack record of building a function or program from the ground up, not just maintaining an established one\nExperience with vendor/third-party risk assessment processes\nExperience implementing risk management frameworks (COSO, ISO 31000, NIST RMF, or similar)\nAbility to translate technical/security concepts into risk language for executives and business language for engineers, with excellent communication skills to influence stakeholders at all levels\nStrong project management skills; comfortable juggling audits, questionnaires, and quarterly reporting simultaneously\nBonus: experience with GRC tooling (Vanta, Drata, Secureframe, ServiceNow GRC, Archer, LogicGate, or similar)\nBonus: hands-on experience with cloud environments (GCP, AWS, Azure) from a compliance and security perspective\nBonus: familiarity with security frameworks such as NIST CSF, CIS Controls, or OWASP\nBonus: relevant certifications (CISA, CRISC, CISSP, CGRC, CRM, CISM, CGEIT, or CIPP)\nWhat Success Looks Like in Year One\nSOC 2 Type II achieved/maintained with no material findings\nVendor risk assessment process in place and adopted before contract signing\nEnterprise risk register matured and reviewed quarterly\nIncident response plan tested via tabletop exercise\nInsurance program reviewed for adequacy with no coverage gaps\nSecurity questionnaire turnaround time meets sales cycle needs\nWhy Join Sigma\nThis is an opportunity to build and lead a world-class Trust & Assurance function — not just checking boxes, but genuinely enabling the business to pursue opportunities with confidence. You'll have direct access to the General Counsel and executive team, build and grow your own team from the ground up, and make a tangible impact on how Sigma manages risk and earns customer trust as we scale.\nAdditional Job details\nThe base salary range for this position is $225k to $265k annually.\nCompensation may vary outside of this range depending on a number of factors, including a candidate's qualifications, skills, competencies and experience. Base pay is one part of the Total Package that is provided to compensate and recognize employees for their work at Sigma Computing. This role is eligible for stock options, as well as a comprehensive benefits package.\nAbout us:\nSigma is the AI Apps and agentic analytics platform built on the cloud data warehouse. Business and technical teams use Sigma to explore live data, build intelligent applications, and automate critical workflows all without moving data or breaking governance. Sigma supports a spreadsheet interface, SQL, Python, and native AI in a single governed workspace, giving every team the speed to act and IT the control to scale. Sigma is trusted by more than 2,000 customers, including AMD, Duolingo, Colgate-Palmolive, and JPMorgan Chase.\nSigma announced its $80M in Series E financing in May 2026. The round was led by Princeville Capital, with new strategic investors Databricks Ventures, ServiceNow Ventures, and Workday Ventures participating alongside returning investors Altimeter Capital, Avenir Growth Capital, D1 Capital Partners, K5 Global, NewView Capital, Spark Capital, Sutter Hill Ventures, and XN. This milestone follows Sigma reaching $200M in annual recurring revenue in April 2026, with more than 100% year-over-year growth and 1.1 million new active users added in the latest fiscal year.\nCome join us!\nBenefits For Our Full-Time Employees:\nEquity\nGenerous health benefits\nFlexible time off policy. Take the time off you need!\nPaid bonding time for all new parents\nTraditional and Roth 401k\nCommuter and FSA benefits\nLunch Program\nDog friendly office\nSigma is an equal opportunity employer. We are committed to building a smart and strong team regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender, gender identity or expression, veteran, or any other protected status. We look forward to learning how your experience can enable all of us to grow.\nNote: We have an in-office work environment in all our offices in SF, NYC, London and Sydney.\nOur Privacy Practices\nWhen you submit a job application on this site, Sigma processes your personal data for the purposes of evaluating your candidacy for employment at Sigma and as otherwise needed throughout the recruitment and hiring process. Please review Sigma's Candidate Privacy Notice for more details. Please note that your personal data may be transferred to a country other than the one in which it was provided (including to the USA, the UK, and Canada, Australia).\nSigma's use of AI\nThis hiring process utilizes artificial intelligence tools to assist in candidate screening and assessment. Our AI tools are designed to complement, not replace, human decision-making.","datePosted":"2026-08-06T16:25:15.036Z","dateModified":"2026-08-06T16:25:15.036Z","hiringOrganization":{"@type":"Organization","name":"Sigma Computing","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Millbrae","addressRegion":"CA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"aed8ecee1e0695e1bcdc44a4"},"url":"https://jobsearcher.com/jobs/aed8ecee1e0695e1bcdc44a4"}}