
Manager, Governance, Risk & Compliance
Posted 6 days ago

Posted 6 days ago
This is a fully remote position, open to applicants in Ohio.
• Take ownership and enhance MRI's GRC framework, which encompasses policies, procedures, internal controls, and documentation of risk appetite.
• Facilitate enterprise-wide risk assessments while collaborating with Engineering, Product, IT, and various business units to identify, evaluate, and mitigate risks.
• Stay updated on regulatory changes and translate these developments into practical compliance strategies.
• Lead efforts for SOC 2, ISO 27001, PCI-DSS, and other compliance certifications.
• Oversee internal and external audit processes from the planning phase through to remediation.
• Design and implement compliance training programs.
• Create and present executive-level dashboards, metrics, and reports on risk and compliance.
• Manage third-party risk, including vendor security assessments, contract risk reviews, due diligence, and supplier monitoring.
• Lead incident response and investigations related to compliance breaches or policy violations.
• Mentor and manage GRC analysts and specialists.
• Foster relationships throughout the organization to make compliance more accessible and practical.
• Collaborate with Legal, Sales, InfoSec, and Customer Success on security questionnaires, RFP responses, and due diligence requests.
• Report directly to the SVP of Legal and Compliance and play a role in strategic business decisions.
• A Bachelor's degree in information security, business, law, or a closely related field.
• Over 8 years of progressive experience in governance, risk, compliance, information security, or internal audit.
• A minimum of 4 years of management or leadership experience.
• Proficiency in NIST, SOC 2, ISO 27001, NIST CSF, PCI, and other relevant regulatory frameworks and standards.
• Experience within the SaaS or technology industry is essential.
• An active professional certification is required: CISA, CRISC, CISSP, CIPP, CCEP, or an equivalent certification.
• Demonstrated experience in building, scaling, and enhancing GRC programs in rapidly growing technology settings.
• Exceptional communication skills with the capability to explain complex compliance requirements to both technical and non-technical audiences.
• Practical experience implementing and optimizing GRC platforms such as Jira, BitSight, OneTrust, Archer, LogicGate, Vanta, or Drata.
• Experience managing customer-facing compliance tasks, security questionnaires, audits, and supporting enterprise sales.
• Strong business acumen with the ability to balance risk mitigation with business enablement.
• An advanced degree (MBA or Master's in Cybersecurity/Risk Management) is highly preferred.
• Additional professional certifications are preferred.
• Employee-led resource groups.
• 16 additional hours of time off through the Flex at MRI program.
• 16 hours of paid volunteer time.
• Employee referral program.
• Region-specific healthcare benefits for employees and their families.
• Parental Leave and related parental support perks.
• Paid time off days in addition to observed holidays.
• Tuition reimbursement opportunities.
• Flexibility to work from anywhere in the world for two weeks each year.
ICON plc
US Anesthesia Partners
MultiplyMii
Paychex
Get handpicked remote jobs straight to your inbox weekly.