GRC Domain Lead + Products
WHY ZANIA
Every enterprise spends millions of dollars on Governance, Risk, and Compliance (GRC). It's one of the most critical, yet universally painful, parts of running a business. For decades, this industry has been dominated by legacy systems with notoriously low NPS scores, making it totally ripe for disruption.
Zania is building agentic AI for Governance, Risk, and Compliance (GRC) to solve this massive problem. We are on a rocketship trajectory, creating intelligent agents that automate and augment the most complex risk and compliance workflows. We have found exceptional product-market fit and are scaling our team very quickly. Some reasons to join Zania are:
- Dream Customers: Our customers are the most notable enterprises in the world, including FAANG, Big 4 firms, and a portfolio of top customers.
- Tier 1 Backing: Funded by a leading Tier 1 venture capital fund. Series A led by NEA, with Anthropic and Menlo Ventures. $18M raised to build a generational company.
- World-Class Team: Zania is hiring the best. Our team includes AI and Security leaders from Airbnb, Microsoft, Bain & Company, Deloitte, PwC, Brex, and Instacart.
- Hyper-Growth: We have seen 10x ARR growth in the last year and are rapidly expanding.
- Competitive Compensation & Equity.
THE ROLE
As a Risk and Compliance Expert at Zania, you are the senior GRC voice our customers rely on. This is a non-technical, customer-facing domain expert role, not a software engineering position. We are looking for someone with in-depth knowledge of specific GRC domains who can serve as the ultimate compliance authority.
You will own the customer relationship post-sale, leading transformations and implementations. Because you will be interacting heavily with CISOs and VPs of Risk, you must be exceptionally structured in your communication and highly skilled at managing relationships. You will set clear success goals with every customer, drive engagements toward those milestones with urgency, and know exactly when you have landed the outcome you both committed to.
In addition to your customer-facing responsibilities, you will be the GRC depth behind our products. Everything you learn in the field driving implementations will directly shape what Zania builds, ensuring our AI agents behave accurately from a practitioner's standpoint.
WHAT YOU'LL DO
- Drive post-sale transformations: Lead implementations for enterprise customers from scoping and configuration through to a defined go-live. You are a closer who doesn't let engagements drift.
- Manage senior relationships: Act as the primary customer-facing GRC expert. Communicate in a highly structured way to build trust, manage expectations, and align with executive stakeholders (CISOs, VPs of Risk).
- Apply in-depth GRC methodology: Provide deep expertise in specific risk and compliance domains. When customers ask complex questions about control mappings or frameworks, you answer with precision and credibility.
- Shape product decisions: Translate what you hear during customer implementations into a prioritized, opinionated point of view for our product team.
- Ensure GRC accuracy: When an agent's output falls short of what a practitioner would accept, diagnose why from a GRC standpoint and define the fix.
REPRESENTATIVE PROJECTS
- Kick off a new enterprise engagement by running a structured goal-setting session with the customer's CISO and GRC lead, defining measurable success outcomes for their post-sale transformation.
- Sit with a Fortune 500 CISO and their GRC lead to work through how Zania maps to their existing control framework, driving their implementation forward.
- Run a structured review of agent output across real customer assessments, leveraging your deep domain expertise to identify failure patterns for the engineering team.
WHAT YOU HAVE
- Deep GRC Expertise (Depth, not exposure): 5+ years of in-depth knowledge in specific risk and compliance domains, security compliance, or IT audit, with real ownership of programs.
- Non-technical domain mastery: You are an expert in GRC methodologies, not software development. You have direct professional experience applying at least two major compliance or risk frameworks (e.g., SOC 2, ISO 27001, NIST CSF, FedRAMP, HIPAA, PCI-DSS).
- Relationship Management: Executive presence and a proven ability to own relationships with senior security and risk stakeholders. You are comfortable presenting, advising, and pushing back when needed.
- Structured Communication: You are highly organized and can translate complex GRC concepts into clear, structured communication for both customers and internal teams.
- A closer's instinct: You drive post-sale implementations toward success with urgency, bringing customers to a clear finish line.
MINIMUM QUALIFICATIONS
- Bachelor's degree in Information Security, Business, Risk Management, or a related field, or equivalent practical experience.
- 5+ years of hands-on, non-technical experience as an expert in GRC, information security compliance, risk management, or IT audit.
- Direct professional experience applying major compliance or risk frameworks (e.g., SOC 2, ISO 27001, NIST CSF, FedRAMP, HIPAA, PCI-DSS) or recognized third-party risk methodologies.
- Proven track record in a customer-facing role driving transformations, implementations, or complex post-sales engagements.
- Strong structured written and verbal communication skills, with the ability to command a room and earn trust with executive leadership.
NICE TO HAVE
- Experience at a Big 4 or Tier 2 advisory firm (risk advisory, internal audit, or cyber practice).
- In-house GRC experience at a company that was regularly audited or assessed.
- Hands-on use of GRC platforms such as Archer, OneTrust, AuditBoard, LogicGate, or ServiceNow IRM.
- Prior customer success, implementation, or consulting experience.
COMPENSATION & BENEFITS
- Competitive salary + significant equity
- Flexible PTO
- Medical, dental, and vision insurance
- Meals and snacks in the office
- Relocation and immigration support
Zania is an equal opportunity employer and does not discriminate on the basis of race, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition, or any other basis protected by law.