Director, Trust & Assurance

Sigmacomputing · San francisco, CA · Other

Posted 2026-08-12

Apply for this role →

Director, Trust & Assurance

Reports to: General Counsel

Location: San Francisco office or New York office

Type: Full-time

About the Role

Sigma is looking for a Director of Trust & Assurance to build and run our compliance and enterprise risk function, and to lead the team behind it. You will own our GRC program end-to-end (SOC 2/ISO audits, policies, vendor risk) while positioning the team and the function to grow into an enterprise risk function as the company matures. This is a builder-and-leader role for someone who has run a similar successful program.

You will take ownership of compliance, contractual, vendor, and enterprise/business risk, reporting directly to the General Counsel, with a team reporting to you.

You will also work closely with Security, HR, Sales, and other members of leadership.

What You'll Do

Compliance & Controls

Own our SOC 2 (and/or ISO 27001) program — including PCI DSS and other relevant standards as applicable — covering control implementation, evidence collection, audit management, and remediation tracking

Maintain and evolve our internal policy library and employee attestation process

Monitor regulatory requirements relevant to our business (data privacy, industry-specific regulations) and work with the Legal team to assess impact and translate requirements into practical controls

Conduct internal audits and assessments to validate control effectiveness

Manage security awareness training programs enterprise-wide

Vendor & Third-Party Risk

Run vendor risk assessments and maintain a vendor risk inventory, including contract reviews and ongoing monitoring

Manage subprocessor tracking and disclosures

Partner with Legal on risk-related contract terms for vendors

Customer Trust

Own the security questionnaire response process (VSAs, SIGs, and custom questionnaires) and our customer-facing trust documentation

Maintain ready-to-use compliance artifacts and trust center content to support efficient deal cycles

Act as a trusted resource for Sales, Sales Engineering, and Solutions teams on security-related deal questions

Business Continuity & Incident Response

Maintain our business continuity/disaster recovery plan, including regular testing

Together with the Security team, own the incident response plan, including running periodic tabletop exercises

Lead post-incident reviews and track remediation

Growth into Enterprise Risk

Mature and maintain a enterprise risk register

Create risk treatment plans and track remediation activities across the organization

Run quarterly risk reviews

Scan for emerging risks (regulatory, market, operational) and flag material developments to the GC

Insurance

Manage the company's insurance program (cyber, E&O, D&O) including renewals and coverage review

Serve as primary point of contact with brokers and carriers

Team Leadership

Manage and develop a team of 3+ direct reports covering compliance analysts, vendor risk, and/or a GRC coordinator

Set goals, run performance reviews, and build career paths for direct reports

What We're Looking For

8+ years of experience in GRC, compliance, audit, or risk management, ideally in a SaaS or technology company, including at least 2–3 years directly managing people

Has personally owned a SOC 2 or ISO 27001 program through at least one full audit cycle, including managing the auditor relationship end-to-end — not just executing tasks within someone else's program

Track record of building a function or program from the ground up, not just maintaining an established one

Experience with vendor/third-party risk assessment processes

Experience implementing risk management frameworks (COSO, ISO 31000, NIST RMF, or similar)

Ability to translate technical/security concepts into risk language for executives and business language for engineers, with excellent communication skills to influence stakeholders at all levels

Strong project management skills; comfortable juggling audits, questionnaires, and quarterly reporting simultaneously

Bonus: experience with GRC tooling (Vanta, Drata, Secureframe, ServiceNow GRC, Archer, LogicGate, or similar)

Bonus: hands-on experience with cloud environments (GCP, AWS, Azure) from a compliance and security perspective

Bonus: familiarity with security frameworks such as NIST CSF, CIS Controls, or OWASP

Bonus: relevant certifications (CISA, CRISC, CISSP, CGRC, CRM, CISM, CGEIT, or CIPP)

What Success Looks Like in Year One

SOC 2 Type II achieved/maintained with no material findings

Vendor risk assessment process in place and adopted before contract signing

Enterprise risk register matured and reviewed quarterly

Incident response plan tested via tabletop exercise

Insurance program reviewed for adequacy with no coverage gaps

Security questionnaire turnaround time meets sales cycle needs

Why Join Sigma

This is an opportunity to build and lead a world-class Trust & Assurance function — not just checking boxes, but genuinely enabling the business to pursue opportunities with confidence. You'll have direct access to the General Counsel and executive team, build and grow your own team from the ground up, and make a tangible impact on how Sigma manages risk and earns customer trust as we scale.

Additional Job details

The base salary range for this position is $225k to $265k annually.

Compensation may vary outside of this range depending on a number of factors, including a candidate’s qualifications, skills, competencies and experience. Base pay is one part of the Total Package that is provided to compensate and recognize employees for their work at Sigma Computing. This role is eligible for stock options, as well as a comprehensive benefits package.

About us:

Apply for this role →

← Back to all jobs