Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Manager, Information Security (GRC) (Remote)

Neumo Holdings LLC

Salem, OR
  • Remote job

Job Description

Job Description

Job Summary:

We are seeking a Manager, Information Security (GRC) to own and mature Neumo's Governance, Risk, and Compliance program. This role is critical to maintaining our SOC 1, SOC 2, and PCI certifications and to raising our overall information security maturity. You will build the foundation for data governance, risk acceptance and exceptions processes, and a recurring cadence of monthly, quarterly, and annual risk mitigation. This is a hands-on leadership role: you will manage 1–2 direct reports while personally driving audits, risk assessments, and control automation, and participate in incident management alongside the broader security team.

You will be the connective tissue between security engineering, legal, engineering, and executive leadership: translating regulatory and contractual requirements into practical controls, and translating control performance into risk language leadership can act on.

This role directly protects Neumo's ability to do business: Our certifications are foundational to customer trust and revenue. You will have the mandate to modernize how we manage risk and compliance, including building automation and AI-driven workflows that scale the program without scaling headcount linearly.


Duties and Responsibilities:

Leadership & Program Ownership

  • Own and execute Neumo's GRC strategy and roadmap, in partnership with the CISO.
  • Manage, mentor, and grow 1–2 direct reports supporting compliance, risk, and audit activities.
  • Set the foundation for data governance: data classification, ownership, retention, and handling standards.
  • Build and maintain the risk register; lead monthly, quarterly, and annual risk mitigation cycles.
  • Own the risk acceptance and policy exception process, including documentation, approval workflows, and periodic review.
  • Report on compliance posture, audit status, and risk trends to executive stakeholders and the board as needed.

Compliance & Audit Management

  • Own end-to-end readiness and execution for SOC 1, SOC 2, and PCI DSS audits, including evidence collection, auditor coordination, and remediation tracking.
  • Maintain and continuously improve the internal control framework mapped to SOC 1/2, PCI, and other applicable frameworks (e.g., ISO 27001, NIST CSF).
  • Track control ownership, testing cadence, and control health across the organization using the GRC platform and Jira.
  • Partner with engineering and IT teams to close control gaps and drive remediation of audit findings within SLA.

Risk, Automation & Cross-Functional Work

  • Design and implement control automation to reduce manual evidence collection and continuous control monitoring (CCM).
  • Leverage AI/LLM tooling to accelerate evidence review, policy drafting, control testing, and risk analysis, with appropriate human oversight.
  • Participate in incident management as the GRC/risk representative: assessing regulatory and contractual impact and ensuring proper documentation.
  • Manage third-party/vendor risk assessments and questionnaires (customer security questionnaires, vendor due diligence).
  • Partner with Legal and Privacy on data protection, regulatory, and contractual compliance requirements.


Education and Experience:

  • 6+ years of experience in GRC, information security compliance, or IT audit, including experience managing or mentoring others.
  • Direct experience owning SOC 1, SOC 2, and PCI DSS compliance programs end-to-end, including audit management.
  • Hands-on experience with GRC platforms (e.g., Vanta, Drata, ServiceNow GRC, OneTrust, Archer, or similar).
  • Experience building risk management programs: risk registers, risk acceptance/exception processes, and recurring risk mitigation cadences.
  • Foundational experience with data governance concepts (classification, ownership, retention).
  • Relevant certifications (e.g., CISA, CRISC, CISSP, CISM) are a plus but not required.


Knowledge, Skills and Abilities:

  • Strong working knowledge of Jira for control tracking, remediation workflows, and cross-team coordination.
  • Demonstrated ability to build or deploy control automation and continuous control monitoring.
  • Comfort leveraging AI tools to scale GRC operations (evidence review, policy generation, risk analysis).
  • Ability to participate effectively in incident management, translating technical incidents into risk and compliance impact.
  • Excellent written and verbal communication skills; able to translate technical and regulatory detail for executive audiences.



Work Environment :

  • Office setting with a moderate noise level.
  • The employee will work at an individual workstation, using a telephone and computer.
  • Periodic flexibility outside standard business hours may be required to support audits or incident response.


Physical Demands
:

  • Must be able to remain seated for extended periods.
  • Regular use of a computer and other office machinery, such as printers and copy machines.
  • Occasional movement around the office.
  • Frequent communication via telephone.


Neumo Summary:

With the backing of four decades of public sector expertise and corporate capability, Neumo has successfully supported government services. Neumo was honored and recognized for four (4) consecutive years as a GovTech 100 Company representing the top 100 companies focused on making a difference in and selling to state and local government agencies across the United States.

Neumo is committed to helping communities thrive and brings a wealth of experience combined with innovation. Today, Neumo offers more administrative and financial support to government officials than any other organization. And with a responsive, client-focused approach, we foster partnerships that give our customers the certainty they need to accomplish more.

Neumo offers a competitive benefits and compensation package and are looking for team members who will thrive in our dynamic environment.

Neumo is an Equal Opportunity Employer. Selection for a position will be made without regard to race, religion, national origin, sex, political affiliation, marital status, non-disqualifying physical handicap, and age.

Vacancy posted 10 days ago
Similar jobs that could be interesting for youBased on the Manager, Information Security (GRC) (Remote) in Salem, OR vacancy
  •  ...Job Description Job Description Job Summary: We are seeking a Manager, Information Security (GRC) to own and mature Neumo's Governance, Risk, and Compliance program. This role is critical to maintaining our SOC 1, SOC 2, and PCI certifications and to raising our... 
    Remote job
    Work at office
    Local area

    Neumo Holdings LLC

    Carrollton, TX
    10 days ago
  •  ...Director of Information Security Duration: Full-Time Location: Remote About BigRio : BigRio is a Digital Transformation...  ...Security Director to lead and manage enterprise-wide cybersecurity...  ...Governance, Risk & Compliance (GRC) Establish and manage a... 
    Remote work
    Full time

    Saviance

    Boston, MA
    3 days ago
  •  ...Summary The Director of Information Security owns Fetch's security...  ...function end to end: vulnerability management and AppSec, incident...  ...forensics, security architecture, GRC/compliance, third-party risk...  ...offices, or you can work fully remotely from anywhere in the US. We'... 
    Remote work
    Full time
    For contractors
    Work at office
    Flexible hours

    Fetch

    United States
    1 day ago
  •  ...Job Description Job Description Job Summary: We are seeking a Manager, Information Security to lead the execution of our Security Operations and Engineering program. This is a hands-on, player-coach role: you will manage a small, high-caliber team of 2–3 direct... 
    Remote job
    Work at office
    Local area

    Neumo Holdings LLC

    Carrollton, TX
    10 days ago
  •  ...for good. Responsibilities The Security Operations Manager is a working manager who both leads and...  ...contributes to the organization’s information security operations. This role owns day...  ...Tuesday, Wednesday, and Thursday (remote work available Monday and Friday, as... 
    Remote work
    Work at office
    Monday to Friday

    KeHE Distributors, LLC

    Naperville, IL
    24 days ago
  • $167k - $244k

     ...As Marqeta’s Information Security Manager you will lead Vulnerability Management and establish a Data Security...  ...First . This role can be performed remotely anywhere within the United States. We’...  ...Tenable/Snyk workflows into CI/CD and GRC/Risk registers. Background in data... 
    Remote job
    Work at office
    Flexible hours

    Marqeta

    Remote
    more than 2 months ago
  • $175.4k - $283.8k

     ...join us!This role is remote, but distance is no barrier...  ...related to security audits (SOC 2, ISO 270...  ...teams to ensure correct information is provided to customers...  ...reduce workload for PANW GRC teamsNavigate InfoSec...  ...maintain Third Party Risk Management for all unique-to-... 
    Remote work
    Full time

    Palo Alto Networks

    New York, NY
    11 days ago
  •  ...SUMMARY: The Director - Information Security is a "CISO" type role. This is the role of a strategic...  ...appropriate standards and controls, manage security technologies, and direct the...  ...and 401K are provided Hybrid Role - Remote work 2 days per week (after 90 days) [Wednesdays... 
    Remote work
    2 days per week

    The Projex Group

    Camden, NJ
    3 days ago
  •  ...Director Of Information Security As the Director of Information Security, you will lead the execution and operational performance of MRO...  ...measurable outcomes to improve security operations, vulnerability management, incident response, control effectiveness, and business... 
    Remote work

    Q-Centrix by MRO

    United States
    4 days ago
  •  ...Director of Information Security Company: Akamai Work Type: Remote Employment: Full Time Location: US Seniority: Senior Level Technologies: FedRAMP, NIST RMF, NIST SP 800-53, Vulnerability management, Encryption, Security monitoring, Cloud security Requirements: 12+ years... 
    Remote work
    Full time

    Akamai

    United States
    4 days ago
  •  ...Director Of Information Security The Director of Information Security is responsible for leading...  ..., governance, operations, identity management, and risk management program across Network...  ...connectivity, digital platforms, and remote operations. Develop security... 
    Remote work
    For contractors

    Weatherford

    Houston, TX
    2 days ago
  • $185k - $296k

     ...Manager, Security Operations San Francisco, CA • New York, NY • United States Figma is growing...  ...Engineering, Platform Security, IT, GRC, and Legal to strengthen our detection...  ...can be held from one of our US hubs or remotely in the United States. What You'll Do... 
    Remote work
    Minimum wage
    Full time
    Local area
    Flexible hours

    Figma

    United States
    21 hours ago
  •  ...and thrive in an environment informed by creativity and thinking that...  ...The Director of Information Security is responsible for developing...  ...office with Friday being a remote work day. This schedule is subject...  ...investment. Develop and manage the information security... 
    Remote work
    Summer work
    Work at office
    Local area
    Flexible hours
    Night shift

    Centric Brands Inc.

    Greensboro, NC
    4 days ago
  •  ...The Manager, Information Security leads Jewelers Mutual's security engineering and operations function, overseeing information security engineers and...  ..., DevOps, cloud engineering, application teams, and GRC to strengthen security controls, mature operational processes... 
    Contract work
    Work experience placement

    Jewelers Mutual Insurance Company

    Eastern, KY
    1 day ago
  • $150k - $180k

     ...Testing as a Service platform manages customers' attack surfaces by...  ...into the root causes of security risks. We are committed to making...  ...Authorized environment. For more information, please visit We are...  ...Management, and Compliance (GRC) tools. ~ Experience with event... 
    Contract work

    Synack

    San Mateo, CA
    4 days ago
  •  ...Description Job Description   Job Title:            Manager, Information Security Grade:              TBD Department:      Information...  ...forensics, event logging systems, authentication methods, remote and local web application security, and penetration... 
    Remote work
    Local area
    Weekend work

    Building Service 32BJ Benefit Funds

    New York, NY
    9 days ago
  • $225k - $275k

     ...applications create predictable, informed, and convenient...  ...end-to-end business management software, embedded payment...  ...the Chief Information Security Officer (CISO) and...  ...Automated Compliance (GRC Modernization)Continuous...  ...working with distributed and remote team environments.... 
    Remote work
    Full time
    Work at office
    Local area
    Immediate start
    Shift work

    EverCommerce

    Denver, CO
    2 days ago
  •  ...highly skilled and experienced Director, Information Security for our Security Engineering and...  ...key functions Leadership and Team Management: Develop and execute the company's...  ...0 employees in mostly hybrid and 100% remote roles across the United States with... 
    Remote work
    Contract work
    Work from home

    ACHIEVE

    Tempe, AZ
    2 days ago
  • $81.15k - $83.57k

     ...Job Description Job Description Description The Information Technology Manager & Information Security Officer is a hybrid leadership and hands-on...  ...user experience across sites  Coordinate onsite and remote support coverage across all assigned locations  Infrastructure... 
    Remote work
    Local area

    Action for Boston Community Development

    Cambridge, MA
    6 days ago
  • $175.1k - $236.9k

     ...customer who builds on it. AWS Security works at the forefront of the...  ...for a Security Engineering Manager to lead a team of application...  ...degree in Computer Science, Information Security, or a related field-...  ...techniques- Experience managing remote team membersAmazon is an... 
    Remote work
    Flexible hours

    Amazon

    Austin, TX
    3 days ago
  • $175.1k - $236.9k

     ...engineers, supply chain specialists, security experts, operations managers, and other vital roles. You’ll...  ...standards, passion, and discipline for information security. The highest level of...  ...testing techniques- Experience managing remote team membersAmazon is an equal... 
    Remote work
    Flexible hours

    Amazon

    Seattle, WA
    a month ago
  • $207k - $285k

     ...across the globe. As we scale, securing our infrastructure,...  ...and product. Technical Program Managers (TPMs) play a critical leadership...  ...spectrum of insider threat, information security, physical security,...  ...$165.4K - $285KLocationUS - Remote; New York City; San Francisco... 
    Remote work
    Work at office
    Local area
    Flexible hours

    OpenAI

    Washington DC
    a month ago
  •  ....About the role: The Samsara Security team is looking for an Enterprise...  ...Security Technical Program Manager (TPM) to help drive key...  ...also has: Experience working on Information Security and/or Compliance programs...  ...: a flexible, employee-led remote model, a professional... 
    Remote work
    Full time
    Flexible hours

    Samsara

    Dallas, TX
    14 days ago
  •  ...Manager, Security Operations Location: Remote – USA Lead the Future of AI-Driven Cyber Defense We are seeking a Manager, Security Operations, to...  ...Bachelor’s degree in computer science, Cybersecurity, Information Technology, or a related field (or equivalent... 
    Remote work

    E-Solutions

    United States
    4 days ago
  •  ...Manager, Security Operations At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored...  ...Leave for all new parents ~ Health & wellness stipend ~ Remote workspace, internet, and cellphone stipend ~ Commuter... 
    Remote work
    Work experience placement
    Work at office
    Immediate start
    Flexible hours

    Vanta

    United States
    21 hours ago
  •  ...Manager, Security Operations Forward Financing is a financial technology company based in...  ...donation match. Forward is proud to be a remote-first company, keeping workplace...  ...U.S. Equal Opportunity Employment Information Forward Financing is proud to be an... 
    Remote work
    Work at office
    Work from home
    Flexible hours

    Forward Financing

    United States
    3 days ago
  •  ...Role: Cybersecurity GRC Consultant Location: Remote Duration: 6 months...  ...solution architectures| security controls| and cloud solutions...  ...ServiceNow| or similar tools to manage risk lifecycle activities...  ...| and rationalization of information security policies|... 
    Remote work

    Programmers.io

    Remote
    3 days ago
  • $210k - $250k

     ...PubMatic is seeking a Director of Information Security to lead and evolve our global security...  ...velocity, plan phased implementations and manage change adoption across technical and non...  ...days "in office" and 2 days "working remotely") that is intended to maximize... 
    Remote work
    Work at office

    Pubmatic

    Redwood City, CA
    3 days ago
  • $185k - $296k

     ...Manager, Security OperationsSan Francisco, CA • New York, NY • United StatesFigma is growing our...  ...Security Engineering, Platform Security, IT, GRC, and Legal to strengthen our detection...  ...can be held from one of our US hubs or remotely in the United States.What You'll Do At... 
    Remote work
    Minimum wage
    Full time
    Local area
    Flexible hours

    Figma

    New York, NY
    2 days ago
  • $200k - $260k

     ...looking for a seasoned Engineering Manager to lead Aircall's Security Engineering organisation. This is a...  ...and Governance, Risk & Compliance (GRC). You will grow an established team...  ...Governance, Risk & Compliance (GRC / Information Security) Own and continuously improve... 
    Worldwide

    Aircall.io, Inc.

    Bellevue, WA
    8 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Manager, Information Security (GRC) (Remote). Be the first to apply!