Head of Compliance & GRC

Other Jobs To Apply

<h3><strong>About Nametag</strong></h3> <p>Nametag is building the future of secure digital identity. Our mission is to make it easy for people and organizations to prove who they are online - safely and seamlessly. We’re pioneering next-generation identity verification and account protection so that users can control their own identity, and companies can build trust without friction.</p> <p> </p> <h3><strong>The Role</strong></h3> <p>Nametag is seeking an experienced Compliance & GRC leader to own and evolve our security and compliance program. This role is ideal for someone who thrives in a fast-paced startup environment, has deep experience with SOC 2 and other compliance frameworks, and is comfortable building and running programs with limited resources. You'll report directly to the Head of Engineering and partner closely with the engineering team to ensure security is built into everything we do.</p> <p>As the Head of Compliance & GRC, you will own the entire security and compliance function - maintaining our existing certifications, driving new compliance initiatives, coordinating penetration tests, and building trust with customers and prospects. This is a hands-on leadership role where you'll be the team initially, with a clear path to building and leading a team as Nametag scales. You'll work closely with engineering, product, sales, and customer success to ensure security enables the business rather than blocking it.</p> <p> </p> <h3><strong>What You’ll Do</strong></h3> <p><strong> Compliance Program Management</strong></p> <ul> <li>Own and maintain SOC 2 Type II certification, including evidence collection, control monitoring, and audit coordination</li> <li>Drive IAL3 compliance readiness and implementation</li> <li>Manage accessibility compliance (WCAG) requirements</li> <li>Identify and pursue additional certifications as needed based on customer and market requirements</li> </ul> <p><strong> Security Operations</strong></p> <ul> <li>Coordinate penetration testing cycles and drive remediation with engineering</li> <li>Maintain a living view of organizational risk and surface it to leadership</li> <li>Develop and maintain security policies, procedures, and controls</li> <li>Respond to security incidents with speed and clarity</li> </ul> <p><strong> Customer Trust</strong></p> <ul> <li>Respond to customer security questionnaires promptly and accurately</li> <li>Support sales in security-sensitive enterprise deals</li> <li>Maintain public-facing trust documentation</li> <li>Participate in customer security calls and reviews as needed</li> </ul> <p><strong> Cross-Functional Partnership</strong></p> <ul> <li>Partner with engineering to build security into the development process</li> <li>Provide clear security guidance and timely reviews so teams can ship with confidence</li> <li>Collaborate with product on security and accessibility features</li> <li>Work with customer success to address customer security concerns</li> </ul> <h3><strong>Ideal Qualifications</strong></h3> <p>We know that no candidate will perfectly match every requirement - and that’s okay. If you’re passionate about what we’re building and have most of the skills below, we’d love to hear from you.</p> <ul> <li>7+ years of experience in security, compliance, or GRC, with demonstrated ownership of SOC 2 Type II programs</li> <li>Experience building or running compliance programs in startup or resource-constrained environments</li> <li>Strong understanding of how auditors think - ideally from auditor-side experience or running multiple audit cycles</li> <li>Technical fluency to read pen test reports, understand cloud architecture, and have informed conversations with engineers</li> <li>Knowledge of GRC tooling and vendors, with opinions on what's worth investing in at different company stages</li> <li>Excellent communication skills - able to translate security topics for executives, salespeople, and customers</li> <li>Experience with identity verification, authentication, or security-focused products is a strong plus</li> <li>Familiarity with IAL2/IAL3 or NIST 800-63 identity proofing standards is a strong plus</li> <li>CISSP, ISO 27001 Lead Auditor, or similar certifications are a plus but not required</li> </ul> <p> </p> <h3><strong>What We Value</strong></h3> <ul> <li><strong>Intellectual horsepower</strong> – quickly grasping complex technical and business concepts.</li> <li><strong>Kindness and integrity</strong> – earning trust is central to how we build relationships with customers and colleagues.</li> <li><strong>Bias for action</strong> – we move quickly to deliver impact and protect our customers against fast-moving threats.</li> </ul> <p> </p> <h3><strong>Compensation</strong></h3> <p>The base salary range for this full-time position is $120,000-$160,000, plus equity and benefits.</p> <p>Nametag is a founding member of the Open Imperative, publicly committed to pay equity in the technology industry. We post positions with ranges to encourage people of different backgrounds and experiences to apply. Every offer is benchmarked against market data to ensure fairness and consistency.</p> <p>Final compensation is determined by role, level, and additional factors such as skills, experience, and education. Your recruiter or hiring manager can share more details during the hiring process.</p> <p> </p> <p><strong>Culture & Perks</strong></p> <p>At Nametag, we believe trust starts with how we treat each other. We’re a remote-first team that values autonomy, inclusivity, and collaboration - with regular in-person time to stay connected and innovate together.</p> <ul> <li><strong>Remote-first:</strong> Work from anywhere in the US. Our team spans Seattle, San Francisco, Ann Arbor, Denver, New York City, and beyond.</li> <li><strong>Quarterly off-sites:</strong> We bring the team together once per quarter for in-person collaboration - often off-site in new places.</li> <li><strong>Flexible schedules:</strong> Work in your own time zone; we align key meetings across a shared window.</li> </ul> <p> </p> <h3><strong>We Offer</strong></h3> <ul> <li>Competitive salary</li> <li>Meaningful equity ownership</li> <li>Comprehensive health benefits (medical, dental, vision)</li> <li>Flexible paid time off</li> <li>Quarterly team off-sites and travel support</li> <li>New computer hardware and equipment</li> <li>An inclusive environment where your voice has impact and your work drives change</li> </ul>

Back to blog

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...