Tensorwave

Governance, Risk, and Compliance Manager

Las Vegas, Nevada, United StatesFull timeManagerPosted 12 days ago
Apply on Tensorwave →

Sign into see who you know at Tensorwave.

About TensorWave

Our mission is simple: deliver seamless, secure, reliable, and resilient AI compute at scale. We've built a versatile cloud platform that eliminates infrastructure barriers, empowering builders to focus on innovation instead of fighting their stack. Because breakthrough AI should move at the speed of ideas, not infrastructure.

About the Role

As our first dedicated Governance, Risk & Compliance Manager, you'll own the GRC framework end to end. This is the person who turns security from a checkbox into a competitive advantage building the continuous compliance posture that shortens enterprise sales cycles, unlocks larger contracts, and prepares us for stricter regulatory oversight and future liquidity events.

You'll operate as a senior individual contributor with broad ownership: designing controls, running audits inhouse, standing up vendor risk governance, and giving leadership real visibility into risk. You know how to build scrappy but compliant processes at a startup and how to mature them toward enterprise standards and you know the difference.

What You’ll Do

- Own the GRC framework. Design, implement, and continuously test a unified controls framework, including IT General Controls (ITGCs), across a growing regulatory landscape.

- Run audits inhouse. Maintain and mature our SOC 2 Type II and ISO 27001 certifications, driving toward automated, continuous evidence collection instead of manual scramble before audit cycles.

- Build the SOX roadmap. Design and test internal controls over financial reporting (ICFR) and ITGCs aligned to AICPA / PCAOB standards, delivering a gap analysis and remediation roadmap that keeps us futureready.

- Stand up vendor & third party risk. Replace manual, adhoc vendor reviews with an automated, enterprise grade third party risk program built for a complex SaaS ecosystem.

- Operationalize a risk register. Run formal, continuous internal risk assessments, map them to a corporate risk register, an...