Lendistry: Technology-enabled lender providing capital to small businesses.
3+ YOE3-5 years in GRC, data privacy, risk management; SOC 2 and GLBA; cloud experience (AWS/Azure); privacy engineering; CIPT/CDPSE required; CIPM/CISSP preferred; B.S. in CS/Info Security or equivalent.
SHEIN: Global online retailer selling affordable fashion and lifestyle products.
7+ YOE7+ years in information security risk management; bachelor’s degree; CISSP/CISM/CISA or ISO 27001 Lead Auditor desirable; strong standards knowledge; team leadership experience.
Panda Restaurant Group: Operator of American Chinese fast-casual restaurant chains.
7+ YOEBachelor's degree, 7+ years GRC/privacy/security/technology risk experience, knowledge of AI governance and cybersecurity frameworks, policy and program design, and strong advisory skills.
NIST AI RMF, EU AI Act, ISO 42001, NIST CSF, NIST 800-53, ISO 27001, ISO 27002, CIS
Risk Consulting - Risk Technology - Oracle GRC - Manager (New York, NY, US, 10001-8604)
New York or Atlanta or Boston or Chicago or Cleveland or Dallas or Detroit or Pittsburgh or Hoboken or Houston or Los Angeles or McLean or Miami or Minneapolis or North Carolina or Philadelphia or Portland or San Francisco or Seattle or Tampa
$150k-$260k/yrHybridFull Time
EY: Global firm providing audit, tax, and professional consulting services.
5+ YOEBachelor's or master's degree with ~5 years related experience; Oracle security/controls and controls testing experience; strong project management, client service, leadership, communication, analytical skills; valid US driver’s license and passport; willing to travel.
Northwood Space: Manufacturing ground stations and providing satellite communication infrastructure.
5+ YOE5+ years in GRC with ownership of enterprise compliance programs; deep knowledge of CMMC, NIST SP 800-171/800-53, FedRAMP, SOC 2, ITAR; ability to obtain TS/SCI; U.S. citizen or lawful permanent resident required.
Senior Information Security Analyst, GRC/Responsible AI
Irvine or Milpitas
$125k-$207k/yrOnsiteFull Time
SandiskNasdaq: SNDK: Designs and manufactures flash memory and data storage products.
6+ YOE6+ years information security experience with GRC and AI risk management, bachelor's or equivalent, technical proficiency in threat modeling and risk assessment, familiarity with NIST AI RMF and ISO/IEC 42001, and strong cross‑functional communication.
OWASP Top 10 for LLM Applications, NIST AI RMF, ISO/IEC 42001, STRIDE, PASTA, attack tree analysis, CI/CD
Hyundai AutoEver AmericaKorea Exchange: 307950: Provides automotive software and IT services for mobility systems.
10+ YOE3+ Mgmt10+ years in technology audit/technology risk/GRC/IT audit required, 3+ years people leadership, Bachelor\u0002s in Cybersecurity/IT/Computer Science required, familiarity with GRC platforms and technology control frameworks, certifications (CISSP/CISM/CRISC/CIA) preferred.
Miratech: Provides digital engineering and IT consulting for global enterprises
7+ YOE7+ years project/program management in compliance/security/IT, experience with SOC 2/ISO 27001/GDPR audit-readiness, RAID and remediation tracking, cross-functional coordination, and stakeholder reporting.
Latham & Watkins: Global law firm providing legal counsel to businesses.
10+ YOE2+ Mgmt10+ years in GRC/technology risk/compliance/audit/cybersecurity with 2+ years leadership, experience with client security questionnaires, ISO 27001 certification experience, strong communication and project management skills.
Latham & Watkins: Global law firm providing comprehensive legal and advisory services.
10+ YOE2+ Mgmt10+ years in GRC/technology risk/compliance/audit/cyber assurance with 2+ years leadership; experience managing security due diligence, ISO 27001, and client security questionnaires; strong communication and project management skills.
Austin or Denver or Indianapolis or Los Angeles or San Francisco or New York or Salt Lake City or Minneapolis or Seattle or Nashville
$135k-$150k/yrRemoteFull Time
Givebutter: Fundraising and CRM platform for nonprofit organizations.
5+ YOE5+ years IT experience; hands-on IT ops (MDM, device and SaaS administration, identity lifecycle), Notion administration, GRC project management with Vanta/Drata, familiarity with SOC 2/ISO 27001/PCI, remote/Mac environment experience.
Vanta, Drata, Notion, Google Workspace, Slack, 1Password, Mobile Device Management (MDM), Claude, Cursor, ChatGPT
Stamford or Chicago or Kansas City or Costa Mesa or Draper or Dallas or Phoenix or New York City or St. Paul or West Chester or Orlando or Alpharetta or Rapid City or Charlotte or Canton
5+ YOEBachelor's plus 5+ years in compliance/BSA/AML or HS+8; experience with governance routines, executive reporting, KPI/KRI dashboards, change impact assessments, issue management; strong written/verbal communication.
Microsoft Excel, Microsoft PowerPoint, Microsoft Word, SharePoint, Tableau, eGRC
Yuhaaviatam of San Manuel Nation: Operates a luxury resort and casino in Southern California.
6+ YOEBachelor's in a related field, 6+ years in IT/security/privacy/risk, experience with PCI DSS, GRC platforms, vendor risk management, and privacy impact assessments.
Chicago or Tampa or Charlotte or Atlanta or Austin or Washington or Dallas or Los Angeles or Boston or Florham Park or New York or San Francisco or San Jose or Philadelphia or Houston
$99k-$232k/yrOnsiteFull Time
PwC: Providing audit, tax, and management consulting services to businesses.
4+ YOEBachelor's degree, 4+ years delivering SAP compliance, security, and governance solutions; proficiency with SAP GRC and SAP BW/4HANA; experience leading teams, implementing compliance programs, and audit processes.
SAP, SAP Governance, Risk and Compliance (GRC), SAP BW/4HANA
Distribution/Vegetation Management Asset Strategy, Advisor (Pomona, CA, US, 91768)
Pomona or California
HybridFull Time
Edison InternationalNYSE: EIX: Generating and distributing electricity to customers in Southern California.
7+ YOESeven+ years in strategic planning at department/organization level; experience in utility asset/vegetation management, geospatial and data analysis, regulatory filings (GRC/WMP/RAMP), stakeholder coordination, and communication materials.
Advisor Enterprise Compliance (Los Angeles, CA, US, 90017)
Los Angeles, California, United States
$110k-$182k/yrOnsiteFull Time
L.A. Care Health Plan: Public health plan providing coverage to Los Angeles residents.
5+ YOE5+ years designing or monitoring regulatory requirements, policies, or practices in healthcare; bachelor\u0002s required (healthcare administration or related), master\u0002s preferred; GRC administration, policy management, reporting, analysis, and strong communication skills.
SpaceX: Designs and launches advanced rockets and satellite internet constellations.
1+ YOEBachelor's degree or 3+ years managing cyber assurance for classified systems; 1+ years cyber assurance; RMF A&A lifecycle experience; familiarity with Nessus, Splunk, Security Center, ServiceNow, eMASS, and GRC tools; active TS/SCI clearance and CI polygraph or ability to obtain.
RMF, Nessus, Splunk, Security Center, ServiceNow (SNOW), eMASS, GRC, NRO A&A, JSIG A&A