Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Security GRC Manager

$182k - $295k

Hex Technologies

ABOUT THE ROLE

Hex is looking for our first Security GRC Manager to build, scale, and own our security and privacy compliance programs. This role is pivotal in setting the foundation for how Hex meets regulatory, customer, and industry obligations across frameworks including SOC 2, ISO 27001, ISO 27701, HIPAA, GDPR, CCPA, PCI DSS, and emerging requirements that matter to our customers.

As the inaugural GRC hire, you will architect the systems, processes, and culture that ensure Hex operates with integrity, earns customer trust, and maintains continuous audit readiness. You’ll partner closely with engineering, business operations, and our go-to-market teams to develop a world-class GRC function empowered by automation, thoughtful risk management, and clear communication.

This role is both strategic and hands-on: you’ll define long-term program roadmaps while also rolling up your sleeves to run audits, perform risk assessments, and answer customer security questionnaires. You must be technical enough to understand how Hex’s product works under the hood and translate that understanding into defensible compliance, clear documentation, and trust-building narratives for customers.

WHAT YOU WILL DO

SECURITY, PRIVACY & COMPLIANCE PROGRAM OWNERSHIP

* Own and mature Hex’s security and privacy compliance program across SOC 2, ISO 27001, ISO 27701, HIPAA, GDPR, CCPA, PCI DSS, and other frameworks relevant to our business. * Ensure continuous audit readiness: maintain controls, gather evidence, manage auditors, and implement improvements. * Track regulatory and industry changes, advising Hex leadership on impact and recommended responses. * Maintain and develop core security policies, standards, and procedures, tailoring them to Hex’s real operating environment.

RISK ASSESSMENT & GOVERNANCE

* Own Hex’s risk management lifecycle: identify, assess, track, and drive mitigation of security, privacy, operational, and regulatory risks. * Build lightweight but effective governance processes, ensuring clear ownership, documentation, and accountability. * Partner with Engineering and Security to ensure technical controls map appropriately to compliance requirements.

CUSTOMER TRUST & SALES ENABLEMENT

* Serve as the primary owner of customer and prospect security questionnaires, risk assessments, and contractual security provisions. * Manage and improve Hex’s Trust Center / trust portal, ensuring accurate and compelling communication of Hex’s security posture. * Collaborate with Sales, Customer Success, and Legal on security-related deal support, including negotiating security terms. * Build defensible, scalable processes for handling increasing customer scrutiny.

AUDIT & EVIDENCE MANAGEMENT

Lead internal and external audits from planning through remediation. Establish automated or repeatable evidence collection processes, reducing

manual toil and ensuring consistency. * Coordinate cross-functional contributors to meet audit timelines and quality requirements.

THIRD-PARTY RISK MANAGEMENT

* Own Hex’s third-party risk management program, including vendor assessments, reviews, and ongoing monitoring. * Build a lightweight but rigorous process aligned with Hex’s scale and risk profile. * Partner with Procurement, Security, and IT to ensure defensible vendor decisions.

SECURITY CULTURE, ENABLEMENT & AWARENESS

Define and run security awareness training tailored to Hex’s environment. Evangelize GRC internally—driving a culture of risk-aware decision-making and

operational excellence. * Document processes, playbooks, and FAQs to make compliance and risk management accessible across the organization.

PROGRAM AUTOMATION & TOOLING

* Evaluate, implement, and administer GRC tools (evidence automation, Trust Center platforms, access review tooling, vendor management systems). * Build automation into compliance wherever possible—access reviews, evidence collection, user lifecycle processes, vendor workflows, and more. * Partner with engineering teams to understand Hex’s infrastructure and embed compliance requirements into CI/CD, logging, monitoring, and cloud security controls.

--------------------------------------------------------------------------------

WHO YOU MIGHT BE

TECHNICAL & COMPLIANCE EXPERTISE

* 5–8+ years in GRC, compliance, security engineering, privacy, audit, or a related field. * Deep familiarity with frameworks such as SOC 2, ISO 27001, ISO 27701, PCI DSS, HIPAA, GDPR, and associated security controls. * Experience running or contributing significantly to audit cycles and certification processes. * Technical literacy in cloud-native environments (AWS preferred), SaaS architectures, and modern security tooling. * Ability to understand and explain product architecture, data flows, and control implementations to auditors and customers.

PROGRAM BUILDING & OWNERSHIP

Experience building or maturing GRC programs at a high-growth company. Strong project/program management skills: you can set roadmaps, drive

timelines, and deliver on deadlines. * Comfort creating order out of ambiguity—you design the playbook, not just follow one.

CUSTOMER-FACING & CROSS-FUNCTIONAL SKILLS

* Exceptional communicator with the ability to translate complex topics into clear, concise, customer-ready language. * Strong stakeholder management skills—you can collaborate with engineering, sales, legal, executives, and prospects with equal effectiveness. * Empathic, diplomatic, and able to balance customer expectations with business realities.

PROFESSIONAL COMPETENCIES

Highly organized and detail-oriented; rigorous in execution. Naturally curious with a continuous-improvement mindset. Thrives in distributed, fast-paced environments. Comfortable making risk-based decisions and presenting tradeoffs to

leadership.

PREFERRED (BUT NOT REQUIRED)

* Certifications such as CISA, CISM, CISSP, CRISC, ISO 27001 Lead Implementer/Auditor. * Experience with GRC automation platforms (e.g., Vanta, Drata, Tugboat, SecureFrame) and Trust Center tools (e.g., Conveyor, SafeBase). * Familiarity with data protection operations, privacy programs, DPIAs, or AI/ML compliance contexts.

--------------------------------------------------------------------------------

WHY YOU’LL LOVE THIS ROLE

* You’ll build a foundational function from scratch—your work defines how Hex earns and maintains customer trust. * You’ll work across the entire company, influencing product decisions, customer outcomes, and security posture. * You’ll shape a modern, automation-forward GRC program rather than inheriting legacy complexity. * You’ll partner with world-class engineers and operators who care deeply about doing things the right way. * You’ll have meaningful ownership, visibility, and impact as Hex continues to scale.

--------------------------------------------------------------------------------

OUR STACK

Our product is a web-based notebook and app authoring platform. Our frontend is built with Typescript and React, using a combination of Apollo GraphQL and Redux for managing application state and data. On the backend, we also use Typescript to power an Express/Apollo GraphQL server that interacts with Postgres, Redis, and Kubernetes to manage our database and Python kernels. Our backend is tightly integrated with our infrastructure and CI/CD, where we use a combination of Terraform, Helm, and AWS to deploy and maintain our stack.

--------------------------------------------------------------------------------

In addition to our unique culture, Hex proudly offers a competitive total rewards package, including but not limited to, market-benched salary & equity, comprehensive health benefits, and flexible paid time off.

The salary range for this role is: $182,000 - $295,000

The salary range shown may be a reflection of additional factors such as geographical location and skill ranges/levels we’re open to. Placement in the salary range will be decided upon completion of the interview process, taking into account factors like leaving room for growth, internal fairness & parity, your demonstrated skills, and the depth of your experience. Our Recruiting team will be able to provide more details during the interview process.

By submitting an application the candidate consents to the use of their personal information in accordance with the Hex Privacy policy: [

Hex Technologies uses AI-assisted tools as part of our application review process, including for resume screening and fraud detection. These tools help our team evaluate applications and verify applicant information. All AI-generated recommendations are reviewed by a member of our recruiting team before any hiring decision is made. No application is automatically rejected based solely on an AI tool's output.

Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Security GRC Manager in New York, NY vacancy
  • $1,000 per month

     ...Security GRC Manager Credit Genie is a mobile-first financial wellness platform designed to help individuals take control of their financial future. We leverage artificial intelligence to provide personalized insights and are building a financial ecosystem by offering... 
    Suggested
    Temporary work
    Work at office
    Immediate start
    Remote work
    Flexible hours

    Credit Genie

    New York, NY
    14 hours ago
  • $212k - $230k

     ...in the United States is seeking a Director of Governance, Risk, and Compliance (GRC) to define and execute security governance strategies. This role requires strong expertise in managing compliance, overseeing third-party risks, and leading audits. The ideal candidate... 
    Suggested
    Remote work

    Clover Health

    New York, NY
    2 days ago
  • £55k - £75k per year

     ...Want to lead security operations that directly help clients strengthen their security posture? As a GRC Operational Security Manager, you will implement the strategy, policies and working practices defined within the Information Security Management System for your assigned... 
    Suggested
    Permanent employment
    Full time
    Remote work
    Flexible hours

    Sopra Steria

    New York, NY
    2 days ago
  • $138k - $219k

     ...Security Architecture Manager Location: New York City, Los Angeles, San Francisco The Protiviti Career provides opportunity to learn, inspire...  ...tooling (Wiz, Prisma, Defender for Cloud, Okta/Entra, ServiceNow GRC, Archer, and the like) ~ Advanced or architecture-focused... 
    Suggested
    Full time
    Work at office
    Local area
    Remote work
    Flexible hours

    Protiviti

    New York, NY
    4 days ago
  •  ...turn ideas into reality. We Are Platform Security professionals develop and deliver...  ...deployment of SAP application Security Roles, SAP GRC Access and Process Control solutions,...  ...role based security, and ERP vulnerability management solutions that minimize the impact of... 
    Suggested
    Contract work
    Work experience placement
    Live in
    Work at office
    Local area

    Accenture

    New York, NY
    2 days ago
  •  ...One mission. One team. That’s OneStudyTeam. The Director of Security leads enterprise security strategy and execution across governance, risk, compliance, and security engineering. This role manages the GRC and Security Engineering teams, partners with technology and... 
    Contract work
    For contractors
    For subcontractor
    Work at office
    Remote work
    Visa sponsorship
    Work visa

    OneStudyTeam, Inc.

    New York, NY
    2 days ago
  •  ...Title: Security Program Manager Location: Remote (U.S., New York / EST Time Zone Preferred) About Rhymetec Rhymetec was founded in New York City...  ...year. Qualifications 4+ years working in cybersecurity and GRC 2+ years of program management Demonstrated ability to function... 
    Summer work
    Remote work

    RHYMETEC LLC

    New York, NY
    2 days ago
  • $500 per month

     ...broker‑dealers, investment advisors, wealth managers, hedge funds, and crypto exchanges—over 9...  ...the Global CISO, the Head of Information Security (APAC) will drive the regional security,...  ...information security, cybersecurity or GRC, preferably in fintech or financial services... 
    Local area
    Home office

    Alpaca

    New York, NY
    15 hours ago
  • $70k

     ...JOB TITLE: Security Manager JOB POSTED: March 26, 2026 DEPARTMENT: Security Services REPORTED TO: Associate Director, Security Services  SCHEDULE: FT, Exempt, Tue-Sat, 8 am-4pm EST (subject to change) COMPENSATION: $70,000 annual POSITION OVERVIEW... 
    Full time
    Work at office
    Local area
    Remote work
    All shifts
    Shift work
    Weekend work
    Afternoon shift

    School of Visual Arts

    New York, NY
    5 days ago
  • $110k - $114.75k

     ...Security Manager (SSL) Securitas Security Services USA, Inc. is the global leader in protective services, delivering specialized guarding, advanced technology solutions, and comprehensive risk management to clients across a wide range of industries. Our mission is... 
    Contract work
    Work at office

    Securitas

    New York, NY
    3 days ago
  •  ...Position Description: The ServiceNow Identity Security Manageris responsible forleading the execution and delivery of identity security...  ...authorization visibility solutions using ServiceNow and Veza. The Manager works closely with client stakeholders, architects, and... 
    Remote work

    Templar Shield

    New York, NY
    2 days ago
  • $85k - $95k

     ...offices in Colorado, Florida, and Washington DC, Fairstead owns and manages a portfolio of more than 30,000 apartments, including pipeline,...  ..., innovation, partnership, dedication, and integrity. The Security Manager provides strategy and activities related to information... 
    Work at office
    Immediate start
    All shifts
    Flexible hours
    Shift work

    Fairstead ESC LLC

    New York, NY
    11 hours ago
  • $28 - $30 per hour

     ...Manager – Venue Security US Concerts is seeking a Manager – Venue Security. The Security Manager is responsible for the overall management of the security department to ensure guest, employee, artist and venue safety. Also, controls cost and ensures total guest satisfaction... 
    Hourly pay
    Local area

    Live Nation Entertainment

    Brooklyn, NY
    14 hours ago
  • $43 per hour

     ...Security Manager MoMA is hiring for a Security Manager Position in Midtown, New York City. Base pay starts at $43/hr. #TransparentPay #TransparentSalaries #NYCJobs #SalaryTransparency At The Museum of Modern Art and MoMA PS1, we celebrate creativity, openness, tolerance... 
    Local area
    Flexible hours
    Afternoon shift

    BANDANA

    New York, NY
    14 hours ago
  • $70k - $90k

     ...Trump International Hotel and Tower is seeking a Security Manager who will lead, coach, and counsel our Security Team as well as manage all functions within the Security Department. The Security Manager will also direct and implement the organization's safety and security... 
    Local area

    Trump International Hotel and Tower Chicago

    New York, NY
    11 hours ago
  •  ...deliver agile technology solutions, AI‑driven talent strategies, and a FastTrack program to develop tech talent. Summary The IT Security Manager develops and implements IT security standards, best practices, and systems to ensure the security of information systems... 
    Work experience placement
    Flexible hours

    Cook Systems

    New York, NY
    2 days ago
  • $227k - $303k

     ...Learn more at What You'll Do: The Security Products team at CoreWeave is responsible...  ...IAM, future encryption lifecycle and key management capabilities, and supporting...  ...Security to translate customer, compliance, and GRC requirements into clear technical designs... 
    Permanent employment
    Temporary work
    Casual work
    Work at office
    Remote work
    Flexible hours

    CoreWeave

    New York, NY
    1 day ago
  • $161.6k - $202k

     ...patients - and that responsibility demands a security and compliance program that scales with...  .... We're building out our dedicated GRC team to improve and mature our program!...  ...SOC 2, PCI-DSS, HIPAA), third-party risk management, security awareness training, and technical... 
    Work from home
    Flexible hours

    Headway - Design & Development

    New York, NY
    1 day ago
  • $70.7k

     ...Become a Site Security Manager at GardaWorld! As a Security Site Manager, you will oversee the daily operations of a security site, ensuring the safety and security of the premises. You'll manage security personnel, coordinate with clients, handle incidents, and... 
    For contractors
    Local area
    Monday to Friday
    Weekend work

    GardaWorld

    Brooklyn, NY
    4 days ago
  •  ...Introduction The Corporate Security Manager oversees all physical security, emergency preparedness, and protective operations for the company’s flagship office building in New York City. This high-profile role requires a seasoned professional with extensive law enforcement... 
    Contract work
    Work at office
    Local area

    IBM

    New York, NY
    2 days ago
  •  ...creativity and humility are our daily motivation. Does it sound like you? Maybe you are a Zara person. Purpose The Security Manager – Field Operations supports the protection of company assets, including employees, customers, facilities, and merchandise across... 
    Local area

    ZARA

    New York, NY
    1 day ago
  •  ...Audit Board (GRC) Implementation Specialist Audit Board (GRC) Implementation Specialist Direct message the job poster from Minisoft...  ...AuditBoard platform, including setting up the control library, managing hierarchical structures, platform settings, inventories, and user... 
    Contract work
    For contractors
    Remote work

    Minisoft Technologies

    New York, NY
    4 days ago
  • $75k - $85k

     ...Director Of Security & Operations The person filling this position is expected, under general direction, to ensure the smooth day-to...  ...address and investigate client complaints). Assist the Program Manager in providing oversight for all aspects of the program in his/... 
    Full time
    Contract work
    Immediate start

    CAMBA

    Brooklyn, NY
    4 days ago
  • $70k - $74k

     ...Director of Security & Operations CAMBA is a community of staff, volunteers, clients, donors, neighbors and partners who work together...  ...investigate client complaints). Assist the Senior Program Manager in providing oversight for all aspects of the program in his/her... 
    Permanent employment
    Full time
    Contract work
    Immediate start

    CAMBA

    Brooklyn, NY
    3 days ago
  • $170k - $210k

     ...A leading security consultancy in the United States is seeking a Security Operations Leader to drive their global operations strategy. This role involves leading a high-performing team for 24/7 security monitoring, incident response, and ensuring regulatory compliance... 

    The Security Executive Council

    New York, NY
    2 days ago
  • $150k - $190k

     ...A leading technology service provider is seeking a skilled Security Operations Manager to work remotely, providing cybersecurity operations support for federal projects. The ideal candidate will have a Bachelor’s degree, at least 10 years of experience in cybersecurity... 
    Remote work

    ECS Limited

    New York, NY
    2 days ago
  • $70k - $85k

     ...Amalgamated Bank seeks Corporate Security Manager who is responsible for the oversight and administrative management of Physical Security for Amalgamated Bank branches and offices, to include related persons and property within. Essential Job Functions: # Responsible... 
    For contractors
    Work experience placement
    Work at office
    Remote work
    Visa sponsorship
    Work visa

    Amalgamated Bank of NY

    New York, NY
    3 days ago
  • $114.1k - $268.18k

     ...consider a career in Advisory. KPMG is currently seeking a Manager, SAP Security for our Consulting practice. Responsibilities: Plan and execute client engagements focusing on SAP security, SAP GRC, and the audit readiness of complex SAP environments (... 
    H1b
    Local area

    KPMG

    New York, NY
    2 hours ago
  • $60.7k - $90k

     .../Non-Exempt Anticipated Salary Range: $60,697.00 - $90,000.00 Security Clearance: TS/SCI Level of Experience: Mid Employee Referral Amount...  ...TS/SCI required. This individual wil provide Program Security Management Support, to include: Develop and implement security policy and... 
    Hourly pay
    Full time
    Local area
    Worldwide

    HII Mission Technologies Division

    New York, NY
    15 hours ago
  •  ...Bright Defense · SecOps Team · Now Hiring Information Security Manager SecOps — Continuous Monitoring & Client Risk Management Full-Time • Remote...  ...& compliance (required) 3–6 years in information security, GRC, or compliance‑adjacent roles Hands‑on experience with SOC 2,... 
    Full time
    Immediate start
    Remote work
    Flexible hours

    Bright Defense, LLC.

    New York, NY
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Security GRC Manager. Be the first to apply!