About Decagon
Decagon is the leading conversational AI platform empowering every brand to deliver concierge customer experience. Our AI agents provide intelligent, human-like responses across chat, email, and voice, resolving millions of customer inquiries across every language and at any time.
Since coming out of stealth, Decagon has experienced rapid growth. We partner with industry leaders like Hertz, Eventbrite, Duolingo, Oura, Bilt, Curology, and Samsara to redefine customer experience at scale. We've raised over $200M from Bain Capital Ventures, Accel, a16z, BOND Capital, A*, Elad Gil, and notable angels such as the founders of Box, Airtable, Rippling, Okta, Lattice, and Klaviyo.
We’re an in-office company, driven by a shared commitment to excellence and velocity. Our values—customers are everything, relentless momentum, winner’s mindset, and stronger together—shape how we work and grow as a team.
The Security Engineering team at Decagon protects the platform that powers the most advanced conversational AI agents for enterprise customers across voice, chat, email and SMS. We build the security foundations that enable Decagon's AI agents to handle sensitive customer data with complete trust while defending against sophisticated, AI-enabled threats at massive scale.
Our mission is to secure magical support experiences, ensuring that AI agents and human agents can collaborate safely to help users resolve their issues while maintaining the highest standards of security and privacy.
Join Decagon as a Senior GRC Analyst and play a critical role in securing customer trust as we scale to serve Fortune 500 and international enterprises. Working closely with the head of security and compliance, you'll be responsible for the day-to-day execution of our compliance program and customer security engagements. This is a high-impact role where you'll directly contribute to closing enterprise deals by efficiently managing security communications with customers, supporting compliance audits, and improving our security documentation. Perfect for someone who thrives in a high impact organization with attention to detail, excellent writing skills, and who wants to build expertise in enterprise AI compliance.
Drive compliance certifications including SOC 2 Type II, ISO 27001, PCI DSS, HIPAA, and CCPA
Automate or execute compliance evidence collection, ensuring all controls are properly documented and audit-ready
Maintain and improve security documentation including policies, procedures, and customer-facing security collateral
Support customer security assessments by preparing materials for security reviews and helping address technical inquiries from Fortune 500 security teams
Manage security and compliance topics in RFPs end-to-end, coordinating responses across engineering, product, and legal teams to deliver accurate, timely responses to enterprise customers.
Coordinate with contractors and vendors to maintain response quality and meet timelines during peak sales periods
Build and optimize repeatable processes to scale our GRC operations to hundreds of enterprise customers
Partner with sales engineering to understand customer security requirements and proactively prepare responses for common concerns
Partner with Sales and Customer Success to accelerate deal velocity by proactively addressing customer security concerns with published content
Collaborate with Security, Engineering, and Product teams to translate compliance requirements into actionable technical controls and ensure new features meet regulatory standards
Establish vendor risk management programs to assess and monitor third-party security risks across our supply chain
3-5 years of GRC experience in high-growth SaaS or technology companies, with direct responsibility for compliance programs
Proven track record successfully contributing to SOC 2, ISO 27001, or similar enterprise compliance certifications
Experience in data privacy regulations including CCPA, GDPR, and emerging AI governance frameworks
Strong project management skills with ability to coordinate cross-functional teams under tight deadlines
Excellent written and verbal communication skills to translate complex security concepts for diverse audiences
Working knowledge of technical security controls and ability to collaborate effectively with engineering teams
Experience with AI/ML compliance frameworks and understanding of unique risks in conversational AI systems
Background in healthcare or financial services with knowledge of HIPAA or PCI requirements
Track record of building GRC programs at companies scaling from startup to enterprise
Experience with GRC platforms like Vanta, Drata, or SecureFrame to automate compliance workflows
Understanding of cloud security particularly Google Cloud Platform compliance and security features
Medical, dental, and vision benefits
Take what you need vacation policy
Daily lunches, dinners and snacks in the office to keep you at your best
$140K – $220K + Offers Equity
If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.
Finch is hiring a meticulous Demand Reviewer with deep personal-injury experience to produce high-quality, persuasive demand packages using proprietary AI tools.
Experienced registered nurse with utilization review expertise sought for a remote, contract appeals role creating clinical appeals to overturn payer denials on a 1099 basis.
Retired Big 4 SOX controls consultant needed to design and document control approaches, risk mappings, and mitigation strategies for S/4HANA and cloud-native solutions at an established genomics firm.
Bush & Bush Law Group is hiring a bilingual (English/Spanish) Labor & Employment Law Paralegal in Texas to support employment and personal injury litigation from intake through trial.
Experienced estate planning attorney needed at a respected national law firm in New York to draft wills and trusts, advise on tax and probate matters, and work closely with clients and professional advisors.
Lead KIND’s San Francisco legal program to deliver high-quality immigration representation, pro bono mentoring, and program management for unaccompanied and separated children.
Serve as a legislative advocate and policy advisor for Michigan Farm Bureau, helping develop, communicate, and implement state-level agricultural policies.
DCAS is hiring a Vendor Contract Auditor (Staff Analyst) to conduct contract and invoice audits, evaluate internal controls, and support agency-wide compliance and risk management.
MUFG is hiring an experienced Internal Audit Vice President to lead and execute audits across Global Corporate & Investment Banking, providing governance, risk and control assurance while managing a team and executive relationships.
The New York County DA's Office seeks a bilingual Spanish Engagement Specialist to support victims and witnesses through outreach, translation, referrals, and case intake for the Early Engagement Case Support Unit.
Serve as an Agency Attorney Intern at DCAS, assisting with disciplinary investigations, prosecuting cases under Civil Service Law and collective bargaining agreements, and providing legal research and counsel across agency matters.
Finch Legal seeks a bilingual (English/Spanish) Legal Intake Specialist to qualify personal injury cases, secure client sign-ups, and deliver a high-trust intake experience for partner law firms.
Experienced attorney needed to serve as Associate General Counsel supporting corporate, real estate, technology and contract matters for Church’s Texas Chicken at the Atlanta Restaurant Support Center.