Benepass: Platform for distributing and managing flexible employee benefits.
5+ YOE5+ years in GRC, information security, IT audit or risk management; hands-on SOC 2, ISO 27001/HITRUST; policy, evidence & audit readiness; strong communication.
Compyl: A provider of a platform to help companies understand and manage risk, security, and compliance.
5+ YOE5+ years GRC experience with audits, risk assessments, and policy/control rollouts; familiarity with SOC 2/ISO 27001/HIPAA/PCI-DSS/NIST; strong consultative communication and judgment.
Kokosing: Provides heavy civil, industrial, and marine construction services.
5+ YOE5+ years GRC/cybersecurity experience; knowledge of CMMC and NIST 800-171; strong risk management, policy and vendor risk experience; ability to influence stakeholders and support audits and data governance.
DoorDashNASDAQ: DASH: On-demand delivery platform connecting consumers with local merchants.
6+ YOE6+ years in security compliance/GRC with 3+ years implementing HIPAA programs in technology or regulated environments; strong HIPAA Security Rule knowledge, multi-framework experience, technical fluency with cloud/IAM/CI/CD, and stakeholder communication skills.
Hillsboro or Irvine or Phoenix or Tacoma or Utah or San Diego or Denver or Liberty Lake or Los Angeles or Las Vegas or Seattle
$80k-$165k/yrOnsiteFull Time
Columbia BankNASDAQ: COLB: Commercial and consumer banking services in the Western United States.
7+ YOE7+ years in information security/IT audit/operations; ServiceNow IRM/GRC experience; knowledge of NIST, FFIEC, CIS, ITIL, COBIT; familiarity with PCI DSS, GLBA, HIPAA; bachelor’s preferred.
WHOOP: Wearable technology for personalized health and performance tracking.
6+ YOE6+ years in cybersecurity or enterprise risk; experience conducting structured cyber/IT risk assessments, maintaining risk registers, familiarity with security frameworks and AI risk; strong communication and analysis skills.
NIST CSF, ISO 27001, PCI DSS, GDPR, HIPAA, NIST AI RMF, ISO/IEC 42001, FAIR
Workato: Enterprise platform for automating business workflows and integrating applications.
8+ YOE8+ years in cybersecurity, audits, risk management, or compliance; hands-on FedRAMP experience; cloud security controls; strong communication; eligibility for federal programs.
AWS GovCloud, Azure Government, Google Cloud, NIST 800-53, FedRAMP, PCI-DSS, SOC 2, ISO 27001, 27701
CMG Financial: Provides residential mortgage loans and home financing services.
5+ YOEBachelor's or equivalent, 5+ years IT audit/compliance/GRC experience, SOC 2 management, knowledge of NIST CSF/ISO 27001/SOX and financial regulations (GLBA, CFPB, NYDFS), strong policy writing and communication; CISA/CRISC/GRCP preferred.
Calgary or Vancouver or Spain or Switzerland or United Kingdom or United States
HybridFull Time
Benevity: Provides enterprise software for corporate social responsibility programs.
5+ YOE5+ years privacy/GRC experience in SaaS or tech; deep knowledge of GDPR, UK-GDPR, CPRA/CCPA, PIPEDA, CASL; hands-on ROPA, DSAR, DPIA, DPA review; experience with OneTrust or Hyperproof; CIPP/CIPM/CISM/C RISC certifications valued.
YETINYSE: YETI: Sells premium outdoor gear, coolers, and drinkware.
6+ YOE5+ years experience in SAP GRC and SAP security, SoD risk analysis, SOX compliance knowledge, GRC module administration, strong communication and independent multitasking skills.
RobloxNYSE: RBLX: Platform for creating and playing user-generated 3D digital experiences.
4+ YOE4+ years GRC experience, risk assessment and policy development, ability to work with engineers, knowledge of compliance frameworks and security controls.
Factor Analysis of Information Risk (FAIR), Roblox Studio
Amynta: Provides specialty insurance, warranty programs, and underwriting management services.
4+ YOE4–7 years in information security, governance, risk and compliance; Bachelor's in Information Systems or related field; strong communication; willing to work in Fort Worth, TX; certifications preferred.
DeltekNYSE: ROP: Software and information solutions for project-based businesses.
3+ YOE3+ years in GRC engineering/cloud security/compliance or related fields, Bachelor\u0002s in a related field or equivalent experience, experience with AWS/Azure/OCI, knowledge of security frameworks and cloud controls, certification(s) preferred, US citizenship required.
Clear Capital: AI-driven real estate valuation and property data solutions.
3+ YOE5+ years GRC/risk/compliance experience with Bachelor’s (or 3+ years with Master’s) or equivalent; deep knowledge of NIST, ISO, SOC 2, GLBA/CCPA/GDPR; relevant certifications (CISSP, CISM, CISA, CRISC, AIGP); familiarity with Vanta, Drata, OneTrust, cloud and DevOps; strong analytics and communication.
NIST CSF, NIST RMF, ISO 27001, ISO 27002, ISO 42001, SOC 2, GLBA, CCPA, GDPR, Vanta, Drata, OneTrust, DevOps, cloud computing
SkyePoint Decisions: Provider of cybersecurity, infrastructure, and IT development services.
5+ YOEBachelor's degree and 5+ years cybersecurity GRC experience supporting Federal programs; knowledge of NIST frameworks, FISMA, risk assessments, audit prep, U.S. citizenship and ability to obtain Public Trust required.
MISO: Manages the high-voltage electricity grid and wholesale energy markets.
5+ YOEBachelor's degree in a related field, 5+ years cybersecurity risk management experience, vendor risk assessment expertise, knowledge of NIST frameworks, and relevant certifications (CRISC/CISSP/CISA/CISM) preferred.