
Manager, GRC Engineering
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in California.
• Client Relationship Management: Act as the dedicated virtual CISO for a portfolio of clients, fostering deep, trusted relationships while operating with the authority and credibility of an embedded security executive.
• Lead Client Engagements: Direct clients through security program development and compliance initiatives from initial assessment to certification, offering strategic guidance, proactive risk management, and executive-level communication at every milestone.
• Represent Clients on Prospect and Customer Calls: Participate in clients’ sales and due diligence calls as their CISO, addressing technical security inquiries in real-time with precision and confidence.
• Handle Escalations with Professionalism: Address complex client issues and escalations with promptness and composure, taking ownership of decisions and making security judgments independently.
• Be a Trusted Advisor: Gain a deep understanding of each client’s business, technology, risk appetite, and compliance drivers to provide specific, contextualized security advice rather than generic recommendations.
• Maintain Client Mastery: Participate in weekly syncs, review GRC platform results in a business context, monitor architecture changes and upcoming projects, and proactively identify emerging risks before they arise in routine discussions.
• Provide Strategic Security Leadership: Develop and maintain a security program roadmap for each client, aligned with their business objectives and relevant compliance frameworks.
• Advise C-suite and board-level stakeholders on security posture, risk tolerance, and investment priorities.
• Lead Risk & Compliance Oversight: Oversee risk assessments, risk register development, and treatment planning. Assist clients with SOC 2 (Type I/II), ISO 27001, ISO 42001, HIPAA, CMMC, NIST CSF/800-171, GDPR, CCPA, DORA, NYDFS, and other applicable frameworks.
• Develop Client Security Programs: Create and enhance security programs for early-stage clients and optimize existing programs for more mature organizations.
• Create customized policies, controls, and compliance roadmaps that reflect each client’s specific technology and business model.
• Deliver Advanced Security Strategy: Produce architecture recommendation memoranda that include trade-off analyses, vulnerability disclosure assessments, threat modeling exercises, and executive security briefings.
• Assist with security hire interviews, contract reviews, and bug bounty SOP development.
• Monitor Regulatory Developments: Stay updated on evolving regulations and frameworks to ensure compliance controls remain relevant and accurate.
• Manage Compliance Operations: Conduct quarterly access reviews, annual penetration testing engagements, and annual tabletop exercises for incident response and business continuity.
• Utilize GRC platforms like Vanta, Drata, and SecureFrame to ensure continuous audit readiness.
• Manage and Develop a Pod of Analysts: Lead a team of 3–5 analysts through coaching, mentoring, and performance management, fostering accountability, quality, and professional growth.
• Drive Consistent Delivery: Ensure the team meets deadlines and delivers high-quality work across all active client engagements, providing support where necessary.
• Contribute to Practice Development: Refine vCISO playbooks, templates, and service delivery standards to enhance consistency and quality across the practice.
• Mentor and Support Team Members: Coach junior team members, share domain expertise, and contribute to a culture of continuous learning.
• Support Pre-Sales: Engage in pre-sales discussions to scope vCISO engagements and assist in proposal development.
• 8+ years of experience in information security, with a minimum of 3 years in a senior security leadership role.
• Proven experience managing client relationships directly; comfortable taking ownership of accounts, leading challenging conversations, and serving as the trusted representative of a security engagement.
• Ability to communicate fluently and specifically about security architecture, compliance status, and control trade-offs during high-stakes client and prospect discussions.
• In-depth working knowledge of security frameworks, including SOC 2, ISO 27001, NIST CSF, HIPAA, HITRUST, NIST SP 800-171, and/or CMMC.
• Demonstrated experience managing multiple security programs or client engagements simultaneously (consulting, fractional, or advisory background preferred).
• Exceptional written and verbal English communication skills; able to convey technical risks in business terms without sacrificing precision.
• Independent decision-making capability: you are responsible for your client portfolio and make security decisions without needing approval for every judgment call.
• Strong understanding of technical control implementation in cloud platforms (AWS, GCP, Azure).
• Career Development: Defined career path with mentorship and training opportunities.
• Technical Training: Comprehensive onboarding on security and compliance frameworks.
• Competitive Compensation: Attractive base salary with regular performance reviews tied to merit-based appraisals and bonus opportunities.
• Growth Opportunity: Early-stage company offering substantial potential for career advancement.
• Remote-First Culture: Flexibility to work from anywhere while collaborating with a global team.
• Work Environment Requirements: Reliable high-speed internet connection. Quiet, professional home office setup. Must be willing to work US Time zone hours. Proficiency in written and verbal English communication skills.
Twilio
Firstup
Weekday (YC W21)
Instacart
Get handpicked remote jobs straight to your inbox weekly.