Remote job
Program Manager, Security GRC
Job details
About this role
Role overview This role leads program management for a Security Governance, Risk, and Compliance (GRC) function in a fully remote setting. The position partners closely with engineering, security, legal, and business stakeholders to mature the organization's control environment and keep risk and compliance programs operating at scale. It is a senior, cross-functional role suited to someone who enjoys turning regulatory and security obligations into durable, well-run programs.
Responsibilities - Drive the planning, execution, and reporting cadence for security GRC programs and initiatives - Coordinate risk assessments, control testing, and remediation workflows across multiple teams - Support audits and external assessments by managing evidence collection, walkthroughs, and follow-ups - Maintain and improve policies, standards, and procedures that reflect current frameworks and business needs - Track program metrics, surface risks and blockers early, and communicate status to leadership and partners - Partner with security and engineering owners to ensure controls are implemented effectively and sustainably
Requirements - Demonstrated experience running security, GRC, or risk and compliance programs in a complex organization - Familiarity with common security and privacy frameworks such as SOC 2, ISO 27001, PCI DSS, or similar - Strong program management skills, including planning, dependency tracking, and stakeholder communication - Ability to translate technical and regulatory concepts into clear guidance for non-technical audiences - Comfort operating independently in a remote environment and managing multiple workstreams