4+ YOE4+ years GRC or information security governance experience; hands-on change management, risk assessment, policy management; familiarity with ISO 27001/SOC 2/NIST CSF; stakeholder engagement and strong written communication.
New York City or Chicago or Austin or Dallas or Denver or Miami or San Francisco or Seattle
$270k-$290k/yrHybridFull Time
DriveWealth: Provides API-based brokerage infrastructure for fractional stock trading.
15+ YOE15+ years in information security/GRC in regulated financial services; deep SEC/FINRA and global privacy knowledge; hands-on GRC, audit, TPRM, incident response, and executive/board reporting; relevant certifications preferred.
Columbus or Chicago or Detroit or Tupelo or Charlotte or Dallas or Atlanta or Houston or Birmingham
$70k-$140k/yrOnsiteFull Time
HuntingtonNASDAQ: HBAN: Provides regional commercial, consumer, and mortgage banking services.
5+ YOEBachelor's degree or 4+ years equivalent experience, 5+ years software development, and preferably 5+ years in GRC systems. Requires analytical, troubleshooting, communication, and programming skills.
Archer, OpenPages, ProcessUnity, ServiceNow IRM, AWS, Apigee, Linux OS, OpenShift, .NET, C#, Python, Java, Microsoft Office
ConcentraNYSE: CON: Provider of occupational health, urgent care, and physical therapy.
8+ YOE3+ MgmtBachelor’s degree in computer science or information security; 8–10 years in risk management; 3–4 years in project management; GRC, cloud/SaaS, privacy framework, third-party risk, audit, and stakeholder leadership experience.
Fidelity Investments: Provides investment management, retirement planning, and brokerage services.
8+ YOERequires 8+ years supporting Archer 6.x GRC applications and 9 years in information security or IT, with Archer, web technologies, Python, SQL, integrations, and GRC expertise.
NTT DATA: Global provider of IT and business consulting services.
10+ YOE10 years of security experience; hands-on GRC, control assessments, compliance monitoring, audit support, risk management, and systems/network administration; preferred CISSP, GIAC, SSCP, or CEH.
Fidelity Investments: Provides investment management, retirement planning, and brokerage services.
8+ YOE8+ years developing and supporting Archer 6.x GRC applications, 9+ years in information security/IT/GRC, expert risk and compliance knowledge, hands-on Python and SQL, web tech (CSS, JavaScript, jQuery, XML), RESTful API integration, and stakeholder collaboration.
Archer 6.x, CSS, JavaScript, jQuery, XML, Python, SQL, JavaScript Transformer, RESTful APIs, Snowflake, Power BI
McKessonNew York Stock Exchange: MCK: Distributes pharmaceuticals and provides healthcare information technology solutions.
5+ YOEDegree or equivalent, typically 5+ years relevant experience, 3+ years SOX/SOC hands-on experience, combined business and technology experience, strong analysis, stakeholder management, and presentation skills.
New York or Atlanta or Boston or Chicago or Cleveland or Dallas or Detroit or Pittsburgh or Hoboken or Houston or Los Angeles or McLean or Miami or Minneapolis or Charlotte or Philadelphia or Portland or San Francisco or Seattle or North America
$123k-$213k/yrHybridFull Time
EY: Global firm providing audit, tax, and professional consulting services.
3+ YOERequires 3–5+ years of SAP Security/GRC experience, bachelor's degree preferred, SAP implementation expertise, GRC Access Control and IAM experience, U.S. driver's license, passport, and willingness to travel up to 80%.
SAP Application Security, SAP GRC Access Control, S/4HANA, SAP ECC, FIORI, ARIBA, HCM, SuccessFactors, Saviynt, SailPoint, SAP IAG, ServiceNow, HP ALM, BTP, SAC, AI, RPA
Caris Life SciencesNASDAQ: CAI: Provides molecular profiling and AI-driven precision medicine diagnostics.
4+ YOEBachelor's or equivalent experience, 4+ years in information security risk management or third‑party risk, knowledge of HIPAA/SOX/GDPR and NIST/ISO/CIS frameworks, strong communication, analytical skills, and proficiency with Excel/PowerPoint.
Microsoft Excel, Microsoft PowerPoint, Compyl, AuditBoard, RSA Archer, LogicGate, AWS, Azure, GCP
Amynta: Provides specialty insurance, warranty programs, and underwriting management services.
4+ YOE4–7 years in information security, governance, risk and compliance; Bachelor's in Information Systems or related field; strong communication; willing to work in Fort Worth, TX; certifications preferred.
Trace3: Provides IT consulting and technology solutions for enterprise digital transformation.
10+ YOEBachelor’s degree and 10–15 years of security consulting and enterprise security experience required. Expertise in GRC frameworks, risk and control assessments, client advisory, presentations, and security program roadmaps required.
NIST CSF, NIST RMF, NIST 800-53, ISO 27001, ISO 27005, SOC 2, PCI DSS, HIPAA, FFIEC, GLBA, SOX, GDPR, CMMC, EU AI Act, Microsoft PowerPoint
Infor: Provides industry-specific cloud enterprise software for global businesses.
Proven leadership of enterprise cybersecurity GRC programs across multi-cloud SaaS environments, expertise in regulatory frameworks, AI governance, third-party risk, audits, and board-level risk reporting.
Azure, AWS, GCP, ServiceNow IRM, Archer, OneTrust, Drata, Vanta, NIST CSF 2.0, NIST 800-53, ISO 27001, ISO 27701, ISO 42001, SOC 2, PCI DSS, FedRAMP, HIPAA, GDPR, NIST AI RMF, FAIR, SBOM
Chicago or Dallas or New York or United Kingdom or Europe or Asia or North America
$120k/yrRemoteFull Time
ECI: Provider of managed IT, cybersecurity, and cloud solutions for finance.
8+ YOEApproximately 8 years in cybersecurity, risk management, or IT governance; relevant bachelor's degree or equivalent experience; security assessments, audits, risk analysis, regulatory frameworks, and stakeholder communication.
NIST CSF 2.0, CMMC, GDPR, Data Protection Act 2018, ISO 27001, NIST, CIS, CIS Controls, COBIT, Microsoft, Cisco, IAM, O365 admin center
LennarNYSE: LEN: Builds and sells quality residential homes across the United States.
7+ YOEBachelor's degree in computer science, information security, or related field; 7+ years cybersecurity experience; leadership, GRC, vulnerability management, incident response, and advanced certifications required.
GRC, PCI, FFIEC, Sarbanes-Oxley Act (SOX), HIPAA, GDPR, GLBA, ISO 17799, ITIL, NIST, Factor Analysis of Information Risk (FAIR)
Vanguard: Global investment management and financial services provider.
5+ YOEFive years of information security or fraud experience, undergraduate degree or equivalent, expertise in NIST, CIS Controls, ISO 27002, GRC platforms, automation, and financial services cyber regulations.
ATINYSE: ATI: Manufactures specialty materials and metal components for aerospace and defense.
3+ YOEBachelor's in Accounting/Finance, 3+ years audit/accounting experience, knowledge of SOX 404 and auditing standards, proficiency with Microsoft Excel/Word/PowerPoint, AuditBoard/GRC and data analytics experience preferred, professional certifications (CPA/CIA/CISA) preferred.
AuditBoard, GRC platforms, data analytics tools, Microsoft Excel, Microsoft Word, Microsoft PowerPoint
Senior Analyst, IT Internal Controls & SOX Compliance
San Francisco or Salt Lake City or Phoenix or Los Angeles or Chicago or Boston or Austin or New York City or Miami or Tampa or Atlanta or Columbus or Boise or San Diego or Minneapolis or Houston or Raleigh or Nashville or Kansas City or Charlotte or Portland or Philadelphia or Dallas or Washington D.C. or Seattle
$113k-$148k/yrRemoteFull Time
CircleNYSE: CRCL: Digital currency issuer and blockchain financial infrastructure provider.
4+ YOE4+ years Big 4 IT audit/controls experience, Bachelor's in related field, CPA/CISA/CIA/CISSP required; strong SOX/ITGC knowledge, cloud/SaaS/SDLC/IAM experience, ERP/GRC familiarity, and stakeholder communication skills.
Slack, Apple MacOS, Google Workspace, ERP, GRC, AI
Denver or Stamford or Washington or Orlando or Tampa or Atlanta or Chicago or Boston or Minneapolis or Charlotte or Short Hills or New York City or Philadelphia or Dallas or Houston or McLean
FieldFull Time
KPMG: Global professional services network providing audit, tax, and advisory.
3+ YOERequires 3+ years in SAP audit, controls, security, GRC, ERP implementation, or transformation; bachelor's degree; SAP GRC and security experience; and strong communication skills.