Baseten: Scalable infrastructure platform for deploying and serving AI models.
5+ YOE5+ years GRC or security compliance experience in SaaS/cloud; strong knowledge of SOC 2, ISO 27001, NIST, GDPR; audit and certification management; third-party risk and cross-functional collaboration.
OpenAI: Develops artificial intelligence models and generative AI software services.
Experienced GRC/product assurance professional with product launch review, customer trust, and security compliance experience; able to build operating models, automation, metrics, and clear customer-facing security narratives.
New York City or Chicago or Austin or Dallas or Denver or Miami or San Francisco or Seattle
$270k-$290k/yrHybridFull Time
DriveWealth: Provides API-based brokerage infrastructure for fractional stock trading.
15+ YOE15+ years in information security/GRC in regulated financial services; deep SEC/FINRA and global privacy knowledge; hands-on GRC, audit, TPRM, incident response, and executive/board reporting; relevant certifications preferred.
United States or San Francisco or New York City or Bengaluru
$150k-$200k/yrHybridFull Time
Mesh: Connecting digital wallets and exchanges for unified cryptocurrency payments.
5+ YOERequires 5+ years of hands-on GRC experience, compliance program management, major security framework familiarity, business continuity and disaster recovery experience, risk lifecycle expertise, and scalable process-building skills.
Sierra: Conversational AI platform for building enterprise customer agents
10+ YOE3+ Mgmt10+ years in compliance/security/customer trust, 3+ years building/scaling customer-facing security programs, experience with regulated industries, knowledge of security frameworks and multi-cloud, and experience implementing trust automation platforms.
NIST 800-53, SOC 2, ISO 27001, PCI DSS, HIPAA, AWS, GCP, GDPR, UK GDPR, EU AI Act, SIG, CAIQ, ISO 42001, NIST AI RMF, CRM
Cyber - SAP Security and GRC Access & Process Control Manager
San Francisco, California, United States
$135k-$265k/yrHybridFull Time
Deloitte: Provides professional audit, consulting, tax, and advisory services.
8+ YOE8+ years in SAP S/4HANA security and GRC; hands-on SAP security design, deployment, and implementation across S/4HANA, Fiori, Ariba, IBP, BTP, and BDC; prior SAP GRC ARA/ARM/EAM/BRM experience; travel ~50%.
SAP S/4HANA, Fiori, Ariba, Integrated Business Planning (IBP), Business Technology Platform (BTP), Business Data Cloud (BDC), GRC Access Control, GRC Process Control, Access Risk Analysis (ARA), Access Request Management (ARM), Emergency Access Management (EAM), BRM, NextLabs, Onapsis, CISSP, CISM, CISA
San Francisco or New York City or London or Sydney
$190k-$215k/yrOnsiteFull Time
Sigma Computing: Cloud-native analytics platform featuring a spreadsheet-style interface.
4+ YOE4+ years GRC experience in SaaS/tech, proven track record building GRC programs and leading SOC 2/ISO 27001/HIPAA audits, experience with ERM frameworks (COSO, ISO 31000, NIST RMF), data privacy (GDPR/CCPA), policy and control development, strong communication.
Risk Consulting - Risk Technology - Oracle GRC - Manager (New York, NY, US, 10001-8604)
New York or Atlanta or Boston or Chicago or Cleveland or Dallas or Detroit or Pittsburgh or Hoboken or Houston or Los Angeles or McLean or Miami or Minneapolis or North Carolina or Philadelphia or Portland or San Francisco or Seattle or Tampa
$150k-$260k/yrHybridFull Time
EY: Global firm providing audit, tax, and professional consulting services.
5+ YOEBachelor's or master's degree with ~5 years related experience; Oracle security/controls and controls testing experience; strong project management, client service, leadership, communication, analytical skills; valid US driver’s license and passport; willing to travel.
Chicago or Miami or Tampa or Los Angeles or Boston or Cleveland or New York City or Florham Park or San Diego or San Francisco or Philadelphia or Houston
$124k-$280k/yrFieldFull Time
PwC: Providing audit, tax, and management consulting services to businesses.
7+ YOEBachelor’s degree and 7+ years of experience; GRC technology proficiency, ISO/IEC 27001, NIST CSF, compliance programs, risk assessments, data analysis, and team leadership.
Ivo: AI-powered contract review and intelligence platform for legal teams.
3+ YOE3–5 years GRC/InfoSec/IT audit experience; hands-on SOC 2 Type II, ISO 27001, CSA STAR, ISO/IEC 42001; experience with Vanta, audits, evidence management, risk assessments, policy maintenance, and strong communication skills.
New York or Atlanta or Boston or Chicago or Cleveland or Dallas or Detroit or Pittsburgh or Hoboken or Houston or Los Angeles or McLean or Miami or Minneapolis or North Carolina or Philadelphia or Portland or San Francisco or Seattle or Tampa
$150k-$260k/yrHybridFull Time
EY: Provides audit, tax, consulting, and strategy services globally.
4+ YOEBachelor's degree plus 5 years or master's degree plus 4 years implementing ServiceNow IRM, TPRM, or BCM solutions; ServiceNow CSA and GRC certification required; project leadership and client-facing consulting experience.
ServiceNow IRM, Archer, AuditBoard, Microsoft PowerPoint, Microsoft Word, Microsoft Excel, Microsoft Visio, Integration Hub, API, Waterfall, Agile, REST, SOAP, Spotfire, PowerBI, Tableau, OneTrust, AI
United States or Canada or Columbus or Austin or San Francisco or New York City
$172k-$238k/yrRemoteFull Time
UpstartNasdaq: UPST: AI-powered lending marketplace for consumer and automotive loans.
8+ YOE3+ MgmtBachelor's or equivalent, 8+ years technology risk/information security/IT audit experience in banking, 3+ years people management, FFIEC/OCC regulatory experience, regulator engagement, and GRC program experience; professional certs preferred.
UberNYSE: UBER: A technology platform for transportation, delivery, and freight.
7+ YOERequires 7+ years in technical program management or software development leadership, technical systems expertise, KPI and budget ownership, software lifecycle experience, and a bachelor's degree or equivalent experience.
PenumbraNYSE: PEN: Designs and manufactures medical devices for vascular conditions.
8+ YOEBachelor's in accounting or information systems, 8+ years in IT SOX compliance/InfoSec/IT risk, experience with SOX 404, ITGCs/ITACs, SAP and GRC platforms preferred, strong communication and problem-solving skills.
DocuSignNASDAQ: DOCU: Provides electronic signature and agreement management software solutions.
8+ YOE8+ years in security risk management/GRC, bachelor’s in CS/InfoSec, experience with cloud (AWS/Azure/GCP), GRC platforms, risk quantification (FAIR), and security domain expertise; CISSP/CRISC/CISM preferred.
AWS, Azure, GCP, ServiceNow IRM, OneTrust, FAIR, Tableau, Power BI
5+ YOE5+ years in security operations/GRC/IT security, SOC 2 familiarity, incident response, endpoint and access controls, vendor and MSP management, strong communication and independent execution.
15+ YOE15+ years in risk operations, compliance, internal audit or information security with leadership experience; experience building controls assurance, third-party risk, incident response, and AI safety; familiarity with auditors/regulators and GRC platforms.
Parafin: Embedded financial infrastructure for small business platforms.
3+ YOE3+ years compliance or business banking experience; familiarity with vendor management, SOC1/SOC2, risk/GRC processes; strong communication and multi-tasking; experience with BSA/AML/OFAC/KYC and bank partners preferred.
DocuSignNASDAQ: DOCU: Provider of e-signature and intelligent agreement management software.
8+ YOE8+ years in security risk/GRC, Bachelor's in CS/InfoSec, experience with cloud (AWS/Azure/GCP), GRC platforms, risk quantification (FAIR), and strong communication; CISSP/CRISC/CISM preferred.
AWS, Azure, GCP, ServiceNow IRM, OneTrust, Tableau, Power BI