Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Manager, Information Security (GRC) (Remote)

Neumo Holdings LLC

Salem, OR
  • Remote job

Job Description

Job Description

Job Summary:

We are seeking a Manager, Information Security (GRC) to own and mature Neumo's Governance, Risk, and Compliance program. This role is critical to maintaining our SOC 1, SOC 2, and PCI certifications and to raising our overall information security maturity. You will build the foundation for data governance, risk acceptance and exceptions processes, and a recurring cadence of monthly, quarterly, and annual risk mitigation. This is a hands-on leadership role: you will manage 1–2 direct reports while personally driving audits, risk assessments, and control automation, and participate in incident management alongside the broader security team.

You will be the connective tissue between security engineering, legal, engineering, and executive leadership: translating regulatory and contractual requirements into practical controls, and translating control performance into risk language leadership can act on.

This role directly protects Neumo's ability to do business: Our certifications are foundational to customer trust and revenue. You will have the mandate to modernize how we manage risk and compliance, including building automation and AI-driven workflows that scale the program without scaling headcount linearly.


Duties and Responsibilities:

Leadership & Program Ownership

  • Own and execute Neumo's GRC strategy and roadmap, in partnership with the CISO.
  • Manage, mentor, and grow 1–2 direct reports supporting compliance, risk, and audit activities.
  • Set the foundation for data governance: data classification, ownership, retention, and handling standards.
  • Build and maintain the risk register; lead monthly, quarterly, and annual risk mitigation cycles.
  • Own the risk acceptance and policy exception process, including documentation, approval workflows, and periodic review.
  • Report on compliance posture, audit status, and risk trends to executive stakeholders and the board as needed.

Compliance & Audit Management

  • Own end-to-end readiness and execution for SOC 1, SOC 2, and PCI DSS audits, including evidence collection, auditor coordination, and remediation tracking.
  • Maintain and continuously improve the internal control framework mapped to SOC 1/2, PCI, and other applicable frameworks (e.g., ISO 27001, NIST CSF).
  • Track control ownership, testing cadence, and control health across the organization using the GRC platform and Jira.
  • Partner with engineering and IT teams to close control gaps and drive remediation of audit findings within SLA.

Risk, Automation & Cross-Functional Work

  • Design and implement control automation to reduce manual evidence collection and continuous control monitoring (CCM).
  • Leverage AI/LLM tooling to accelerate evidence review, policy drafting, control testing, and risk analysis, with appropriate human oversight.
  • Participate in incident management as the GRC/risk representative: assessing regulatory and contractual impact and ensuring proper documentation.
  • Manage third-party/vendor risk assessments and questionnaires (customer security questionnaires, vendor due diligence).
  • Partner with Legal and Privacy on data protection, regulatory, and contractual compliance requirements.


Education and Experience:

  • 6+ years of experience in GRC, information security compliance, or IT audit, including experience managing or mentoring others.
  • Direct experience owning SOC 1, SOC 2, and PCI DSS compliance programs end-to-end, including audit management.
  • Hands-on experience with GRC platforms (e.g., Vanta, Drata, ServiceNow GRC, OneTrust, Archer, or similar).
  • Experience building risk management programs: risk registers, risk acceptance/exception processes, and recurring risk mitigation cadences.
  • Foundational experience with data governance concepts (classification, ownership, retention).
  • Relevant certifications (e.g., CISA, CRISC, CISSP, CISM) are a plus but not required.


Knowledge, Skills and Abilities:

  • Strong working knowledge of Jira for control tracking, remediation workflows, and cross-team coordination.
  • Demonstrated ability to build or deploy control automation and continuous control monitoring.
  • Comfort leveraging AI tools to scale GRC operations (evidence review, policy generation, risk analysis).
  • Ability to participate effectively in incident management, translating technical incidents into risk and compliance impact.
  • Excellent written and verbal communication skills; able to translate technical and regulatory detail for executive audiences.

Work Environment :

  • Office setting with a moderate noise level.
  • The employee will work at an individual workstation, using a telephone and computer.
  • Periodic flexibility outside standard business hours may be required to support audits or incident response.


Physical Demands
:

  • Must be able to remain seated for extended periods.
  • Regular use of a computer and other office machinery, such as printers and copy machines.
  • Occasional movement around the office.
  • Frequent communication via telephone.


Neumo Summary:

With the backing of four decades of public sector expertise and corporate capability, Neumo has successfully supported government services. Neumo was honored and recognized for four (4) consecutive years as a GovTech 100 Company representing the top 100 companies focused on making a difference in and selling to state and local government agencies across the United States.

Neumo is committed to helping communities thrive and brings a wealth of experience combined with innovation. Today, Neumo offers more administrative and financial support to government officials than any other organization. And with a responsive, client-focused approach, we foster partnerships that give our customers the certainty they need to accomplish more.

Neumo offers a competitive benefits and compensation package and are looking for team members who will thrive in our dynamic environment.

Neumo is an Equal Opportunity Employer. Selection for a position will be made without regard to race, religion, national origin, sex, political affiliation, marital status, non-disqualifying physical handicap, and age.

Vacancy posted 9 days ago
Similar jobs that could be interesting for youBased on the Manager, Information Security (GRC) (Remote) in Salem, OR vacancy
  •  ...Job Description Job Description Job Summary: We are seeking a Manager, Information Security (GRC) to own and mature Neumo's Governance, Risk, and Compliance program. This role is critical to maintaining our SOC 1, SOC 2, and PCI certifications and to raising our... 
    Remote work
    Work at office
    Local area

    Neumo Holdings LLC

    West Jordan, UT
    8 days ago
  • $204.72k - $254.26k

     ...chapter of your career. Senior Manager, Security Engineering Business...  ...Operations, Privacy, GRC, and Enterprise Technology leaders...  ...~8+ years in information security, including significant...  ...and paid time off (PTO). #Li-remote Notice of Collection and... 
    Remote work
    Full time

    6sense

    Remote
    3 days ago
  •  ...Job Description Job Description Summary:The Information Security Governance, Risk, and Compliance (GRC) Manager is responsible for leading the development, implementation, and ongoing management of the organization's security governance framework. Responsible for the... 
    Suggested

    Sutton Bank

    Columbus, OH
    10 days ago
  • $150k - $175k

     ...Annually Description: Our client is currently seeking a Manager, IT Security, GRC. This is FT perm role and hybrid in Burlington, NJ Position...  ...) plays a critical mid-level leadership role within the Information Security function, responsible for translating strategy into... 
    Suggested
    Permanent employment

    The Judge Group

    Burlington, NJ
    5 days ago
  • $167.1k - $208.9k

     ...As Marqeta’s Information Security Manager you will lead Vulnerability Management and establish a Data Security...  ...First . This role can be performed remotely anywhere within the United States. We’...  ...Tenable/Snyk workflows into CI/CD and GRC/Risk registers. Background in data... 
    Remote work
    Work at office
    Flexible hours

    Marqeta

    Remote
    more than 2 months ago
  •  ...advice to our regional, national and international clients.The Manager, Information Security, will join a dynamic security team that is responsible for...  ...segmentation, vulnerability management, privileged / remote access management, EDR/NGAV, SIEM, email security and continuous... 
    Remote work
    Full time
    Work at office

    Buchanan Ingersoll & Rooney

    Pittsburgh, PA
    5 days ago
  • $109.37k - $123.04k

     ...a highly skilled and motivated Senior Manager, IT Security Operations to join our team. As the Senior...  ...and confidentiality of sensitive information, and maintaining the overall security...  ...each month of the employee’s choosing. Remote work within the United States may be considered... 
    Remote work
    Full time
    Work experience placement
    Work at office
    Local area

    National Audubon Society

    Washington DC
    21 hours ago
  •  ...selling experience into a simple, secure, and enjoyable process. Our SMB and...  ...every year.WHAT YOU'LL WORK ONAs the Information Security Engineering Manager, you'll lead the team that owns...  ...Austin, Texas, we're open to exploring remote possibilities for qualified... 
    Remote work
    Work at office
    Flexible hours

    Qualia

    Austin, TX
    4 days ago
  • $175.1k - $236.9k

     ...engineers, supply chain specialists, security experts, operations managers, and other vital roles. You’ll...  ...standards, passion, and discipline for information security. The highest level of...  ...testing techniques- Experience managing remote team membersAmazon is an equal... 
    Remote work
    Flexible hours

    Amazon

    Seattle, WA
    1 day ago
  • $152k - $272.25k

     ...Requisition ID #26WD99489Position OverviewAutodesk's Information Security Engineering organization is looking for a Senior Manager, Data Security Engineering to lead the...  ...raise the quality bar for their team.This role is remote-friendly within North America. For those who... 
    Remote work
    Full time
    For contractors
    Work at office

    Autodesk

    Boston, MA
    1 day ago
  •  ...Job Title: Manager, Information Security Grade: TBD Department: Information Technology Reports To: Senior Manager, IT Infrastructure FLSA Status:...  ...forensics, event logging systems, authentication methods, remote and local web application security, and penetration testing... 
    Remote work
    Local area
    Weekend work

    Building Service 32BJ Benefit Funds

    New York, NY
    1 day ago
  •  ...Director of Information Security Duration: Full-Time Location: Remote About BigRio : BigRio is a Digital Transformation...  ...Security Director to lead and manage enterprise-wide cybersecurity...  ...Governance, Risk & Compliance (GRC) Establish and manage a... 
    Remote work
    Full time

    Saviance

    Boston, MA
    2 days ago
  • $169k - $296k

     ...collaboration, join us!Figma's Information Security team is growing and looking for a Strategic Program Manager to drive strategic...  ...organization, working closely with GRC, Security Operations, Security...  ...held from one of our US hubs or remotely in the United States. What... 
    Remote work
    Minimum wage
    Full time
    Local area
    Flexible hours

    Figma

    New York, NY
    3 days ago
  •  ...Job Description Job Description Job Summary: We are seeking a Manager, Information Security to lead the execution of our Security Operations and Engineering program. This is a hands-on, player-coach role: you will manage a small, high-caliber team of 2–3 direct... 
    Remote work
    Work at office
    Local area

    Neumo Holdings LLC

    West Jordan, UT
    8 days ago
  • $145.75k - $300.07k

     ...care about. Within EPD, the Security team plays a critical role in...  ....Staff Technical Program Manager, SecurityThis role is within...  ...and stakeholders.5+ years of information security, risk and/or compliance...  ...about our working model.#LI-REMOTE#LI-DM57At Pinterest we believe... 
    Remote work
    Work experience placement
    Work at office
    Local area
    Relocation
    Relocation package

    Pinterest

    San Francisco, CA
    5 days ago
  • The Manager, Information Security leads the operational and incident-response function within the Information Protection - Network Security (IP-NS...  ...service portfolio (Zscaler ZIA/ZPA, Imprivata VAM, and Legacy Remote Access tools). The successful candidate will bring proven... 
    Remote work
    Contract work
    Visa sponsorship
    Flexible hours

    Mayo Clinic

    Rochester, MN
    3 days ago
  • $212k - $230k

     ...of Governance, Risk, and Compliance (GRC) to define and execute security governance strategies. This role requires strong expertise in managing compliance, overseeing third-party risks...  ...have over 8 years of experience in information security and a proven record in... 
    Remote job

    Clover Health

    New York, NY
    5 days ago
  •  ...seeking a Director of Governance, Risk, and Compliance (GRC) to define and execute security governance and risk strategy for a public, technology-enabled...  ..., Internal Audit, and the Board. A senior leader will manage a vendor for GRC services and ensure audit readiness and... 
    Remote job

    DaParrot Ltd

    Brooklyn, NY
    2 days ago
  • $90k - $160k

    Washington, D.C.Information Security /Full-time /HybridA World-Changing CompanyPalantir builds...  ...missing children, and more.The RoleAs a GRC Program Manager, you are the engine behind Palantir's...  ...are a few roles that allow for “Remote” work on an exceptional basis. If you... 
    Remote work
    Full time
    Work experience placement
    Work at office
    Local area
    Immediate start
    Work from home
    Relocation package

    Palantir Technologies

    Washington DC
    4 days ago
  • $112k - $190.5k

     ...fraternal benefit society that provides financial security to members and their families through our...  ...of Governance, Risk, and Compliance (GRC) is a resourceful and experienced information security leader responsible for managing, and continuously improving, the... 
    Full time
    Temporary work
    Work experience placement
    Flexible hours

    knightsofc

    New Haven, CT
    8 days ago
  •  ...Solutions, and Eco Solutions. Our management philosophy, "Jeong-do...  ...DescriptionLG Electronics' Information Display Division is seeking...  ...Solutions Manager - Networks & Security to join our rapidly growing...  ...signage hardware and cloud-based Remote Monitoring & Management (RMS... 
    Remote work
    Full time
    Temporary work
    For contractors
    Work at office
    Local area
    Immediate start

    LG Electronics

    Lincolnshire, IL
    4 days ago
  • $140k - $245k

     ...looking for an expert Technical Program Manager (TPM) to support our Security Operations team. In this role, you’...  ...be held from one of our US hubs or remotely in the United States. What you’...  ...~ Strong understanding of information security principles and controls, including... 
    Remote work
    Full time
    Work from home

    Figma

    Remote
    a month ago
  • $200k - $260k

     ...About The Role: The Technical Manager, Cybersecurity is a hands‑on...  ...This role bridges strategic security direction with day‑to‑day technical...  ...and implement appropriate remote and local access controls for...  ..., Computer Science, Information Systems, or related technical... 
    Remote work
    Contract work
    Local area

    Atomic Machines

    Emeryville, CA
    5 days ago
  •  ...of users across the globe. As we scale, securing our infrastructure, protecting sensitive...  ...policy, and product. Technical Program Managers (TPMs) play a critical leadership role in...  ...crossing the spectrum of insider threat, information security, physical security, and... 
    Remote work
    Full time

    OpenAI

    Remote
    9 days ago
  •  ...IT Hardware, Software, Cloud Services, Information Security technologies, and related professional services. This role independently manages sourcing projects from business requirements...  ...in California, Colorado, New York or remote jobs that can be performed in California... 
    Remote work
    Full time
    Contract work
    Temporary work
    Flexible hours
    Shift work

    Sandisk

    Milpitas, CA
    7 days ago
  •  ...Only W2 no C2C Job Title: IT Security ANALYST (GRC) Job ID: 13235 Client:...  ...800-53R5 (Must have) Risk Management Framework (RMF) Windows/Unix...  ...to join our team as a Information Security Analyst, (ISA) contractor...  ...participate in the State's Remote Work Program and are able... 
    Remote work
    Contract work
    For contractors
    Local area
    Work from home
    Visa sponsorship
    Flexible hours

    S-R-International-Inc

    Phoenix, AZ
    4 days ago
  • Ellenco Estágios e Treinamentos is seeking a Senior Information Security GRC Analyst to manage security audits and compliance efforts. The role requires...  ...understanding of NIST standards. This position allows for remote work and involves managing multiple information... 
    Remote job

    Ellenco Estágios e Treinamentos

    New York, NY
    5 days ago
  •  ...new industry develops. As a remote co-located team, we're inspired...  ...commerce. Role Whatnot's Security GRC team is dedicated to building...  ...protect our users' data and information as if it were our own. As...  ...Leading our security risk management program to prioritize security... 
    Remote work
    Local area
    Work from home
    Home office

    Whatnot

    Los Angeles, CA
    1 day ago
  •  ...technology consulting firm is seeking an Infosec or GRC Leader to implement and manage Information Security Management Systems and coordinate risk assessments....  ...chain risk management. The role is available remotely for a duration of 6+ months. #J-18808-Ljbffr Avantdigitalnow
    Remote job

    Avantdigitalnow

    San Francisco, CA
    1 day ago
  • Medasource is seeking an IT GRC Analyst to join our IT Security and Governance team on a...  ...-to-hire basis, working remotely within the USA. The role...  ...regulatory compliance, risk management, audit readiness, policy...  ...has 3-5 years in information security/GRC, healthcare... 
    Remote job
    Contract work

    Medasource

    Brooklyn, NY
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Manager, Information Security (GRC) (Remote). Be the first to apply!