About Decagon
Decagon is the leading conversational AI platform empowering every brand to deliver concierge customer experience. Our AI agents provide intelligent, human-like responses across chat, email, and voice, resolving millions of customer inquiries across every language and at any time.
Since coming out of stealth, Decagon has experienced rapid growth. We partner with industry leaders like Hertz, Eventbrite, Duolingo, Oura, Bilt, Curology, and Samsara to redefine customer experience at scale. We've raised over $200M from Bain Capital Ventures, Accel, a16z, BOND Capital, A*, Elad Gil, and notable angels such as the founders of Box, Airtable, Rippling, Okta, Lattice, and Klaviyo.
We’re an in-office company, driven by a shared commitment to excellence and velocity. Our values—customers are everything, relentless momentum, winner’s mindset, and stronger together—shape how we work and grow as a team.
About the Team
The Security Engineering team at Decagon protects the platform that powers the most advanced conversational AI agents for enterprise customers across voice, chat, email and SMS. We build the security foundations that enable Decagon's AI agents to handle sensitive customer data with complete trust while defending against sophisticated, AI-enabled threats at massive scale.
Our mission is to secure magical support experiences, ensuring that AI agents and human agents can collaborate safely to help users resolve their issues while maintaining the highest standards of security and privacy.
About the Role
Lead Decagon's governance, risk, and compliance strategy as we scale our AI platform to serve the world's most security-conscious enterprise customers. You'll be the primary point of contact for customer security requirements, managing everything from contract negotiations to compliance certifications. This role offers the opportunity to build a GRC program that enables rapid sales cycles while maintaining the trust of Fortune 500 companies. You'll work directly with sales, legal, and engineering teams to position Decagon as the security leader in conversational AI.
In this role, you will
Lead customer security engagements by negotiating information security exhibits and contractual requirements with enterprise customers and their legal teams, in collaboration with the legal team
Build and manage a scalable security questionnaire process
Drive compliance certifications including SOC 2 Type II, ISO 27001, PCI DSS, HIPAA, and CCPA
Develop and maintain comprehensive security documentation including policies, procedures, and evidence collection
Partner with Sales and Customer Success to accelerate deal velocity by proactively addressing customer security concerns with published content
Collaborate with Security, Engineering, and Product teams to translate compliance requirements into actionable technical controls and ensure new features meet regulatory standards
Establish vendor risk management programs to assess and monitor third-party security risks across our supply chain
Create reporting on risk posture, compliance status, and security metrics that demonstrate continuous improvement
Your background looks something like this
3+ years of GRC experience in high-growth SaaS or technology companies, with direct responsibility for compliance programs
Proven track record successfully completing SOC 2, ISO 27001, or similar enterprise compliance certifications
Expertise in data privacy regulations including CCPA, GDPR, and emerging AI governance frameworks
Experience negotiating security terms with Fortune 500 customers and their procurement teams
Strong project management skills with ability to coordinate cross-functional teams under tight deadlines
Excellent written and verbal communication skills to translate complex security concepts for diverse audiences
Working knowledge of technical security controls and ability to collaborate effectively with engineering teams
Even better
Experience with AI/ML compliance frameworks and understanding of unique risks in conversational AI systems
Background in healthcare or financial services with deep knowledge of HIPAA or PCI requirements
Track record of building GRC programs at companies scaling from startup to enterprise
Experience with GRC platforms like Vanta, Drata, or SecureFrame to automate compliance workflows
Understanding of cloud security particularly Google Cloud Platform compliance and security features
Benefits:
Medical, dental, and vision benefits
Take what you need vacation policy
Daily lunches, dinners and snacks in the office to keep you at your best
Compensation
$180K – $250K + Offers Equity
If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.
Lead regulatory legal strategy for Airwallex in the Americas, advising on payments, card programs and market expansion while helping build an AI-enabled regulatory legal function.
Support ASH’s national regulatory compliance program by conducting legislative research, preparing filings and reports, and coordinating cross-functional compliance activities in a hybrid San Diego-based role.
Lead Bank is looking for a Payments Compliance ITM Analyst to strengthen payments and consumer-banking compliance controls across internal teams and fintech partners in a remote, high-autonomy role.
WOONGJIN, Inc. is hiring a Customs Entry Writer in Plano to prepare and file customs entries, manage importer accounts, and ensure compliance across brokerage operations.
BGM is hiring a Commercial Counsel (SaaS) to lead enterprise contract negotiations, privacy/security responses, and contract operations to support scalable revenue growth.
BGM is hiring a Commercial Counsel to lead SaaS contracting, privacy/compliance, and legal ops to accelerate enterprise deals and enable scalable commercial growth.
Responsible for managing the contract lifecycle for clinical and professional services, ensuring accurate drafting, negotiation, and compliance across stakeholders at a top pediatric hospital.
Remote part-time role for an immigration paralegal or legal professional to edit and validate AI-generated humanitarian immigration documents and contribute to product quality.
Prestigious global law firm seeks an experienced Texas-based Employment & Labor associate to handle litigation, client counseling, government investigations, and policy drafting across individual and class action matters.
The OCME is hiring a Policies & Procedures Specialist to author, manage, and maintain SOPs and the employee manual to support accreditation and consistent agency operations.
Ro seeks a Senior Commercial Counsel II to lead negotiation of commercial agreements and manage the company's contracts queue while partnering with business leaders across the organization.
Senior legal leader needed to direct the Supplemental Needs Trust Program at NYC Department of Social Services, combining complex legal advisory, program management, and policy development.
As Commercial Counsel at BuildOps, you will lead negotiation of SaaS agreements and data/privacy terms while partnering with Sales, Security, Product, and Finance to scale contracting and accelerate revenue.