Loading_
Security is the promise. I make sure it's kept.

Harlin Lipman

I am a

/ About Me

Harlin Lipman
Security GRC Leader

Cybersecurity GRC professional with 10+ years of experience building and scaling governance, risk, and compliance programmes at high-growth SaaS companies. I specialise in translating complex regulatory requirements into pragmatic security frameworks that enable business rather than slow it down.

From early-stage startups to NYSE-listed companies, I've led SOC 2, ISO 27001, FedRAMP, and PCI DSS programmes — and built the teams, tooling, and culture to sustain them.

LocationUnited States
CurrentTines
Blogharlin.io
Connect on LinkedIn
Harlin Lipman

/ Education

University of Minnesota
2020 – 2023
Master of Business Administration (MBA)
Marquette University
2012 – 2016
Bachelor of Science — Information Technology
Information Technology Student Organization

/ Experience

Staff GRC
Tines · Feb 2026–Present
Senior Manager, InfoSec
Chronosphere · Aug 2022–Feb 2026
Sr. IS Risk Specialist
SentinelOne · Nov 2020–Aug 2022
3rd Party Security Specialist
OnSolve · Aug 2019–Nov 2020
Senior Associate
Schellman · Oct 2018–Sep 2019
SOC Auditor
Sikich · Nov 2017–Nov 2018
Feb 2026 — Present Current
Staff GRC
Tines · Security Automation Platform · Remote

Leading the GRC function at Tines, an AI-powered security workflow automation platform used by security teams at some of the world's most recognisable companies. In this role I own and drive the strategy across four core pillars of the security programme.

  • Lead internal and external audit programmes — coordinating SOC 2 Type 2, ISO 27001, and other compliance assessments end-to-end, from scoping and evidence collection through to audit closure and remediation.
  • Own the vendor risk management programme — developing and maintaining the third-party risk framework, conducting security assessments of critical vendors, and ensuring ongoing supplier due diligence at scale.
  • Drive the privacy programme — ensuring compliance with GDPR, CCPA, and other applicable data protection regulations, partnering with legal and engineering to embed privacy-by-design into product development.
  • Oversee the customer trust programme — managing security questionnaire responses, maintaining the trust portal, and serving as the primary security contact for enterprise and regulated-industry customers.
GRC StrategyAudit ProgramsVendor RiskPrivacyCustomer TrustSOC 2
Aug 2022 — Feb 2026
Senior Manager, Information Security
Chronosphere · Cloud-Native Observability · Remote

Built and scaled Chronosphere's first enterprise security programme from the ground up — growing from Information Security Manager to Senior Manager over 3.5 years — establishing security as a strategic differentiator during high-growth phases.

  • Spearheaded the organisation's SOC 2 program and inaugural ISO 27001 compliance — achieved ISO 27001 certification within 3 months of project start.
  • Implemented and integrated a SIEM and SAST tool, enhancing threat detection, incident response, and code security to mitigate organisational risk.
  • Successfully completed over 150 customer sales requests — questionnaires, documentation, contract reviews, and audits — and introduced a customer trust portal for self-service access.
  • Coordinated security training and awareness across 300 employees, achieving 100% adherence to training requirements.
  • Appointed as Data Protection Officer — ensured GDPR compliance through regular audits and implementing controls to safeguard sensitive data.
  • Advised executive team on defining risk appetite and aligning security investments with business growth priorities and regulatory obligations.
ISO 27001SOC 2GDPR / DPOSIEMTrust PortalRisk Strategy
Nov 2020 — Aug 2022
Senior Information Security Risk Specialist
SentinelOne · AI-Powered Cybersecurity

Led audit and compliance initiatives at SentinelOne during a period of rapid growth and the company's landmark NYSE IPO in 2021.

  • Successfully led the organisation's initial SOC 2 Type 2 audit — conducted internal assessments, remediated control deficiencies, and supervised the external audit stage.
  • Led Common Criteria audit on a critical product enabling potential attainment of $5M+ annual recurring revenue.
  • Guided a global team of 4 specialists dedicated to assisting internal and external audit assessments.
  • Received Outstanding Performance award for commendable accomplishments and leadership qualities.
SOC 2 Type 2Common CriteriaAudit LeadershipRisk Management
Aug 2019 — Nov 2020
Third Party Security & Compliance Specialist
OnSolve · Critical Event Management · Greater Milwaukee

Responded to information security risk assessments from customers and prospects, providing due diligence assurances of OnSolve's security posture.

  • Led maturing of the sales process as it relates to OnSolve's security posture through process improvements, software implementations, and training.
  • Developed and maintained OnSolve's privacy program aligned with GDPR, CCPA, and other applicable regulations.
  • Developed and led the security vendor management program including risk assessments of vendors, software providers, suppliers, and contractors.
  • Assisted in SOC 2, SOC 3, ISO 27001, HIPAA, and FedRAMP audits.
TPRMGDPRCCPASOC 2FedRAMP
Oct 2018 — Sep 2019
Senior Associate
Schellman & Company, LLC · IT Audit & Compliance

Directed preparation, fieldwork, and reporting for SOC 1, 2, and 3, HIPAA, Privacy, and ISO engagements at one of the leading independent IT audit firms in the US.

  • Performed comprehensive workflow audits and process interviews with senior management to align procedures with AICPA SOC control and reporting standards.
  • Expanded involvement to include privacy and GDPR projects, evaluating and augmenting frameworks to optimise testing capacity and efficacy.
  • Supported training and onboarding efforts — educated new hires on workflow and reviewed employee workpapers and deliverables.
SOC 1/2/3HIPAAGDPRISOIT Audit
Nov 2017 — Nov 2018
SOC Auditor
Sikich · Advisory & Accounting Services · Brookfield, WI

Conducted SOC 1, 2, and 3 engagements including planning, fieldwork, and reporting stages across a wide variety of industries.

  • Conducted walkthroughs and process interviews with C-level executives and senior management personnel.
  • Performed IT general control assessments using industry-standard control frameworks across Higher Education, Manufacturing, and Non-Profit sectors.
  • Facilitated the transition of specific methodologies to new control sets, ensuring a seamless conversion.
SOC 1/2/3ITGCIT AuditControls Testing

/ Certifications

/ Publications

📝
Why Most SOC 2 Programmes Fail — And How to Build One That Doesn't

A practical guide to building a SOC 2 programme that goes beyond checkbox compliance and actually reduces risk. Based on lessons from 6 companies and a dozen audit cycles.


Read article →
Vendor Risk at Scale: A Practical TPRM Playbook

How to build a third-party risk programme that scales with your vendor count without adding headcount.


Read →
GRC in the Age of AI: New Risks, Same Principles

How AI tools are changing the threat landscape for compliance teams — and what to do about it.


Read →
From Auditor to Builder: Making the Jump to In-House GRC

What I learned moving from a Big 4-style audit firm to building an internal GRC programme from scratch.


Read →

/ Contact Me

Available for consulting & volunteer work

I'm open to security GRC consulting engagements and volunteer opportunities with mission-driven organisations. Whether you need help with compliance frameworks, risk assessments, or building a security programme from scratch — let's talk.

GRC Consulting Volunteer Work SOC 2 Advisory ISO 27001 Risk Assessments Non-profits
Please complete the captcha before sending.
Message sent! I'll get back to you as quickly as possible.