Oversee and enhance the GRC program at Retool, ensuring compliance with SOC 2 and ISO 27001. Collaborate with multiple teams to embed compliance into workflows and manage risk across vendors, while maintaining customer trust through operational excellence.
ABOUT RETOOL
Nearly every company in the world runs on custom software: Gartner estimates that up to 50% of all code is written for internal use. This is the operational software for refunding orders, underwriting loans, onboarding employees, analyzing transactions, and providing customer support. But most companies don’t have adequate resources to properly invest in these tools, leading to a lot of old and clunky internal software or, even worse, users still stuck in manual and spreadsheet flows.
At Retool, we’re on a mission to bring good software to everyone. We’re building a new type of development platform that combines the benefits of traditional software development with a drag-and-drop UI editor and AI, making it dramatically faster to build internal tools. We believe that the future of software development lies in abstracting away the tedious and repetitive tasks developers waste time on, while creating reusable components that act as a force multiplier for future developers and projects. The result is not just productivity, but good software by default. And that’s a mission worth striving for.
Today, our customers span from small startups building their first operational tools to Fortune 500 companies building mission-critical apps for thousands of users across their business. Interested in joining us? Let us know!
WHY WE’RE LOOKING FOR YOU
Retool's Trust Team is seeking an experienced GRC Lead to build and scale our governance, risk, and compliance program. Today, we maintain SOC 2 Type II and ISO 27001 certifications, but we're looking for someone who sees compliance not as a checkbox exercise, but as the foundation of customer trust and operational excellence.
In this role, you'll own the maturity journey from being just "compliant" to enabling true program excellence through building the processes, policies, and evidence infrastructure that let us confidently say what we do and demonstrably do what we say. You'll work at the nexus of security, legal, engineering, and go-to-market teams to ensure our compliance posture enables rather than constrains the business, and engineering to build safely at-speed.
This is a hands-on role with strategic scope. You'll shape GRC strategy, scale our assurance capabilities, and build the operational muscle that enables Retool to earn and maintain customer trust at scale.
At Retool, we're not just building a product—we're building a company where security is foundational to everything we do. If you're passionate about leading a critical function in a dynamic, innovative environment, we'd love to hear from you.
IN THIS ROLE, YOU WILL:
- Own and mature our compliance programs (SOC 2, ISO 27001, and future frameworks), including audit preparation, evidence collection, and auditor relationships
- Build and operate our customer assurance function, maintaining Trust Program documentation, managing security questionnaire responses, and supporting customer security reviews
- Develop and govern security policies, standards, and procedures, ensuring alignment between documented controls and operational reality
- Stand up and run our third-party risk management program, assessing vendor security posture across the procurement lifecycle
- Establish risk management practices including risk identification, assessment, treatment tracking, and executive reporting
- Partner with Engineering and Product teams to embed compliance considerations into development workflows without creating friction
- Define metrics and reporting that demonstrate program effectiveness to senior leadership
THE SKILLSET YOU'LL BRING:
- 8+ years in GRC, security compliance, or related roles, with experience building programs, not just operating within established ones
- Deep expertise in SOC 2, ISO 27001, and familiarity with adjacent frameworks (NIST CSF and SSDF, etc.)
- Experience supporting B2B SaaS sales cycles through customer security reviews and Trust documentation
- Strong technical fluency, such that you can read a system architecture diagram and have credible conversations with engineers
- Comfort with ambiguity and the ability to prioritize ruthlessly in a fast-moving environment
- Excellent written and verbal communication, with the ability to translate compliance requirements into business terms
- A builder's mindset for a company of builders: you think about automation, efficiency, and scalability, not just completeness
NICE TO HAVE:
- Experience with FedRAMP, FISMA, or FIPS 140-2/3 compliance requirements
- Familiarity with privacy frameworks (GDPR, CCPA) and their intersection with security compliance
- Hands-on experience with GRC platforms (Vanta, Drata, Delve, etc.) and a perspective on how to use tooling to scale
- Previous experience at a high-growth B2B SaaS company, particularly one selling to security-conscious enterprises
- Relevant certifications (CISA, CRISC, CISSP, CIPP, or similar)
- Experience building or contributing to customer-facing trust centers or security portals
For candidates based in the United States, the pay range(s) for this role is listed below and represents base salary range for non-commissionable roles or on-target earnings (OTE) for commissionable roles. This salary range may be inclusive of several career levels at Retool and will be narrowed during the interview process based on a number of factors such as (but not limited to), scope and responsibilities, the candidate’s experience and qualifications, and location.
Additional compensation in the form(s) of equity and/or commission are dependent on the position offered. Retool provides a comprehensive benefit plan, including medical, dental, vision, and 401(k). Pay and benefits are subject to change at any time, consistent with the terms of any applicable compensation or benefit plans.
The base pay range for this role is $198,300 – $288,225 per year.
Retool offers generous benefits to all employees and hybrid work location. For more information, please visit the benefits and perks section of our careers page!
Retool is currently set up to employ all roles in the US and specific roles in the UK and Mexico. To find roles that can be employed in the UK and Mexico, please refer to our careers page and review the indicated locations.
Top Skills
Grc Platforms
Iso 27001
Nist Csf
Soc 2
Retool New York, New York, USA Office
Retool NYC is in the heart of the Flatiron District, with tons of shopping and dining nearby. The 23rd Street station is just a short walk away. We have limited bike storage and 24/7 security.
Similar Jobs
AdTech • Consumer Web • Digital Media • eCommerce • Marketing Tech
The Assistant Editor will update and optimize library articles, track performance analytics, collaborate with teams, and support editorial projects.
Top Skills:
Ai ToolsContent Management SystemsGoogle AnalyticsLookerSeo
Artificial Intelligence • Cloud • Machine Learning • Mobile • Software • Virtual Reality • App development
As a Machine Learning Engineer, you'll build and deploy models for core products, apply ML techniques to solve problems, and collaborate on features.
Top Skills:
Caffe2PyTorchScikit-LearnSpark MlTensorFlow
Artificial Intelligence • Cloud • Machine Learning • Mobile • Software • Virtual Reality • App development
Develop features for Android applications, conduct code reviews, and evaluate technical tradeoffs while ensuring great user experiences.
Top Skills:
DaggerJavaKotlinRxjava
What you need to know about the NYC Tech Scene
As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.
Key Facts About NYC Tech
- Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
- Key Industries: Artificial intelligence, Fintech
- Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
- Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory


