Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Governance Risk Compliance (GRC) Manager

Antithesis

GRC Role at Antithesis

We are looking for our first dedicated GRC hire. This is an ownership, hands-on role.

You will build and run our compliance program end-to-end — not as a support function, but as a core part of how we earn and keep customer trust. At a company like ours, where enterprise customers need to trust us with their most sensitive infrastructure, GRC is a sales function as much as it is an operational one.

A note on what we mean by "ownership." This is not a role where you maintain a checklist someone else built. You will own the GRC calendar, the Vanta instance, the policy library, the audit evidence, and the security questionnaire queue. If something in our compliance posture is broken, that's yours to fix. If a deal is stalling because a prospect has a 40-question security questionnaire, you're the one who unblocks it.

This is an individual contributor role. It is not a CISO, not a security engineering role, and not a penetration tester. You will not own security architecture or vulnerability management — but you will need strong enough relationships with the people who do to keep those programs feeding your compliance work on time.

This role will initially report to the VP, Strategic Initiatives within the Operations team, with a strong dotted line to the Head of Infrastructure. Within the first ~3-6 months, we will collaboratively identify the long-term reporting structure for this role. This role will work closely with Operations, Legal, People (HR), Engineering, and IT.

What You'll Own

SOC 2 & Audit Management

  • Own our SOC 2 audit end-to-end, including the transition from point-in-time to a rolling 12-month window
  • Serve as the primary liaison with our external auditors
  • Maintain the evidence repository and ensure controls are documented, tested, and current
  • Own and maintain Vanta as the system of record for our compliance program

Policy & Controls

  • Maintain and continuously improve our policy library — keeping policies accurate, readable, and actually followed
  • Run the GRC calendar: tabletop exercises, prepare security committee meetings, security awareness training, and annual reviews
  • Identify control gaps and drive remediation across Engineering, IT, HR, and Operations

Trust Center & Customer-Facing Compliance

  • Own and maintain our trust center
  • Manage the inbound security questionnaire queue for enterprise sales — turn these around quickly and accurately with a sales-forward mindset to accelerate deals
  • Be the go-to resource for enterprise prospects who need to understand our security and compliance posture
  • Support vendor security reviews on both sides: evaluating vendors we onboard and participating in customer-side reviews of us

Risk Management

  • Maintain the risk register and lead regular risk review cadences
  • Identify, document, and escalate risks across people, vendors, and infrastructure

Additional

  • Support penetration testing, vulnerability management, and security architecture — Engineering and Infra lead these, but you keep them on-track and ensure findings are tracked and remediated
  • Lay groundwork for future frameworks as the business requires: e.g., ISO 27001, GDPR, FedRAMP
  • Support Legal and commercial contracting on security-related clauses and DPAs
  • Support HR policy development in partnership with the Head of HR, including security-related employee policies, acceptable use, and onboarding/offboarding procedures
Who You'll Work With

You will interface regularly with Engineering & Infrastructure, Legal, HR, Finance, and Operations. You will represent Antithesis externally in front of enterprise buyers, auditors, and security-conscious prospects.

Requirements

Required

  • 3–5 years of GRC, compliance, or IT audit experience, ideally in a SaaS or highly technical environment
  • Hands-on experience with multiple SOC 2 audits — not advisory, not adjacent, but in the room with the auditors and owning the evidence
  • Ability to go deep on our technical architecture, understand what we do and why — including bespoke features of our environment such as NixOS
  • SRE, security engineering, engineering or equivalent technical background (education and/or experience)
  • Experience with AWS and GCP infrastructure, and Infrastructure as code (IaC)
  • Strong written communication (including customer-facing communications) and comfortable writing policy, not just reviewing it
  • Ability to learn quickly in a fast-paced, high-growth environment

Nice to Have

  • Relevant certifications: CISA, CISSP, CISM, CCSK, or similar
  • Familiarity with ISO 27001, GDPR, or FedRAMP frameworks
  • Experience supporting Legal on DPAs or commercial security schedules
  • Experience owning or heavily using a GRC tool (Vanta preferred)
Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Governance Risk Compliance (GRC) Manager in Vienna, VA vacancy
  •  ...Security is offering an exciting internship opportunity for a Governance, Risk, and Compliance (GRC) Analyst. This role is perfect for students or recent...  ...-on experience in cybersecurity, compliance, and risk management. The internship provides the potential to convert into... 
    Suggested
    Full time
    Internship

    Ruleset Security

    Arlington, VA
    3 days ago
  •  ...Security is offering an exciting internship opportunity for a Governance, Risk, and Compliance (GRC) Analyst. This role is perfect for students or recent...  ...‑on experience in cybersecurity, compliance, and risk management. The internship provides the potential to convert into... 
    Suggested
    Remote job
    Full time
    Internship

    Ruleset Security

    Arlington, VA
    3 days ago
  •  ...seeking a Cybersecurity Analyst in Alexandria, VA, focused on governance, risk, and compliance (GRC) activities. The ideal candidate should have a minimum...  ...certifications. You will lead compliance efforts, manage security controls, and provide risk analysis reporting to... 
    Suggested

    Medium

    Alexandria, VA
    19 hours ago
  • $53.32k - $83.86k

     ...institution is seeking a Remote Analyst for the Finance Risk Office responsible for supporting CFO risk management functions, with a salary range of $53,321 - $83,857...  ...responsibilities include maintaining the Finance GRC content, ensuring data accuracy, and assisting with... 
    Suggested
    Remote job
    Work at office

    PenFed Credit Union

    Mc Lean, VA
    3 days ago
  •  ...As the IT SOX (Sarbanes-Oxley Act) Compliance Manager, you will step into a high-...  ...Design: Oversee the annual IT SOX risk assessment, scoping, and materiality...  ...environments. Tools: Proficiency with Governance, Risk, and Compliance (GRC) tools, with Workiva experience... 
    Suggested
    Work at office
    Local area

    Appian Corporation

    McLean, VA
    24 days ago
  • Director, Cybersecurity Compliance Job Description Purpose & Scope: The Director...  ...organization’s information security governance, risk, and compliance (GRC) program. This role is accountable...  ...regulatory requirements, establishing risk management frameworks, and independently... 

    VHC Health

    Arlington, VA
    2 days ago
  • $89.6k - $194k

     ...is seeking a Senior SAP GRC and Application...  ...implementation project for a large government contract. As a senior-...  ...monitoring, and audit/compliance reporting. This...  ...continuous improvement and risk mitigation. Oversee security...  ...skills to manage multiple priorities, deliverables... 
    Contract work
    Work at office
    Local area
    2 days per week

    CGI

    Fairfax, VA
    4 days ago
  • CoStar Group is seeking a Compliance Manager in Arlington, VA, to oversee and manage their legal compliance program. The successful candidate will help develop policies, conduct risk assessments, and provide training on compliance matters. This role requires a proactive... 

    United Cerebral Palsy of Georgia

    Arlington, VA
    1 day ago
  •  ...performance! Core One is seeking Governance, Risk, and Compliance Analyst / Information System Security...  ...TS/SCI w/ Poly clearance. The GRC Analyst / Information System Security...  ...remediation of security incidents. Manage account recertifications, access reviews... 

    Core One

    McLean, VA
    more than 2 months ago
  • Compliance Manager, Corporate Compliance Location: Arlington, VA | Monday-Friday...  ...standards to ensure governance across CoStar’s global brands...  ...Manager will identify compliance risks and mitigation strategies,...  ...processes and related GRC workflow tools, provide point... 
    Full time
    Local area
    Monday to Friday

    Visual Lease

    Arlington, VA
    19 hours ago
  •  ...in McLean, Virginia is seeking an Analyst for the Information Security Trust team. This role involves supporting the governance, risk, and compliance program and ensuring adherence to security policies across the company. The ideal candidate will have a passion for security... 
    Work at office

    Appian

    Mc Lean, VA
    2 days ago
  • $99k - $225k

    Job Number: R0228967 Senior Product Manager, Compliance Our Product team is defining a new product-led growth business within...  ...of cutting‑edge AI technology to disrupt traditional governance, risk, and compliance (GRC) methods. You will be able to leverage the decades of... 
    Full time
    Contract work
    Part time
    Local area

    Phase2 Technology

    Mc Lean, VA
    4 days ago
  •  ...accessible and affordable across the nation. Our Impact The Compliance Testing (CT) team conducts risk‑based, independent testing across the Enterprise to...  ...and efficacy of Freddie Mac’s compliance risk management activities and identify potential non‑compliance with... 
    Work at office

    Fairygodboss

    Mc Lean, VA
    1 day ago
  • Cybersecurity Compliance & Readiness Manager page is loaded## Cybersecurity Compliance & Readiness Managerlocations...  ...point of contact; manage scope, risks, and delivery quality* Review...  ...understanding of cybersecurity controls, governance, and risk management practices* Prior... 
    Temporary work
    Flexible hours

    Dovel Technologies, Inc

    Mc Lean, VA
    3 days ago
  •  ...Virginia is seeking a Director of Cybersecurity Compliance to lead the organization's information security governance, risk, and compliance program. This position...  ...years of experience in IT security and risk management within the healthcare sector, with leadership... 

    VHC Health

    Arlington, VA
    2 days ago
  •  ...looking for a Cybersecurity Analyst in Alexandria, VA to lead governance, risk, and compliance activities, ensuring compliance with DoD cybersecurity...  ...You will have a role in monitoring security controls and managing vulnerability assessments. The ideal candidate holds... 

    PingWind

    Alexandria, VA
    2 days ago
  • $219k - $329k

    Freddie Mac, based in McLean, Virginia, is seeking a Senior Director - Risk Analytics to lead governance and oversight for stress testing and capital management programs. This influential role requires strong leadership, quantitative expertise, and experience in risk management... 

    Freddie Mac

    Mc Lean, VA
    4 days ago
  • A leading federal services provider is seeking a Cybersecurity Analyst in Alexandria, VA. This role includes managing governance, risk, and compliance activities to ensure compliance with DoD requirements. The ideal candidate will have at least 10 years of relevant experience... 

    PingWind

    Alexandria, VA
    4 days ago
  • Capital One National Association is looking for a Risk Manager in McLean, Virginia. This role will involve developing sustainable policy programs and collaborating with internal stakeholders to enhance policy quality and adherence. Ideal candidates will possess strong... 

    Capital One National Association

    Mc Lean, VA
    19 hours ago
  • $142k - $212k

    Freddie Mac, based in McLean, Virginia, is seeking a Multifamily Counterparty Risk Management Manager to join the Servicer Compliance group. The successful candidate will evaluate compliance, manage risk activities, and support the team’s objectives to enhance housing finance... 

    Fairygodboss

    Mc Lean, VA
    19 hours ago
  • $142k - $212k

     ...nation. We are looking for a Multifamily Counterparty Risk Management Manager to join the Servicer Compliance group within the Counterparty Risk & Compliance...  ..., multifamily and the secondary mortgage markets; Government Sponsored Enterprise ("GSE") experience preferred.... 
    Full time
    Work at office

    Fairygodboss

    Mc Lean, VA
    1 day ago
  • $151.9k - $173.4k

    Compliance Privacy Advisor, Manager The Capital One Privacy Compliance team is seeking a Manager, Compliance...  ...with a passion for mitigation privacy risks at a tech focused finance...  ...certification, or AIGP (Certified AI Governance Professional). At this time, Capital... 
    Full time
    Temporary work
    Part time
    Local area

    Capital One

    McLean, VA
    1 day ago
  • $4,000 per month

     ...program. The Quality Control Manager will provide coaching and training...  ...addresses areas of elevated risk and improve loan quality....  ...• Monitor changes to agency, government, and investor quality control...  ...invoicing system to ensure accuracy, compliance, and operational efficiency.... 
    Temporary work
    Flexible hours

    Stanley Martin Homes , LLC

    Fairfax, VA
    4 days ago
  • $100k - $150k

     ...Job Title: Manager of Contract Compliance Location : Reston, VA Work Type: Hybrid Remote Work...  ...function, ensuring efficient operations, governance, and regulatory compliance across...  ...prime contract management and drives risk mitigation. This position will advance... 
    Full time
    Contract work
    Part time
    Work experience placement
    Remote work

    Gridiron IT

    Reston, VA
    2 days ago
  • Director Compliance Advisory - Personal Loans Corporate Compliance...  ...Director will also own the management and oversight of a robust Compliance...  ...to identify tomorrow’s risks, and able to integrate...  ..., Legal, Compliance Central Governance, and the US Card Business Risk... 
    Full time
    Work at office
    Local area
    Flexible hours

    Capital One

    Mc Lean, VA
    3 days ago
  • The Squires Group in Arlington, VA is seeking an experienced SAP Security Analyst to support a major ERP modernization initiative in a federal environment. This position involves implementing and maintaining application security within an SAP S/4HANA landscape, with 75%...
    Remote job

    The Squires Group

    Arlington, VA
    1 day ago
  • Capital One is seeking an experienced risk manager to lead a team focused on Anti-Money Laundering (AML) risk assessment and regulatory strategies. The role requires a proven leader capable of influencing senior management and external authorities, along with a comprehensive... 

    Information Technology Senior Management Forum

    Mc Lean, VA
    2 days ago
  •  ...Director, Security Compliance Known for being a great place to work and build a career, KPMG...  ...specialist-level knowledge of risk, compliance, and information security controls...  ...innovation and challenging the status quo; manage and review those team members' work product... 
    Temporary work
    H1b
    Local area

    Kpmg India

    McLean, VA
    2 days ago
  •  ...Description: The Compliance Manger is responsible for all multifamily compliance functions...  ...these activities for the Portfolio Management division. The primary responsibility of...  ...management ~ Knowledge of laws governing lending and credit practices, housing finance... 
    For contractors
    Work at office
    Local area

    District of Columbia Housing Finance Agency

    Oakton, VA
    2 days ago
  • $145k - $217k

     ...Overview: This Software Development Manager is a key team member of Freddie Mac's Enterprise Risk Management (ERM) Technologies...  .... The Financial Crimes and Compliance technology team partners with the...  ...teams. Experience with model governance and AI. Bachelor's degree or equivalent... 
    Full time
    Work experience placement
    Work at office
    Immediate start

    Fairygodboss

    Mc Lean, VA
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Governance Risk Compliance (GRC) Manager. Be the first to apply!