The opportunity
At Gusto, we're on a mission to grow the small business economy. We handle the hard stuff — payroll, health insurance, 401(k)s, and HR — so owners can focus on their craft and their customers.
What you'll do
Develop, maintain, and ensure adherence to security and compliance SOPs,: internal documentation, and company-wide policies—particularly supporting SOC 2 and future framework adoption.
Own and manage trust management platforms including documentation of: controls, risks, vendors, and exceptions, and lead the implementation of AI agents to automate and improve the implementation of our controls framework and evidence collection to support it
Collaborate with Legal, Enterprise Applications, and Gusto counterparts to: establish and maintain data governance policies (e.g., classification, retention, handling).
Conduct ongoing internal risk assessments to identify exposure and control: gaps; coordinate remediation plans with functional teams.
Manage the third-party vendor risk program, including onboarding reviews, monitoring, and renewal assessments.
Lead interactions with external auditors and regulatory bodies during: compliance assessments (e.g., SOC 2 Type 2) and oversee responses to client security assessments and due diligence requests.
What they're looking for
- Stay current on relevant compliance frameworks, laws, and regulations to: ensure appropriate coverage and adaptability.
- Partner cross-functionally (e.g., Security, Legal, Engineering, Sales, IT) to: implement scalable GRC processes, harmonize systems, and foster GRC understanding through employee enablement programs and KPI-driven insights.
- + years of experience in governance, risk, and compliance within SaaS,: ideally in the HCM, payroll, or fintech sectors.
- Bachelor’s degree in Business, Information Systems, or a related field.