706 grc manager jobs at 483 companies in United States
1mo
Save
Mark Applied
Hide
1mo
GRC Manager
Toronto or New York City
RemoteFull Time
Valence: Enterprise AI coaching platform helping companies provide personalized guidance to managers and employees.
Experienced in running GRC and security compliance programs (SOC 2, ISO 27001, ISO 42001), audit coordination, risk management, cloud security (AWS/Azure), and cross-functional stakeholder collaboration.
SOC 2, ISO 27001, ISO 42001, NIST CSF, GDPR, EU AI Act, AWS, Azure, Vanta, Drata, Secureframe, OneTrust, Archer
Baseten: Private AI infrastructure provider that trains, deploys, and serves artificial-intelligence models for businesses.
5+ YOE5+ years GRC or security compliance experience in SaaS/cloud; strong knowledge of SOC 2, ISO 27001, NIST, GDPR; audit and certification management; third-party risk and cross-functional collaboration.
RPG Group: A diversified Indian conglomerate with operations in infrastructure, automotive, and IT.
Administer SAP GRC and users, design and maintain SAP security roles, manage authorizations, workflows, risk analysis, segregation of duties, audits, and compliance issues.
North Carolina or Wisconsin or Alaska or West Virginia or Washington or Virginia or Vermont or Utah or Texas or Tennessee or South Dakota or South Carolina or Rhode Island or Pennsylvania or Oregon or Oklahoma or Ohio or North Dakota or New York or New Mexico or New Jersey or New Hampshire or Nevada or Nebraska or Montana or Mississippi or Minnesota or Michigan or Massachusetts or Maryland or Maine or Louisiana or Kentucky or Kansas or Iowa or Indiana or Illinois or Idaho or Georgia or Florida or Delaware or Connecticut or Colorado or California or Arkansas or Arizona or Alabama or Missouri or Wyoming or United States
$130k-$150k/yrRemoteFull Time
Harris Computer: Global provider of mission-critical vertical market software solutions.
5+ YOERequires 5+ years in GRC, IT compliance, or information security compliance; hands-on security program experience; knowledge of HIPAA, SOC 2, HITRUST, or GDPR; auditor and technical organization experience.
North Carolina or Wisconsin or Alaska or West Virginia or Washington or Virginia or Vermont or Utah or Texas or Tennessee or South Dakota or South Carolina or Rhode Island or Pennsylvania or Oregon or Oklahoma or Ohio or North Dakota or New York or New Mexico or New Jersey or New Hampshire or Nevada or Nebraska or Montana or Mississippi or Minnesota or Michigan or Massachusetts or Maryland or Maine or Louisiana or Kentucky or Kansas or Iowa or Indiana or Illinois or Idaho or Georgia or Florida or Delaware or Connecticut or Colorado or California or Arkansas or Arizona or Alabama or Missouri or Wyoming
$130k-$150k/yrRemoteFull Time
Harris Computer: Global provider of mission-critical vertical market software solutions.
5+ YOE5+ years in GRC, IT compliance, or information security compliance; hands-on compliance program experience; knowledge of HIPAA, SOC 2, HITRUST, or GDPR; auditor experience and strong technical writing skills.
Ripple: Enables institutions to move, manage, and tokenize value.
5+ YOE5+ years in GRC or customer security assurance; experience with security questionnaires, information security frameworks, financial services regulations, customer engagements, and GRC or security assurance platforms.
SIG, CAIQ, SOC 2, ISO 27001, NIST, SWIFT, SafeBase, Vanta, Drata, LogiGate, GDPR, CCPA, DORA
Lendistry: Minority-led CDFI fintech lender providing loans and grant programs to underserved small businesses nationwide.
3+ YOE3-5 years in GRC, data privacy, risk management; SOC 2 and GLBA; cloud experience (AWS/Azure); privacy engineering; CIPT/CDPSE required; CIPM/CISSP preferred; B.S. in CS/Info Security or equivalent.
Budapest or New York City or Washington or Vancouver or London or Galway or Munich or Bengaluru or Singapore or Sydney
HybridFull Time
Diligent: Private GRC SaaS providing governance, risk, compliance, audit, and ESG software to boards and organizational leaders.
Experience delivering projects for enterprise customers in complex technical or regulatory environments, with strong communication, project management, stakeholder coordination, and customer enablement skills.
AI, SaaS, large language models, LinkedIn, Facebook
SHEIN: Private global online fashion and lifestyle retailer serving consumers with affordable apparel and everyday products.
7+ YOE7+ years in information security risk management; bachelor’s degree; CISSP/CISM/CISA or ISO 27001 Lead Auditor desirable; strong standards knowledge; team leadership experience.
Mattermost: Private open-source collaboration software serving national security, government, and critical infrastructure teams.
Owner of governance, risk, and compliance programs with federal and commercial experience; familiarity with NIST, CMMC, ISO 27001, SOC 2, third-party risk, and cloud security; strong communication and program leadership.
Claude, OpenAI, Gemini, Vanta, Drata, AWS, GCP, Azure, Microsoft Teams, Outlook, Microsoft 365
United States or Massachusetts or New York or California or Colorado
$70k-$88k/yrRemoteFull Time
Coretelligent: Managed IT and cybersecurity services provider serving small, midsized, and highly regulated businesses across the United States.
3+ YOERequires 3+ years in GRC focused on IT or cybersecurity controls, or 3+ years in IT with a cybersecurity focus, plus analytical, organizational, communication, and project management skills.
Vercel: Software providing developer infrastructure for teams building web applications and AI agents.
3+ YOE3+ years supporting audit lifecycle in cloud environments; manage ISO/SOC/HIPAA/PCI compliance, collaborate with engineering, strong project management and communication; familiarity with cloud and GRC tools.
American TowerNYSE: AMT: Public U.S. REIT that owns, operates, and leases wireless towers, communications sites, and data centers to connectivity providers.
2+ YOERequires 2+ years in GRC or information security, strong project management and communication skills, Microsoft Office and Oracle proficiency, and knowledge of security standards and privacy regulations.
Microsoft Office, Oracle, ISO 27001, ISO 27002, ITIL, Identity and Access Management (IAM)
The Japan Research Institute, Limited: Japanese knowledge-engineering providing IT systems, consulting, economic research, and policy recommendations to businesses and governments.
5+ YOEBachelor's in IT/InfoSec,5+ years IT audit/assurance experience,knowledge of IT controls,regulations and frameworks;strong communication,analytical and project management skills.
ConcentraNYSE: CON: The nation’s leading occupational health care.
8+ YOEBachelor's degree in Computer Science or Information Security; 8–10 years risk management experience; 3–4 years project management; GRC, audits, TPRM, privacy frameworks, and stakeholder leadership experience.
GRC, SOX, SOC2 Type 2, PCI, NIST, HIPAA, SaaS, TPRM
Velera: Credit-union-owned payments CUSO and fintech provider serving more than 4,000 financial institutions.
10+ YOEBachelor's degree or equivalent experience; 10+ years as a DBA or GRC Engineer; database compliance, security GRC, program management, control automation, stakeholder collaboration, and AI solutions experience.
NorthMark Compute & Cloud: Private U.S. high-performance computing infrastructure provider serving businesses with HPC, cloud, AI, and simulation capacity.
4+ YOE4+ years GRC or information security governance experience; hands-on change management, risk assessment, policy management; familiarity with ISO 27001/SOC 2/NIST CSF; stakeholder engagement and strong written communication.
NextrackerNASDAQ: NXT: Solar tracker and energy technology platform for utility-scale power plants.
10+ YOE5+ MgmtBachelor’s degree and 10+ years in GRC, information security, audit, or risk management; 5+ years leading complex programs; ISO 27001 experience and strong risk, audit, policy, and executive communication skills.