
Lead GRC, Security Governance
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in United States.
• Develop and manage Dave’s technology governance program that encompasses technology and cyber risk, IT controls, change management, incident management, business continuity, and policies.
• Create and maintain the technology control inventory, which includes owners, evidence requirements, operating cadence, exceptions, and escalation paths.
• Oversee technology assurance and audit readiness for SOX ITGC, PCI, SOC 2, and other relevant frameworks.
• Coordinate evidence gathering, support testing, identify gaps, and ensure accountability for remediation until completion.
• Manage the technology and cyber risk register along with the control exception process.
• Highlight significant or ongoing risks with context and suggestions, particularly in cases of resistance to escalation.
• Govern change management, incident management, and business continuity processes.
• Leverage AI and automation to enhance evidence analysis, control mapping, policy maintenance, risk reporting, audit preparation, and remediation tracking, while ensuring human review and data protection measures are in place.
• Collaborate with Security, IT, Engineering, Data, Internal Audit, Legal, Compliance, and external assessors.
• Report directly to the Sr. Director, Security & IT.
• Over 8 years of relevant technology experience, with substantial ownership in security governance, technology risk, or security assurance.
• Successfully led a SOC 2 Type II, ISO 27001, or similar audit to a positive conclusion.
• Developed or significantly restructured a governance, risk, or assurance operating model.
• Strong technical knowledge in areas such as cloud, identity, CI/CD, source control, endpoints, networks, and data platforms.
• Capability to convert ambiguous expectations into clear, testable controls and challenge vague responses.
• Experience in taking accountability while allowing technical teams to handle remediation.
• Ability to influence stakeholders in Engineering, SRE, Security, IT, and Data.
• Sound judgment regarding risk and materiality, including the ability to escalate significant risks when there is disagreement among stakeholders.
• Experience collaborating with Internal Audit and Legal teams.
• Excellent written communication and program management abilities.
• Familiarity with SOX ITGC, PCI DSS, NIST-based programs, AI governance or third-party AI risk, and GRC automation platforms like Vanta or Drata is advantageous.
• Must be permanently authorized to work in the United States without requiring visa sponsorship.
• Equity
• Flexible hours
• Virtual-first work culture
• Home office stipend
• Premium Medical, Dental, and Vision Insurance plans
• Generous paid parental and caregiver leave
• 401(k) savings plan with matching contributions
• Financial advisor and financial wellness support
• Flexible PTO
• Generous company holidays, including Juneteenth and Winter Break
• All-company in-person events once or twice a year
• Virtual events throughout the year to connect with team members and leadership
TAG IMF
Neogen Corporation
Parexel
Stone & Company
Get handpicked remote jobs straight to your inbox weekly.