Decagon

Governance, Risk, and Compliance Manager - FedRAMP at Decagon (San Francisco, CA)

Decagon· San Francisco, CA· $190k–$275k·

Role details

Salary
$190k–$275k
Employment
Full-Time
Equity
Yes
Skills
GRCSOC 2ISO 27001PCI DSSHIPAACCPAData Privacy RegulationsTechnical Security ControlsCompliance Program ManagementProject ManagementAI/ML Compliance FrameworksGDPR
Benefits

Vacation Policy · Medical, Dental, And Vision Benefits · Life Insurance · Disability Benefits · Retirement Plan (401K, Pension) · Parental Leave · Fertility And Family Building Benefits · Daily Lunches And Snacks

Decagon at a glance

Autonomous AI agents that resolve enterprise customer support end to end across chat, voice, email, and SMS.

Decagon builds autonomous AI agents for enterprise customer support, handling chat, voice, email, and SMS from one intelligence layer. Its agents resolve requests end to end and take real actions across a company's support stack, with workflows defined in natural language via Agent Operating Procedures so CX teams can iterate without engineering.

$481M+ raised · latest: Series D · $250M · 2026 · backed by Coatue Management, Index Ventures, Andreessen Horowitz (a16z), Accel

Summary

The Governance, Risk, and Compliance Manager drives the execution of Decagon's compliance program,on a high-growth SaaS platform. Responsibilities include managing SOC 2, ISO 27001, and PCI DSS certifications, automating compliance evidence collection, and supporting customer security assessments to ensure regulator...

Job description

About Decagon

Decagon is the leading conversational AI platform empowering every brand to deliver concierge customer experiences. Our technology enables industry-defining enterprises like Avis Budget Group, Block’s Cash App and Square, Chime, Oura Health, and Hunter Douglas to deploy AI agents that power personalized, deeply satisfying interactions across voice, chat, email, SMS, and every other channel. We’re building a future where customer experiences are being redefined from support tickets and hold music to faster resolutions, richer conversations, and deeper relationships. We’re proud to be backed by world-class investors who share that vision, including a16z, Accel, Bain Capital Ventures, Coatue, and Index Ventures, along with many others. We’re an in-office company, driven by a shared commitment to excellence and velocity. Our values — Just Get It Done, Invent What Customers Want, Winner’s Mindset, and The Polymath Principle — shape how we work and grow as a team.

About the Team

The Security Engineering team at Decagon protects the platform that powers the most advanced conversational AI agents for enterprise customers across voice, chat, email and SMS. We build the security foundations that enable Decagon's AI agents to handle sensitive customer data with complete trust while defending against sophisticated, AI-enabled threats at massive scale. Our mission is to secure magical support experiences, ensuring that AI agents and human agents can collaborate safely to help users resolve their issues while maintaining the highest standards of security and privacy.

About the Role

Join Decagon as a Governance, Risk, and Compliance Manager and play a critical role in securing customer trust as we scale to serve Fortune 500 and international enterprises. Working closely with the head of security and compliance, you'll be responsible for the day-to-day execution of our compliance program and customer security engagements. This is a high-impact role where you'll directly contribute to closing enterprise deals by efficiently managing security communications with customers, supporting compliance audits, and improving our security documentation. Perfect for someone who thrives in a high impact organization with attention to detail, excellent writing skills, and who wants to build expertise in enterprise AI compliance.

In this role, you will

  • Own our route to FedRAMP compliance, with experience on both 20x and traditional Rev 5 approach. Partner heavily with our Public Sector sales team to ensure our authorization path and timeline match the agencies we're actually selling into, sequencing sponsorship, boundary decisions, and control work around live deals rather than in isolation.
  • Define and establish the authorization boundary, 3PAO selection and management, SSP and control narratives, NIST 800-53 baselines, POA&M, and continuous monitoring. Set ConMon up as automated, machine-readable evidence rather than a manual documentation exercise.
  • Run StateRAMP and TX-RAMP alongside the federal track.

Your background looks something like this

  • 5+ years of GRC experience in high-growth SaaS or technology companies, with direct responsibility for FedRAMP compliance programs
  • Proven track record successfully contributing to SOC 2, ISO 27001, or similar enterprise compliance certifications
  • Experience in data privacy regulations including CCPA, GDPR, and emerging AI governance frameworks
  • Strong project management skills with ability to coordinate cross-functional teams under tight deadlines
  • Excellent written and verbal communication skills to translate complex security concepts for diverse audiences
  • Working knowledge of technical security controls and ability to collaborate effectively with engineering teams

Even better if you have

  • Experience with AI/ML compliance frameworks and understanding of unique risks in conversational AI systems
  • Background in healthcare or financial services with knowledge of HIPAA or PCI requirements
  • Track record of building GRC programs at companies scaling from startup to enterprise
  • Experience with GRC platforms like Vanta, Drata, or SecureFrame to automate compliance workflows
  • Understanding of cloud security particularly Google Cloud Platform compliance and security features

Compensation

$190K – $275K + Offers Equity

Benefits

We proudly offer the following benefits for our full-time employees:

  • Medical, Dental, and Vision benefits for you and your family
  • Life Insurance and Disability Benefits
  • Retirement Plan (e.g., 401K, pension)
  • Parental Leave
  • Fertility and family building benefits through Carrot
  • Monthly stipend to support your wellness, lifestyle, and work-life balance
  • Daily lunches and snacks in the office to keep you at your best
  • Take what you need vacation policy (subject to local requirements; UK employees receive 25 days of statutory leave)

These benefits are described in more detail in Decagon’s policies, may vary by location, and can change at any time according to applicable compensation and benefits plans.

Why work at Decagon

  • Culture: Described as "Eng-Driven, Ship Fast, Equity, Product Impact" by employees. Values include: "Just get it done," "Invent what customers want," "Winner's mindset," "The Polymath Principle" (cross-functional collaboration) decagon.ai/careers
  • Compensation: "We hire the best and treat them accordingly" — competitive compensation philosophy; Glassdoor rating: 3.9/5.0 (257 reviews), Compensation: 5.0/5.0 in Glassdoor-style internal review jobsbyculture.com
  • Benefits:
    • 100% medical, dental, and vision coverage for dependents
    • 401k and FSA/commuter benefits
    • Flexible PTO + company-wide winter break shutdown
    • Free daily lunches, dinner, and snacks at HQ
    • Wellness programs and company events decagon.ai/careers
  • Remote/Hybrid/Office: HQ in San Francisco (2261 Market Street); London office (50 York Way). Roles span remote, hybrid, and on-site options based on job postings.
  • Engineering culture: 89 technical employees (21% of workforce), Staff/Senior Research Engineer roles for Voice + Speech; "Build, optimize, and scale AI agents" is core identity. Alumni go on to OpenAI, Datadog, Postman, Accel — strong talent pipeline.
  • Growth trajectory: 134 open roles; 300+% headcount growth YoY; $4.5B valuation at 3 years old — extremely high-growth environment ideal for career acceleration.
  • Notable perk: "We’re building a future where customer experiences are being redefined from support tickets and hold music to faster resolutions" — employees report high product impact and ownership.

Application questions