82 grc manager jobs at 60 companies in Stanford, CA
1mo
Save
Mark Applied
Hide
1mo
GRC Manager
San Francisco or New York or United States
$150k-$250k/yrHybridFull Time
Baseten: Private AI infrastructure provider that trains, deploys, and serves artificial-intelligence models for businesses.
5+ YOE5+ years GRC or security compliance experience in SaaS/cloud; strong knowledge of SOC 2, ISO 27001, NIST, GDPR; audit and certification management; third-party risk and cross-functional collaboration.
New York City or Chicago or Austin or Dallas or Denver or Miami or San Francisco or Seattle
$270k-$290k/yrHybridFull Time
DriveWealth: Private B2B financial technology platform providing brokerage infrastructure to banks, brokers, asset managers, wallets, and brands.
15+ YOE15+ years in information security/GRC in regulated financial services; deep SEC/FINRA and global privacy knowledge; hands-on GRC, audit, TPRM, incident response, and executive/board reporting; relevant certifications preferred.
Verkada: Physical security platform for enterprise buildings and facilities.
7+ YOERequires 7+ years in security or IT compliance, cloud service experience, software compliance experience, and SOC 2 or ISO 27001 audit, risk, and compliance experience.
SierraNYSE: TJX: Enterprise AI platform for customer experience automation.
10+ YOE3+ Mgmt10+ years in compliance/security/customer trust, 3+ years building/scaling customer-facing security programs, experience with regulated industries, knowledge of security frameworks and multi-cloud, and experience implementing trust automation platforms.
NIST 800-53, SOC 2, ISO 27001, PCI DSS, HIPAA, AWS, GCP, GDPR, UK GDPR, EU AI Act, SIG, CAIQ, ISO 42001, NIST AI RMF, CRM
MetaNASDAQ: META: Builds technologies that help people connect, find communities, and grow businesses.
7+ YOEBachelor's degree or equivalent experience, 7+ years in trust and safety, integrity, compliance, governance, or risk management, and 3+ years of corporate program management experience.
Austin or Tampa or Chicago or Cleveland or Miami or Los Angeles or Boston or New York or Florham Park or San Diego or San Francisco or Philadelphia or Houston
$77k-$202k/yrOnsiteFull Time
PwC: Global professional services network providing audit, tax, and consulting services.
3+ YOEBachelor's degree, minimum 3 years' experience, knowledge of GRC technologies and risk management, strong analytical and communication skills, client-facing experience, ability to travel up to 60%.
Risk Consulting - Risk Technology - Oracle GRC - Manager (New York, NY, US, 10001-8604)
New York or Atlanta or Boston or Chicago or Cleveland or Dallas or Detroit or Pittsburgh or Hoboken or Houston or Los Angeles or McLean or Miami or Minneapolis or North Carolina or Philadelphia or Portland or San Francisco or Seattle or Tampa
$150k-$260k/yrHybridFull Time
EY: Global professional services firm providing assurance, tax, and consulting.
5+ YOEBachelor's or master's degree with ~5 years related experience; Oracle security/controls and controls testing experience; strong project management, client service, leadership, communication, analytical skills; valid US driver’s license and passport; willing to travel.
Fastpath: Private identity-security software providing privileged access management and authorization for enterprises.
4+ YOE4+ years in technical advisory or customer success roles with deep expertise in GRC/IGA, Segregation of Duties, access reviews/certifications, audit evidence collection, and enterprise application integrations.
Fastpath, SAP, Oracle, Microsoft Dynamics, NetSuite, AuditBoard, Workiva
AdobeNASDAQ: ADBE: Empowering everyone to create through innovative digital experiences.
8+ YOE8–12+ years in strategy, business operations, risk management, or related fields; proven experience building metrics and executive reporting; able to engage and influence executives.
OktaNASDAQ: OKTA: Identity management and access control software provider.
10+ YOE10+ Mgmt10+ years of progressive Security GRC leadership in SaaS, cloud, or enterprise technology; AI governance expertise; security framework mastery; risk quantification; team-building; and a bachelor's degree or equivalent experience.
NIST AI RMF, ISO/IEC 42001, EU AI Act, SOC 1, SOC 2, SOC 3, ISO 27001, ENS High, MS DPR, PCI-DSS, CSA STAR, HDS, AI, ML
Tata Consultancy ServicesBSE: 532540: Global leader in IT services, consulting, and business solutions.
5+ years in cybersecurity/TPRM/GRC with hands-on experience running vendor assessments, managing CAPs, stakeholder escalation, and producing leadership reports.
Ivo: AI-powered contract intelligence platform serving in-house legal and procurement teams at enterprise companies.
3+ YOE3–5 years GRC/InfoSec/IT audit experience; hands-on SOC 2 Type II, ISO 27001, CSA STAR, ISO/IEC 42001; experience with Vanta, audits, evidence management, risk assessments, policy maintenance, and strong communication skills.
Senior Information Security Analyst, GRC/Responsible AI
Irvine or Milpitas
$125k-$207k/yrOnsiteFull Time
SanDiskNASDAQ: SNDK: Specialist in NAND flash memory and data storage solutions.
6+ YOE6+ years information security experience with GRC and AI risk management, bachelor's or equivalent, technical proficiency in threat modeling and risk assessment, familiarity with NIST AI RMF and ISO/IEC 42001, and strong cross‑functional communication.
OWASP Top 10 for LLM Applications, NIST AI RMF, ISO/IEC 42001, STRIDE, PASTA, attack tree analysis, CI/CD
Rippling: Unified workforce management platform for HR, IT, and Finance.
3+ YOERequires 3+ years in customer success, consulting, or compliance roles; 3+ years with compliance frameworks; customer relationship management, communication, technical aptitude, and SaaS experience preferred.
SOC 2, ISO 27001, PCI, Salesforce, Jira, Microsoft 365, Slack
United States or Canada or Columbus or Austin or San Francisco or New York City
$172k-$238k/yrRemoteFull Time
UpstartNasdaq: UPST: Public AI lending marketplace connecting consumers with banks and credit unions for personal, auto, and home-equity loans.
8+ YOE3+ MgmtBachelor's or equivalent, 8+ years technology risk/information security/IT audit experience in banking, 3+ years people management, FFIEC/OCC regulatory experience, regulator engagement, and GRC program experience; professional certs preferred.
PenumbraNYSE: PEN: Medical device manufacturer developing and selling neurovascular and peripheral vascular products to hospitals and healthcare providers.
8+ YOEBachelor's in accounting or information systems, 8+ years in IT SOX compliance/InfoSec/IT risk, experience with SOX 404, ITGCs/ITACs, SAP and GRC platforms preferred, strong communication and problem-solving skills.