4+ YOE4+ years GRC or information security governance experience; hands-on change management, risk assessment, policy management; familiarity with ISO 27001/SOC 2/NIST CSF; stakeholder engagement and strong written communication.
New York City or Chicago or Austin or Dallas or Denver or Miami or San Francisco or Seattle
$270k-$290k/yrHybridFull Time
DriveWealth: Provides API-based brokerage infrastructure for fractional stock trading.
15+ YOE15+ years in information security/GRC in regulated financial services; deep SEC/FINRA and global privacy knowledge; hands-on GRC, audit, TPRM, incident response, and executive/board reporting; relevant certifications preferred.
YETINYSE: YETI: Sells premium outdoor gear, coolers, and drinkware.
6+ YOE5+ years experience in SAP GRC and SAP security, SoD risk analysis, SOX compliance knowledge, GRC module administration, strong communication and independent multitasking skills.
CloudflareNYSE: NET: Provides security and performance services for internet properties.
5+ YOE5+ years in security/compliance/automation; strong automation and IaC/Policy-as-Code experience (Terraform, Pulumi, OPA/Rego); proficiency with Python/Go, JS/TypeScript, React, REST APIs; AI governance experience.
NTT DATA: Global provider of IT and business consulting services.
10+ YOE10 years of security experience; hands-on GRC, control assessments, compliance monitoring, audit support, risk management, and systems/network administration; preferred CISSP, GIAC, SSCP, or CEH.
Fidelity Investments: Provides investment management, retirement planning, and brokerage services.
8+ YOE8+ years developing and supporting Archer 6.x GRC applications, 9+ years in information security/IT/GRC, expert risk and compliance knowledge, hands-on Python and SQL, web tech (CSS, JavaScript, jQuery, XML), RESTful API integration, and stakeholder collaboration.
Archer 6.x, CSS, JavaScript, jQuery, XML, Python, SQL, JavaScript Transformer, RESTful APIs, Snowflake, Power BI
Greystar: Provides global property management and real estate investment services.
8+ YOE2+ Mgmt8+ years in information security with 4+ years focused on GRC and 2+ years people-management. Bachelor's or equivalent, experience with risk management, third-party risk, compliance frameworks (ISO 27001, NIST, SOC 2), GRC platforms, cloud environments, and security awareness programs.
Hyperproof, OneTrust, Archer, AWS, GCP, Azure, SIG, CAIQ, ISO 27001, PCI DSS, SOX, GDPR, CCPA, ISO 42001, NIST AI RMF, SOC 2, NIST 800-53
Ultra Clean HoldingsNASDAQ: UCTT: Provides critical subsystems and cleaning services for semiconductor manufacturing.
3+ YOE3+ years in IT governance, risk, compliance, audit, or related field; bachelor's degree or equivalent experience; professional certifications (CRISC, CISA, CISM, CISSP) preferred; experience with control testing, risk registers, third-party risk, and audit readiness.
Caris Life SciencesNASDAQ: CAI: Provides molecular profiling and AI-driven precision medicine diagnostics.
4+ YOEBachelor's or equivalent experience, 4+ years in information security risk management or third‑party risk, knowledge of HIPAA/SOX/GDPR and NIST/ISO/CIS frameworks, strong communication, analytical skills, and proficiency with Excel/PowerPoint.
Microsoft Excel, Microsoft PowerPoint, Compyl, AuditBoard, RSA Archer, LogicGate, AWS, Azure, GCP
Amynta: Provides specialty insurance, warranty programs, and underwriting management services.
4+ YOE4–7 years in information security, governance, risk and compliance; Bachelor's in Information Systems or related field; strong communication; willing to work in Fort Worth, TX; certifications preferred.
EY: Global firm providing audit, tax, and professional consulting services.
5+ YOE3+ MgmtBachelor's or Master's in related field with SAP Security/GRC leadership and 5+ years experience; 3 years lead; 2 years PM; up to 80% travel.
SAP S/4HANA, SAP FIORI, SAP Security, SAP GRC, GRC Access Control
Tata Consultancy ServicesNational Stock Exchange of India: TCS: Global provider of IT services, consulting, and business solutions.
5+ years in cybersecurity/TPRM/GRC with hands-on experience running vendor assessments, managing CAPs, stakeholder escalation, and producing leadership reports.
Sr Director Analyst, Cyber GRC Tools and Technology (Remote US)
United States or Texas
$172k-$203k/yrRemoteFull Time
GartnerNYSE: IT: Provides research and advisory services for business leaders.
12+ YOE5+ Mgmt12+ years in Cyber GRC/InfoSec/ERM with 5+ years leadership, expertise in Cyber GRC tools, strong research, writing, presentation and client engagement skills; willingness to travel up to 25%.
Security Industry Specialist, Subsidiary & Acquisition GRC
Austin or Hawthorne
$102k-$178k/yrOnsiteFull Time
AmazonNASDAQ: AMZN: Global online retail and cloud computing technology provider.
3+ YOEExperience in security/compliance consulting, 3+ years IT platform implementation, bachelor's in computer science or 5+ years IT security experience, and 3+ years performing technical compliance assessments (e.g., NIST, SOC 2, ISO).
Lantern: Connects employees to high-quality surgical, cancer, and infusion care.
5+ YOE5+ years GRC/compliance/InfoSec; 3+ years healthcare/healthtech; degree in information security, CS, or related; experience with risk registers, HITRUST/SOC 2, HIPAA, NIST CSF, AI RMF; GRC tools.