Back to jobs
New

Product Solutions Owner - Commercial Services

Remote

RegScale is a purpose-built cyber GRC platform designed to enable the CISO to track and monitor security controls. We help organizations break out of the slow and expensive realities that plague legacy GRC tools by bridging security, risk, and compliance through controls lifecycle management. By leveraging RegScale's Continuous Control Monitoring (CCM) instrumentation, organizations experience massive compliance process improvements like 90% faster certification times, and 60% less audit prep time. Today's expansive security and compliance requirements can only be met with a modern, CCM-based approach, and RegScale is the market leader in that space. 

The Role 

RegScale is seeking a Product Solutions Owner, Commercial Solutions to lead our expansion into commercial enterprise markets — spanning industries like financial services, healthcare, and technology. This role is for someone who is fundamentally dissatisfied with how GRC has always been done and is driven to replace legacy, manual compliance programs with modern, automated, AI-powered approaches. 

You are not a requirements gatherer. You are an innovator. You've spent years inside compliance programs, felt the inefficiency firsthand, and now you want to tear it down and rebuild it with better tools. You think creatively about how software and AI can eliminate work that humans shouldn't be doing — and you have the credibility to convince compliance practitioners to trust the new way. 

Reporting to the Chief Product Officer, you'll serve as the solution owner for our commercial verticals. You'll work directly with customers and prospects to understand their scaling challenges, define prescriptive and repeatable workflows that make complex compliance manageable, and validate that our platform delivers real-world impact. The through line of everything you do is tooling innovation: using RegScale's platform and emerging AI capabilities to solve problems that legacy GRC tools have failed to crack for decades. 

Key Responsibilities 

  • Own the commercial product strategy and execution roadmap across key industry verticals including financial services, healthcare, and technology, ensuring alignment with customer needs and market demands. 
  • Serve as the subject matter expert (SME) for commercial Cyber GRC within the RegScale product organization — the go-to voice for how enterprises outside of government manage compliance at scale. 
  • Drive the design of prescriptive, opinionated workflows that guide commercial customers through core compliance tasks — multi-framework management, continuous monitoring, audit response, and risk management — without requiring RegScale or compliance expertise to operate. 
  • Partner with customers and prospects to identify pain points, use cases, and success criteria; synthesize those insights into data-informed product decisions. 
  • Translate customer and market needs into clear, actionable product requirements for engineering and product teams; collaborate closely with Product Management and Engineering on solution design, prioritization, and validation. 
  • Accept product builds for your area — ensuring solutions meet functional expectations and deliver genuine customer value before release. 
  • Be the product org's primary innovator on tooling: constantly asking "how does software and AI eliminate this manual step?" and driving those answers into the platform roadmap. 
  • Lead the integration of AI and automation to fundamentally reimagine — not just incrementally improve — how commercial organizations manage risk and compliance programs at scale. 
  • Work with significant existing and prospective customers to develop public references and case studies that establish RegScale's credibility in commercial markets. 
  • Partner with Sales, Marketing, and Customer Success to enable go-to-market readiness and ensure customers realize value from our solutions. 
  • Represent RegScale at industry events, roundtables, and customer meetings as a trusted expert in commercial GRC. 

What We're Looking For 

  • 10+ years of experience directly managing Governance, Risk, and Compliance programs within commercial enterprises — financial services, healthcare, technology, or similarly regulated environments. 
  • A track record of applying software tooling and AI to modernize compliance programs — you've actually done it, not just recommended it. You know what it takes to move an organization from spreadsheets and email to instrumented, continuous compliance. 
  • Deep, creative instincts for how automation changes what's possible: you don't accept "that's how compliance works" as an answer, and you've built or shaped tools that proved it. 
  • Deep, hands-on familiarity with multi-framework compliance programs (e.g., NIST CSF, ISO 27001, PCI-DSS, HIPAA, SOC 2, HITRUST) and the operational complexity of running them simultaneously. 
  • Proven ability to translate complex compliance requirements into actionable processes and technical requirements that non-experts can execute. 
  • Experience scaling compliance programs through tooling and automation — you understand what it takes to go from manual, spreadsheet-driven programs to instrumented, continuous compliance. 
  • Strong instincts for workflow design and customer experience — you've felt the friction of poor GRC tooling firsthand, you have strong opinions about how to fix it, and you've been frustrated enough to do something about it. 
  • Experience collaborating cross-functionally across business, product, and technology teams. 
  • Strong communicator — equally comfortable with executive stakeholders, technical contributors, compliance practitioners, and external audiences. 
  • Passion for innovation and a genuine desire to modernize how enterprises approach compliance. 

Bonus Points For 

  • Prior experience in a product, solution management, or consulting role within a SaaS or software company. 
  • Familiarity with CCM, automation, or continuous compliance platforms. 
  • Experience driving commercial go-to-market motions for technical products in regulated industries. 
  • Thought leadership or market presence in the GRC space (speaking, writing, community participation). 

Create a Job Alert

Interested in building your career at RegScale? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in RegScale’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.