44 security grc manager jobs at 36 companies in New York
3w
Save
Mark Applied
Hide
3w
Head of Security GRC
New York City or Chicago or Austin or Dallas or Denver or Miami or San Francisco or Seattle
$270k-$290k/yrHybridFull Time
DriveWealth: Provides API-based brokerage infrastructure for fractional stock trading.
15+ YOE15+ years in information security/GRC in regulated financial services; deep SEC/FINRA and global privacy knowledge; hands-on GRC, audit, TPRM, incident response, and executive/board reporting; relevant certifications preferred.
Valence: Builds an AI-native leadership coaching platform for enterprise customers.
Experienced in running GRC and security compliance programs (SOC 2, ISO 27001, ISO 42001), audit coordination, risk management, cloud security (AWS/Azure), and cross-functional stakeholder collaboration.
SOC 2, ISO 27001, ISO 42001, NIST CSF, GDPR, EU AI Act, AWS, Azure, Vanta, Drata, Secureframe, OneTrust, Archer
Baseten: Scalable infrastructure platform for deploying and serving AI models.
5+ YOE5+ years GRC or security compliance experience in SaaS/cloud; strong knowledge of SOC 2, ISO 27001, NIST, GDPR; audit and certification management; third-party risk and cross-functional collaboration.
Los Angeles or Chicago or Nashville or New York or Seattle
$100k-$135k/yrHybridFull Time
Metropolis: Computer vision technology for checkout-free parking and retail payments.
3+ YOE3+ years in information security GRC or technology compliance; experience managing security awareness programs; knowledge of SOC 2 and PCI-DSS; familiarity with AI/data security and training platforms; bachelor\u0002s degree required.
PalantirNasdaq: PLTR: Developing software platforms for data integration and analytics.
Experience managing GRC/compliance programs, knowledge of SOC2/FedRAMP/ISO27001/NIST, audit coordination, risk management, stakeholder communication, and ability to work on-site near a Palantir office; U.S. security clearance eligibility preferred.
United States or San Francisco or New York City or Bengaluru
$150k-$200k/yrHybridFull Time
Mesh: Connecting digital wallets and exchanges for unified cryptocurrency payments.
5+ YOERequires 5+ years of hands-on GRC experience, compliance program management, major security framework familiarity, business continuity and disaster recovery experience, risk lifecycle expertise, and scalable process-building skills.
Alabama or California or Colorado or Georgia or Iowa or Maryland or Michigan or Minnesota or Mississippi or Missouri or New Jersey or New York or North Carolina or Oregon or Pennsylvania or South Carolina or Texas or Utah or Virginia or Washington
$95k-$105k/yrRemoteFull Time
Prowess Consulting: Technical services and software engineering for technology enterprises.
6+ YOE6+ years in product management or security engineering; strong Windows/platform security expertise; experience with secure software supply chains, compliance frameworks (NIST,FedRAMP,CRA), and data-driven compliance reporting.
Active Directory, Group Policy, CVSS, SPDX, CycloneDX, ADO, Jira, CI/CD, Power BI, GRC
Forus: A building an AI-powered platform that connects doctors, pharmacies, payers, and biopharma to accelerate patient access to therapies.
4+ YOE4+ years in GRC/security compliance with hands-on SOC 2 and HIPAA experience, HITRUST a plus; experience with compliance automation, vendor risk, audits, and working with engineering and enterprise buyers.
Albany or Arlington or Atlanta or Austin or Beaverton or Boston or Carmel or Charlotte or Chicago or Cincinnati or Cleveland or Columbus or Culver City or Denver or Des Moines or Detroit or Hartford or Houston or Irving or Miami or Milwaukee or Minneapolis or Morristown or Mountain View or New York City or Overland Park or Philadelphia or Pittsburgh or Raleigh or Sacramento or San Diego or San Francisco or Scottsdale or Seattle or St. Louis or St. Petersburg or United States
$80k-$294k/yrOnsiteFull Time
AccentureNYSE: ACN: Global professional services firm providing consulting and technology solutions.
5+ YOERequires 5+ years in SAP S/4 or cloud environments, technical documentation, SAP security, GRC, vulnerability management, and a bachelor's degree or equivalent experience; leadership and client consulting skills required.
SAP S/4HANA, SAP GRC, SAP BTP, SAP Fiori, SAP HANA, NextLabs, Security Bridge, Onapsis
Madison Square Garden EntertainmentNYSE: MSGE: Operates iconic entertainment venues and produces world-class live shows.
8+ YOERequires 8+ years related experience, 5+ years in information security GRC, a bachelor's degree or equivalent, cloud and on-prem audit experience, and knowledge of regulatory requirements and NIST, ISO, and CIS frameworks.
Risk Consulting - Risk Technology - Oracle GRC - Manager (New York, NY, US, 10001-8604)
New York or Atlanta or Boston or Chicago or Cleveland or Dallas or Detroit or Pittsburgh or Hoboken or Houston or Los Angeles or McLean or Miami or Minneapolis or North Carolina or Philadelphia or Portland or San Francisco or Seattle or Tampa
$150k-$260k/yrHybridFull Time
EY: Global firm providing audit, tax, and professional consulting services.
5+ YOEBachelor's or master's degree with ~5 years related experience; Oracle security/controls and controls testing experience; strong project management, client service, leadership, communication, analytical skills; valid US driver’s license and passport; willing to travel.
Chief Information Security Office-Strategy, Programs & GRC AVP
New York, New York, United States
$65k-$150k/yrOnsiteFull Time
Bank of ChinaHong Kong Stock Exchange: 3988: Provides global commercial and investment banking services.
5+ YOEPlan and coordinate information security strategy, manage CISO programs, perform risk assessments, ensure regulatory compliance, and oversee privacy and identity functions; bachelor\u0002s degree and 5+ years experience required.
Miratech: Provides digital engineering and IT consulting for global enterprises
7+ YOE7+ years project/program management in compliance/security/IT, experience with SOC 2/ISO 27001/GDPR, RAID and remediation tracking, cross-functional coordination, and stakeholder reporting.
Jira, Confluence, ServiceNow, Microsoft SharePoint, Microsoft Project, Smartsheet, Azure DevOps, GRC platforms
Chicago or Dallas or New York or United Kingdom or Europe or Asia or North America
$120k/yrRemoteFull Time
ECI: Provider of managed IT, cybersecurity, and cloud solutions for finance.
8+ YOEApproximately 8 years in cybersecurity, risk management, or IT governance; relevant bachelor's degree or equivalent experience; security assessments, audits, risk analysis, regulatory frameworks, and stakeholder communication.
NIST CSF 2.0, CMMC, GDPR, Data Protection Act 2018, ISO 27001, NIST, CIS, CIS Controls, COBIT, Microsoft, Cisco, IAM, O365 admin center
Denver or Stamford or Washington or Orlando or Tampa or Atlanta or Chicago or Boston or Minneapolis or Charlotte or Short Hills or New York City or Philadelphia or Dallas or Houston or McLean
FieldFull Time
KPMG: Global professional services network providing audit, tax, and advisory.
3+ YOERequires 3+ years in SAP audit, controls, security, GRC, ERP implementation, or transformation; bachelor's degree; SAP GRC and security experience; and strong communication skills.
Chief Information Security Office-Strategy, Programs & GRC AVP
New York, New York, United States
$65k-$150k/yrOnsiteFull Time
Bank of ChinaHong Kong Stock Exchange (SEHK) / Shanghai Stock Exchange (SSE): 3988 / 601988: Global commercial bank providing corporate and retail financial services.
5+ YOEBachelor's degree,5+ years in risk/audit/IT-IS operations,3+ years developing IT/IS risk programs,experience with US banking regulations,strong writing and program management skills.
Chicago or Denver or Phoenix or Chandler or Arizona or Colorado or District of Columbia or Illinois or Maryland or Texas or Virginia or California or Florida or Massachusetts or New York or Oregon or Washington or Wisconsin or United States
$171k-$214k/yrHybridFull Time
Caribou: Connects car owners with lenders to refinance auto loans.
Owner of security and IT programs with proven SOC 2 Type II delivery, SIEM/EDR incident response, GRC controls, SaaS and identity management, vendor management, and people leadership.
Syllo: A legal technology building an AI-powered litigation workspace that helps legal teams manage sensitive data.
5+ YOE5+ years in information security compliance/GRC; hands-on ISO 27001 and SOC 2 experience; Vanta or comparable GRC experience; cloud IAM, logging, and vendor risk management; technical fluency and strong written communication.
Technology and Information Security Risk Specialist
New York City, New York, United States
$160k-$180k/yrHybridFull Time
IDB BankTel Aviv Stock Exchange: DSCT: Provides commercial and private banking services to international clients.
10+ YOE10+ years in technology, information security, cyber risk, or IT controls with strong knowledge of cloud, resilience, access management, NIST, NYDFS Part 500, FFIEC, GRC tools, risk assessments, reporting, and stakeholder engagement; bachelor’s preferred.
Austin or Chicago or New York City or Salt Lake City or San Francisco
$117k-$185k/yrOnsiteFull Time
Gong: AI platform analyzing customer interactions to improve sales performance.
7+ YOE7+ years in third‑party/vendor risk management or GRC; strong knowledge of security/privacy frameworks, vendor assessments, and TPRM tooling; excellent communication and risk translation skills.