Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Manager, Information Security (GRC) (Remote)

Neumo Holdings LLC

Job Description

Job Description

Job Summary:

We are seeking a Manager, Information Security (GRC) to own and mature Neumo's Governance, Risk, and Compliance program. This role is critical to maintaining our SOC 1, SOC 2, and PCI certifications and to raising our overall information security maturity. You will build the foundation for data governance, risk acceptance and exceptions processes, and a recurring cadence of monthly, quarterly, and annual risk mitigation. This is a hands-on leadership role: you will manage 1–2 direct reports while personally driving audits, risk assessments, and control automation, and participate in incident management alongside the broader security team.

You will be the connective tissue between security engineering, legal, engineering, and executive leadership: translating regulatory and contractual requirements into practical controls, and translating control performance into risk language leadership can act on.

This role directly protects Neumo's ability to do business: Our certifications are foundational to customer trust and revenue. You will have the mandate to modernize how we manage risk and compliance, including building automation and AI-driven workflows that scale the program without scaling headcount linearly.


Duties and Responsibilities:

Leadership & Program Ownership

  • Own and execute Neumo's GRC strategy and roadmap, in partnership with the CISO.
  • Manage, mentor, and grow 1–2 direct reports supporting compliance, risk, and audit activities.
  • Set the foundation for data governance: data classification, ownership, retention, and handling standards.
  • Build and maintain the risk register; lead monthly, quarterly, and annual risk mitigation cycles.
  • Own the risk acceptance and policy exception process, including documentation, approval workflows, and periodic review.
  • Report on compliance posture, audit status, and risk trends to executive stakeholders and the board as needed.

Compliance & Audit Management

  • Own end-to-end readiness and execution for SOC 1, SOC 2, and PCI DSS audits, including evidence collection, auditor coordination, and remediation tracking.
  • Maintain and continuously improve the internal control framework mapped to SOC 1/2, PCI, and other applicable frameworks (e.g., ISO 27001, NIST CSF).
  • Track control ownership, testing cadence, and control health across the organization using the GRC platform and Jira.
  • Partner with engineering and IT teams to close control gaps and drive remediation of audit findings within SLA.

Risk, Automation & Cross-Functional Work

  • Design and implement control automation to reduce manual evidence collection and continuous control monitoring (CCM).
  • Leverage AI/LLM tooling to accelerate evidence review, policy drafting, control testing, and risk analysis, with appropriate human oversight.
  • Participate in incident management as the GRC/risk representative: assessing regulatory and contractual impact and ensuring proper documentation.
  • Manage third-party/vendor risk assessments and questionnaires (customer security questionnaires, vendor due diligence).
  • Partner with Legal and Privacy on data protection, regulatory, and contractual compliance requirements.


Education and Experience:

  • 6+ years of experience in GRC, information security compliance, or IT audit, including experience managing or mentoring others.
  • Direct experience owning SOC 1, SOC 2, and PCI DSS compliance programs end-to-end, including audit management.
  • Hands-on experience with GRC platforms (e.g., Vanta, Drata, ServiceNow GRC, OneTrust, Archer, or similar).
  • Experience building risk management programs: risk registers, risk acceptance/exception processes, and recurring risk mitigation cadences.
  • Foundational experience with data governance concepts (classification, ownership, retention).
  • Relevant certifications (e.g., CISA, CRISC, CISSP, CISM) are a plus but not required.


Knowledge, Skills and Abilities:

  • Strong working knowledge of Jira for control tracking, remediation workflows, and cross-team coordination.
  • Demonstrated ability to build or deploy control automation and continuous control monitoring.
  • Comfort leveraging AI tools to scale GRC operations (evidence review, policy generation, risk analysis).
  • Ability to participate effectively in incident management, translating technical incidents into risk and compliance impact.
  • Excellent written and verbal communication skills; able to translate technical and regulatory detail for executive audiences.

Work Environment :

  • Office setting with a moderate noise level.
  • The employee will work at an individual workstation, using a telephone and computer.
  • Periodic flexibility outside standard business hours may be required to support audits or incident response.


Physical Demands
:

  • Must be able to remain seated for extended periods.
  • Regular use of a computer and other office machinery, such as printers and copy machines.
  • Occasional movement around the office.
  • Frequent communication via telephone.


Neumo Summary:

With the backing of four decades of public sector expertise and corporate capability, Neumo has successfully supported government services. Neumo was honored and recognized for four (4) consecutive years as a GovTech 100 Company representing the top 100 companies focused on making a difference in and selling to state and local government agencies across the United States.

Neumo is committed to helping communities thrive and brings a wealth of experience combined with innovation. Today, Neumo offers more administrative and financial support to government officials than any other organization. And with a responsive, client-focused approach, we foster partnerships that give our customers the certainty they need to accomplish more.

Neumo offers a competitive benefits and compensation package and are looking for team members who will thrive in our dynamic environment.

Neumo is an Equal Opportunity Employer. Selection for a position will be made without regard to race, religion, national origin, sex, political affiliation, marital status, non-disqualifying physical handicap, and age.

Vacancy posted 25 days ago
Similar jobs that could be interesting for youBased on the Manager, Information Security (GRC) (Remote) in Salem, OR vacancy
  • $160k - $180k

     ...Job Title: Senior Manager, I nformation Security & IT Reports To: Chief Technology...  ...Department: Technology – Information Security & IT Work Location: Irvine, CA or US-Remote About Genea As leaders...  ...platforms, and automated GRC tools preferred. ~... 
    Remote work
    Full time
    Local area
    Flexible hours

    Genea

    Remote
    3 days ago
  • $150k - $175k

     ...Annually Description: Our client is currently seeking a Manager, IT Security, GRC. This is FT perm role and hybrid in Burlington, NJ Position...  ...) plays a critical mid-level leadership role within the Information Security function, responsible for translating strategy... 
    Suggested
    Permanent employment

    Judge Group, Inc.

    Burlington, NJ
    4 days ago
  •  ...development of a comprehensive information security and compliance strategy, the full-time remote Senior Director of Information Security...  ...of the security program, manage key teams, and serve as the executive...  ...'s information security and GRC program, setting strategic roadmaps... 
    Remote work
    Full time

    Virtual Vocations Inc

    United States
    1 day ago
  •  ...leading software company providing comprehensive business management solutions for law firms and other professional services organizations...  ...of business management software for law firms, and the Information Security team protects the systems, data, and client trust that... 
    Remote work

    Aderant

    United States
    5 days ago
  •  ...Title: Senior Project Manager (IT/Security)(Remote) Duration: 6 Months Location: Remote On‑site (Springfield, IL) presence during the...  ...client is seeking a Senior Project Manager to support the Information Security team in planning, executing, and delivering IT security... 
    Remote work
    Work at office

    Dsnworldwide

    Springfield, MA
    1 day ago
  •  ...the Role The Director of Information Security owns Artisight's security...  ...auditors. This role is remote, based in the United States,...  ...security, identity and access management, and AI/agent architecture...  ...environments. Experience with GRC tooling and control-... 
    Remote work
    Worldwide

    Artisight

    United States
    3 days ago
  •  ...Summary The Director of Information Security owns Fetch's security...  ...function end to end: vulnerability management and AppSec, incident...  ...forensics, security architecture, GRC/compliance, third-party risk...  ...offices, or you can work fully remotely from anywhere in the US. We'... 
    Remote work
    Full time
    For contractors
    Work at office
    Flexible hours

    Fetch

    United States
    5 days ago
  •  ...Job Description Job Description Job Summary: We are seeking a Manager, Information Security to lead the execution of our Security Operations and Engineering program. This is a hands-on, player-coach role: you will manage a small, high-caliber team of 2–3 direct... 
    Remote work
    Work at office
    Local area

    Neumo Holdings LLC

    West Jordan, UT
    25 days ago
  • Job Title: Manager, Information Security Grade: TBD Department: Information Technology Reports To: Senior Manager, IT Infrastructure FLSA Status...  ...forensics, event logging systems, authentication methods, remote and local web application security, and penetration... 
    Remote work
    Local area
    Weekend work

    BLDG SVC 32 B-J

    New York, NY
    7 days ago
  • $81.15k - $83.57k

     ...Job Description Job Description Description The Information Technology Manager & Information Security Officer is a hybrid leadership and hands-on...  ...user experience across sites  Coordinate onsite and remote support coverage across all assigned locations  Infrastructure... 
    Remote work
    Local area

    Action for Boston Community Development

    Boston, MA
    a month ago
  • $167k - $244k

     ...As Marqeta’s Information Security Manager you will lead Vulnerability Management and establish a Data Security...  ...First . This role can be performed remotely anywhere within the United States. We’...  ...Tenable/Snyk workflows into CI/CD and GRC/Risk registers. Background in data... 
    Remote job
    Work at office
    Flexible hours

    Marqeta

    Remote
    more than 2 months ago
  • $96.39k - $162k

     ...About the role: The Samsara Security team is looking for an...  ...Enterprise Security Technical Program Manager (TPM) to help drive key...  ...Experience working on Information Security and/or Compliance programs...  ...success: a flexible, employee-led remote model, a professional... 
    Remote work
    Full time
    Flexible hours

    Samsara

    Remote
    4 days ago
  • $169k - $296k

     ...collaboration, join us! Figma's Information Security team is growing and looking for a Strategic Program Manager to drive strategic...  ...organization, working closely with GRC, Security Operations, Security...  ...held from one of our US hubs or remotely in the United States. What... 
    Remote work
    Minimum wage
    Full time
    Local area
    Flexible hours

    Figma

    San Francisco, CA
    3 days ago
  • DocuSign seeks a Director of Security GRC Product Delivery to lead a unified GRC Pod and drive...  ...to embed controls into CI/CD pipelines, manage audits, and provide executives with...  ...risk reduction. This is a hybrid in-office/remote leadership role in San Francisco. #J-18... 
    Remote work
    Work at office

    UNAVAILABLE

    San Francisco, CA
    3 days ago
  •  ...the design, implementation of security and governance solutions...  ...in SAP security architecture, GRC frameworks, and compliance standards...  ..., authorizations, and user management. • Lead the deployment and...  ...degree in Computer Science, Information Security, or related field.... 
    Remote work

    3B Staffing LLC

    United States
    2 days ago
  • $175.4k - $283.8k

     ...join us!This role is remote, but distance is no barrier...  ...related to security audits (SOC 2, ISO 270...  ...teams to ensure correct information is provided to customers...  ...reduce workload for PANW GRC teamsNavigate InfoSec...  ...maintain Third Party Risk Management for all unique-to-... 
    Remote work
    Full time

    Palo Alto Networks

    New York, NY
    5 days ago
  •  ...Director of Information Security Company: Akamai Work Type: Remote Employment: Full Time Location: US Seniority: Senior Level Technologies: FedRAMP, NIST RMF, NIST SP 800-53, Vulnerability management, Encryption, Security monitoring, Cloud security Requirements: 12+ years... 
    Remote work
    Full time

    Akamai

    United States
    3 days ago
  •  ...SUMMARY: The Director - Information Security is a "CISO" type role. This is the role of a strategic...  ...appropriate standards and controls, manage security technologies, and direct the...  ...and 401K are provided Hybrid Role - Remote work 2 days per week (after 90 days) [Wednesdays... 
    Remote work
    2 days per week

    The Projex Group

    Camden, NJ
    2 days ago
  •  ...Role: Cybersecurity GRC Consultant Location: Remote Duration: 6 months...  ...solution architectures| security controls| and cloud solutions...  ...ServiceNow| or similar tools to manage risk lifecycle activities...  ...| and rationalization of information security policies|... 
    Remote work

    Programmers.io

    Remote
    2 days ago
  • $162k - $219k

     ...Overview As the Director of Information Security, you will lead the execution and operational performance of MRO’s information security...  ...outcomes to improve security operations, vulnerability management, incident response, control effectiveness, and business alignment... 
    Remote work

    MRO

    United States
    3 days ago
  •  ...Director Of Information Security The Director of Information Security is responsible for leading...  ..., governance, operations, identity management, and risk management program across Network...  ...connectivity, digital platforms, and remote operations. Develop security... 
    Remote work
    For contractors

    Weatherford

    Houston, TX
    1 day ago
  • $185k - $296k

     ...Manager, Security Operations San Francisco, CA • New York, NY • United States Figma is growing...  ...Engineering, Platform Security, IT, GRC, and Legal to strengthen our detection...  ...can be held from one of our US hubs or remotely in the United States. What You'll Do... 
    Remote work
    Minimum wage
    Full time
    Local area
    Flexible hours

    Figma

    United States
    4 days ago
  •  ...and thrive in an environment informed by creativity and thinking that...  ...The Director of Information Security is responsible for developing...  ...office with Friday being a remote work day. This schedule is subject...  ...investment. • Develop and manage the information security... 
    Remote work
    Summer work
    Work at office
    Flexible hours
    Night shift

    Centric Brands Inc.

    Greensboro, NC
    1 day ago
  •  ...Director, Information Security Agfa HealthCare, a division of the Agfa-Gevaert Group, headquartered...  ...of security operations. Location: Remote: US What You'll Do: Scaled and...  ...threat intelligence, vulnerability management, and incident response with a focus on... 
    Remote work

    Agfa

    United States
    2 days ago
  •  ...Security Project ManagerLocation: 14700 Caribbean Way, Miramar, Fl 33027 (4 days per week onsite, remote Fridays) Duration: 1 yearJob Description - Royal Caribbean Group (RCG) is seeking a seasoned Information Security Project Manager who will be responsible for managing... 
    Remote work
    Work at office

    RIT Solutions

    Tampa, FL
    1 day ago
  •  ...Director Of Security OperationsAdvance Auto Parts is seeking a seasoned...  ...the operational arm of our Information Security program. This role...  ...response, vulnerability management, and security monitoring across...  ...is 4 days in office, 1 day remote per week, based at our... 
    Remote work
    Work at office
    Local area
    1 day per week

    Advance Auto Parts

    Raleigh, NC
    3 days ago
  • $55 - $80 per hour

    IT GRC Analyst Remote, USA Compensation: $55 - $80 per hour Contract...  ...GRC Analyst to join the IT Security and Governance team on a 6-...  ...compliance, risk management, audit readiness, policy administration...  ...WHAT YOU'LL DO Perform information security risk assessments... 
    Remote work
    Hourly pay
    Full time
    Contract work
    Work at office
    Immediate start
    Flexible hours

    Medasource

    United States
    1 day ago
  •  ...listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Director of Information Security based in the United States. As...  ...with experience and qualifications. Remote opportunity within the United States.... 
    Remote work

    Jobgether

    United States
    3 days ago
  • $125.3k - $196.79k

     ...What Information Security and Risk contributes to Cardinal Health Information Technology oversees...  ...conducts incident response, threat management, vulnerability scanning, virus management...  ...risk assessments. We are a remote-first team that values collaboration,... 
    Remote work
    Full time
    Temporary work
    Local area
    Immediate start
    Flexible hours

    Cardinal Health

    Remote
    4 days ago
  • Job Description: Senior Information Security GRC Analyst Department: Information Security Job Title: Senior Information...  ...) Analyst Reports To: Information Security GRC Manager / Head of Information Security Location: Remote, Hybrid, or Office-Based as assigned Line Management... 
    Remote work
    Contract work
    Work at office

    Golden Technology

    Raleigh, NC
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Manager, Information Security (GRC) (Remote). Be the first to apply!