Remote job
Manager, Governance, Risk & Compliance
Job details
About this role
Role overview A leadership role owning an enterprise Governance, Risk, and Compliance (GRC) program end to end. The position combines people management, strategic program ownership, and executive-level engagement with auditors, customers, and cross-functional partners across security, engineering, IT, legal, people, finance, and sales.
Responsibilities - Define and execute a multi-year GRC strategy and roadmap, including priorities, budget, tooling, KPIs, and reporting on program health and audit readiness to executive leadership. - Hire, manage, coach, and develop a team of GRC analysts, setting goals, career paths, and a culture of rigor and continuous improvement. - Serve as executive owner of SOC 2 Type II, ISO 27001, ISO 27701, and ISO 42001, directing audit scoping, readiness, remediation, evidence strategy, and management reviews for ISMS, PIMS, and AIMS. - Run enterprise and security risk management: own the risk framework, appetite, and register; chair risk forums; and oversee system, vendor, and AI risk assessments through to formal acceptance. - Design a common control framework and continuous-monitoring approach mapping ISO, SOC 2, NIST, GDPR/CPRA, PCI, and HIPAA/HITRUST; oversee control testing and corrective action. - Lead third-party risk management, customer trust (questionnaires, RFPs, Trust Center content), access governance, policy lifecycle, privacy operations, incident response tabletop exercises, and BC/DR testing. - Shape responsible AI governance in line with ISO 42001 and emerging regulation, partnering with product and engineering to embed controls into AI systems.
Requirements - 8+ years in GRC, security audit, or risk management, with at least 1 year managing people and owning a GRC program end to end. - Track record scaling a program and team through rapid company growth. - Executive-level ownership of SOC 2 Type II and ISO 27001 across multiple certification and surveillance cycles, including scoping, auditor management, and remediation. - Hands-on experience with ISO 27701 and ISO 42001, or equivalent privacy and AI governance programs. - Deep command of management systems (ISMS/PIMS/AIMS), Trust Services Criteria, common control frameworks, control testing, sampling, and evidence sufficiency in cloud-first environments (AWS/Azure/GCP, SaaS). - Experience designing enterprise risk management, including appetite, registers, forums, and formal risk acceptance with senior leadership. - Proven ability to run access certifications, third-party risk management, and customer security reviews at enterprise scale. - Strong executive communication skills, comfortable presenting to leadership, boards, auditors, and enterprise customers.
Nice to have Relevant certifications such as CISA, CISSP, CISM, CRISC, ISO 27001 Lead Auditor/Implementer, or CIPP/CIPM.
Benefits and work setup Salary range: $170,000–$190,000 USD.