HubSpotNYSE: HUBS: Provides a customer platform for marketing, sales, and service.
Experience in Security GRC/IT Compliance or IT Audit, people management plus hands-on IC work, deep control design (SOX 404), risk-based scoping/testing, AWS/microservices/CI/CD familiarity, strong communication.
AWS, CI/CD, IAM, ISO 27001, SOC 1, SOC 2, NIST, ISO 42001
Form Energy: Developing multi-day batteries for grid-scale energy storage.
10+ YOE5+ Mgmt10+ years in cybersecurity/IT GRC with 5+ years leadership; deep ITGC, IAM, EDR/MDR, vulnerability management, incident response, and audit liaison experience; ISO 27001/SOC 2/NIST familiarity; strong executive communication.
WHOOP: Providing wearable health trackers and physiological performance analytics.
6+ YOE6+ years in cybersecurity or enterprise risk management, experience conducting structured cyber/IT and AI risk assessments, maintaining risk registers, familiarity with NIST/ISO/PCI/GDPR/HIPAA, and strong communication skills.
NIST CSF, ISO 27001, PCI DSS, GDPR, HIPAA, NIST AI RMF, ISO/IEC 42001, FAIR
Manager and Senior Manager: Governance, Risk, & Compliance (GRC)
Boston, Massachusetts, United States
$155k-$205k/yrOnsiteFull Time
WHOOP: Wearable technology for personalized health and performance tracking.
8+ YOE4+ Mgmt8+ years GRC or information security experience, 4+ years managing GRC/compliance teams, deep knowledge of ISO 27001/SOC2/GDPR/NIST/HIPAA, strong communication and program-building skills, relevant certifications preferred.
Risk Consulting - Risk Technology - Oracle GRC - Manager (New York, NY, US, 10001-8604)
New York or Atlanta or Boston or Chicago or Cleveland or Dallas or Detroit or Pittsburgh or Hoboken or Houston or Los Angeles or McLean or Miami or Minneapolis or North Carolina or Philadelphia or Portland or San Francisco or Seattle or Tampa
$150k-$260k/yrHybridFull Time
EY: Global firm providing audit, tax, and professional consulting services.
5+ YOEBachelor's or master's degree with ~5 years related experience; Oracle security/controls and controls testing experience; strong project management, client service, leadership, communication, analytical skills; valid US driver’s license and passport; willing to travel.
Blitzy: Autonomous AI platform for enterprise software development.
Hands-on ownership of SOC 2 Type II or ISO 27001:2022 audits, Vanta or equivalent GRC platform experience, auditor/vendor management, FedRAMP exposure preferred, strong written and judgment skills.
DigitalOceanNew York Stock Exchange: DOCN: Simplifies cloud infrastructure for developers, startups, and SMBs.
5+ YOE5+ years GRC experience with multi-standard programs (ISO 27001/27017/22301), familiarity with SOC 2 and HIPAA, risk assessment and remediation, control design, policy authoring, and cross-functional project management.
KlaviyoNYSE: KVYO: Software platform for automated e-commerce marketing and customer data.
6+ YOE6+ years as a technical programme manager in information security; experience with risk, compliance, AI governance; proficient with security frameworks; PMI/ITIL-like certifications; strong stakeholder management.
NIST, ISO 27001, SOC 2, PCI DSS, CIS Controls, GRC tooling, TPRM, AI governance tools
Sr. Technical Program Manager, Cybersecurity Remediation
Cambridge, Massachusetts, United States
$146k-$234k/yrHybridFull Time
ModernaNasdaq: MRNA: Develops and manufactures messenger RNA medicines and vaccines.
8+ YOE8+ years technical program or cybersecurity program management experience; experience leading cross-functional remediation programs, vulnerability management, incident/audit remediation, metrics and executive reporting.
vulnerability management platforms, GRC tools, NIST, ISO 27001, CIS
Senior Manager, Technology Product Management - Technology & Cyber Governance - Remote or Hybrid in MN or DC
Boston or Minneapolis or Washington
$113k-$193k/yrRemoteFull Time
UnitedHealth GroupNYSE: UNH: Provides health insurance and technology-enabled health care services.
10+ YOEAssociate’s degree (or higher) in related field, 10+ years in technology/information security with risk governance experience, 5+ years in matrixed orgs; experience designing governance, risk metrics, and control assessment; preferred certifications CISA, CRISC, CISSP, CISM.
NIST CSF, ISO 27001, COBIT, SOX, FFIEC, SDLC, DevSecOps, GRC
6+ YOEBachelor's in business or related,6+ years risk/control experience,knowledge of financial services risk and regulatory environment,control writing/testing,GRC tools (Archer) and strong communication and analytical skills.
United States or Boston or Knoxville or Washington
RemoteFull Time
RegScale: Automated compliance software for continuous security controls monitoring.
4+ YOE4+ years experience in compliance/cybersecurity/GRC or SaaS professional services; Bachelor's (4 yrs exp) or Master's (3 yrs exp); strong communication, GRC framework knowledge, SaaS/product familiarity, and willingness to travel up to 25%.
Chicago or Tampa or Charlotte or Atlanta or Austin or Washington or Dallas or Los Angeles or Boston or Florham Park or New York or San Francisco or San Jose or Philadelphia or Houston
$99k-$232k/yrOnsiteFull Time
PwC: Providing audit, tax, and management consulting services to businesses.
4+ YOEBachelor's degree, 4+ years delivering SAP compliance, security, and governance solutions; proficiency with SAP GRC and SAP BW/4HANA; experience leading teams, implementing compliance programs, and audit processes.
SAP, SAP Governance, Risk and Compliance (GRC), SAP BW/4HANA
Re:Build Manufacturing: Provides advanced engineering and US-based contract manufacturing services.
Lead CMMC compliance program, gap analysis, and documentation; implement controls aligned with NIST SP 800-171; coordinate across IT, Legal, HR, and business units.
Atlanta or Chicago or Boston or Minneapolis or Charlotte or Short Hills or New York City or Philadelphia or McLean
OnsiteFull Time
KPMG: Global professional services network providing audit, tax, and advisory.
3+ YOE3+ years of recent experience with SAP security, SAP GRC, SAP audit or controls; bachelor\u0002s degree; hands-on SAP GRC and S/4HANA exposure; strong analytical and communication skills; ability to travel; U.S. work authorization required.
Bright HorizonsNYSE: BFAM: Provides child care, early education, and workforce education services.
10+ YOE10+ years privacy compliance and risk management experience, 7+ years with GRC tools (OneTrust/TrustArc), Bachelor's degree (or 5+ years additional experience), CIPM within 12 months preferred, strong analytical and leadership skills.