
Manager, Governance, Risk & Compliance
Posted 11 hours ago

Posted 11 hours ago
This is a fully remote position, open to applicants in United States.
• Develop and implement a multi-year Governance, Risk, and Compliance (GRC) strategy and roadmap; establish priorities, budget, tools, KPIs, and report on program health, risk posture, and audit readiness to the Chief Information Security Officer (CISO) and executive leadership.
• Recruit, manage, mentor, and cultivate a team of GRC analysts; set objectives and career trajectories, conduct performance evaluations, assign framework and workstream responsibilities, and foster a culture of rigor and continuous improvement.
• Act as the executive owner for SOC 2 Type II, ISO 27001, ISO 27701, ISO 42001, and prospective frameworks; guide audit scoping, readiness evaluations, remediation strategies, evidence collection, auditor relationships, and management review cycles.
• Oversee enterprise and security risk frameworks, risk appetite, risk registers, risk review forums, assessments, escalation processes, remediation efforts, and formal risk acceptance.
• Create a common control framework and continuous monitoring strategy that aligns with ISO, SOC 2, NIST, GDPR/CPRA, PCI, and HIPAA/HITRUST; supervise testing, exceptions, and corrective actions.
• Manage access governance, encompassing access certifications, least-privilege standards, joiner/mover/leaver controls, and privileged access monitoring.
• Establish vendor risk strategies and tiering; supervise due diligence, contractual security and privacy obligations, and the oversight of critical suppliers, partners, and AI service providers.
• Direct customer trust initiatives including security and privacy questionnaires, RFP responses, Trust Center content, and customer-facing security assessments; collaborate with Sales on enterprise contracts.
• Oversee policy and standards lifecycle, security and privacy awareness training, role-based training, and privacy operations including Data Protection Impact Assessments (DPIAs), data mapping, and data subject requests.
• Champion incident response tabletop exercises and business continuity/disaster recovery testing; present executive and board-level dashboards.
• Guide responsible AI governance under ISO 42001 and emerging regulations like the EU AI Act, collaborating with Product and Engineering teams.
• Over 8 years of experience in GRC, security audit, or risk management, including a minimum of 1 year in a managerial role overseeing a GRC or compliance program from start to finish.
• Proven history of hiring, developing, and retaining top-tier GRC professionals, as well as scaling programs and teams through periods of rapid company growth.
• Executive-level accountability for SOC 2 Type II and ISO 27001 programs during multiple certification and surveillance cycles, including scoping, auditor selection, management, and remediation.
• Practical experience with ISO 27701 and ISO 42001 or similar privacy and AI governance frameworks.
• Extensive knowledge of management systems (ISMS/PIMS/AIMS), Trust Services Criteria, common control frameworks, control testing, sampling, and evidence adequacy in cloud-first environments (AWS/Azure/GCP, SaaS).
• Experience in designing and managing enterprise risk management, including risk appetite, risk registers, risk forums, and formal risk acceptance in collaboration with senior leadership.
• Demonstrated capability to conduct access certifications, third-party risk management, and customer security assessments at an enterprise level, along with selecting and implementing GRC tools and automation.
• Exceptional executive communication skills: adept at presenting risk and compliance status to leadership, boards, auditors, and enterprise clients, while translating technical details into business implications.
• Relevant certifications such as CISA, CISSP, CISM, CRISC, ISO 27001 Lead Auditor/Implementer, or CIPP/CIPM are advantageous.
• Competitive salary and performance-based bonuses.
• Comprehensive health, dental, and vision insurance.
• Generous paid time off and flexible working arrangements.
• Opportunities for professional development and certification reimbursement.
• Collaborative and inclusive company culture.
Freudenberg Group
Secfix
Mercor
Lifelancer
Get handpicked remote jobs straight to your inbox weekly.