Manager of Governance, Risk and Compliance (GRC)
$119k - $155kSpyCloud
SpyCloud is on a mission to make the internet a safer place by disrupting the criminal underground. SpyCloud's solutions thwart cyberattacks and protect more than 4 billion accounts worldwide. Cybersecurity is an exciting, evolving space, and being at the forefront of the fight to disrupt cybercrime makes SpyCloud a special place to work. If you're driven to align your career with a fantastic mission, look no further!
SpyCloud is seeking a hands-on and operationally focused Manager of Governance, Risk and Compliance (GRC) to lead and mature critical compliance, governance, and risk management initiatives across the organization. This role will own day-to-day execution of SpyCloud's compliance and security governance programs while helping scale operational processes that support the company's security posture and customer trust objectives. The ideal candidate brings strong experience operating security compliance programs within cloud-native and SaaS environments and has deep familiarity with frameworks such as SOC 2, ISO 27001, NIST, and CMMC 2.0. This individual will work cross-functionally with Privacy, Security Engineering, DevOps, Legal, Product Engineering, and business stakeholders to drive compliance readiness, risk mitigation, policy governance, third-party risk management, and audit coordination. This role is highly collaborative and execution-oriented, requiring both strategic judgment and operational ownership. The Manager of GRC will also directly manage at least one team member while helping evolve SpyCloud's overall security governance maturity. What You'll Do:- Governance & Compliance Operations
- Own and manage SpyCloud's day-to-day GRC and compliance operations across multiple frameworks, including SOC 2, ISO 27001, NIST, and CMMC 2.0.
- Lead internal and external audit coordination activities, evidence collection, remediation tracking, and control validation efforts.
- Maintain and improve security policies, standards, procedures, and governance documentation.
- Drive ongoing compliance readiness activities and operationalize scalable compliance processes across the business.
- Partner closely with Legal, Security Engineering, DevOps, and Engineering teams to ensure alignment on security and regulatory requirements.
- Risk Management
- Conduct enterprise risk assessments and facilitate ongoing risk identification, tracking, remediation, and reporting processes.
- Develop and maintain risk registers and support leadership reporting on security and compliance risks.
- Lead third-party/vendor risk management activities, including security reviews and vendor assessments.
- Support customer trust initiatives, including security questionnaires, compliance inquiries, and due diligence requests.
- Cloud Security & Security Governance
- Partner with DevOps and Security Engineering teams to strengthen cloud security governance across AWS and cloud-native environments.
- Ensure security controls are aligned with compliance frameworks and operational best practices.
- Support implementation and monitoring of governance controls related to cloud infrastructure, identity management, logging, vulnerability management, and secure development practices.
- Contribute to ongoing security awareness and compliance education initiatives across the organization.
- Leadership & Cross-Functional Collaboration
- Manage and mentor direct report(s), supporting professional growth and operational excellence within the GRC function.
- Collaborate with technical and non-technical stakeholders to drive accountability and operational maturity.
- Help prioritize remediation efforts and compliance initiatives based on business risk and organizational goals.
- Support the Senior Director of Governance, Risk and Information Security in scaling SpyCloud's overall security governance program.
- Experience
- 6+ years of experience in Governance, Risk, and Compliance (GRC), Information Security, Security Compliance, or related fields.
- Demonstrated hands-on experience managing operational compliance programs within SaaS, cloud, or cybersecurity environments.
- Proven experience supporting and maintaining compliance frameworks such as:
- SOC 2
- ISO 27001
- NIST
- CMMC 2.0
- Experience leading audits, managing evidence collection, and coordinating remediation activities.
- Experience with third-party/vendor risk management and enterprise risk assessment processes.
- Experience working cross-functionally with Legal, Engineering, DevOps, Security, and executive stakeholders.
- Education
- Bachelor's degree in Cybersecurity, Information Security, Computer Science, Business, or related field, or equivalent practical experience.
- Skills
- Strong understanding of security governance, compliance operations, and risk management practices.
- Familiarity with cloud security concepts and governance within AWS or similar cloud environments.
- Strong organizational and project management skills with the ability to manage multiple priorities simultaneously.
- Excellent written and verbal communication skills.
- Ability to translate compliance requirements into practical operational processes.
- Strong analytical, documentation, and problem-solving skills.
- Prior people management or mentorship experience preferred.
- Certifications
- One or more of the following certifications strongly preferred:
- CISSP
- CISA
- CRISC
- CISM
- ISO 27001 Lead Auditor or Lead Implementer
- Experience within cybersecurity SaaS organizations.
- Experience supporting customer-facing security and trust initiatives.
- Familiarity with security tooling, cloud-native environments, and DevSecOps practices.
- Experience with AI governance, security governance automation, or modern GRC tooling.
- Experience working in fast-paced, high-growth technology environments.
- 401(k) with Employer Contribution
- Health, Vision, and Dental Insurance
- Health Savings Account (HSA) available with Employer Contribution
- Employer Paid Life, Short-term, and Long-term Disability Insurance
- Generous PTO Plan and 16 paid holidays per year
- Retirement Savings Plan with Employer Contribution
- Employer Provided Private Health Insurance and Healthcare Cashplan
- Employer Paid Life Insurance and Income Replacement
- Generous Holiday Plan and 14 paid holidays per year
About SpyCloud: SpyCloud transforms recaptured darknet data to disrupt cybercrime. Its automated identity threat protection solutions leverage advanced analytics and AI to proactively prevent ransomware and account takeover, detect insider threats, safeguard employee and consumer identities, and accelerate cybercrime investigations. SpyCloud's data from breaches, malware-infected devices, and successful phishes also powers many popular dark web monitoring and identity theft protection offerings. Customers include seven of the Fortune 10, along with hundreds of global enterprises, mid-sized companies, and government agencies worldwide. Headquartered in Austin, TX, SpyCloud is home to more than 200 cybersecurity experts whose mission is to protect businesses and consumers from the stolen identity data criminals are using to target them now. To learn more and see insights on your company's exposed data, visit spycloud.com. Our Mission: Our mission is to make the internet a safer place by disrupting the criminal underground. Together with our customers and partners, we aim to end criminals' ability to profit from stolen information. Who We Are: SpyCloud is a place for innovative, collaborative, and problem-solvers to thrive. Individually, we're amazing, but together, we're unstoppable. We celebrate diversity and various perspectives and aim to create an inclusive and supportive environment for all. We are proud to be an Equal Employment Opportunity and Affirmative Action employer of choice. All aspects of employment decisions will be based on merit, performance, and business needs. We do not discriminate on the basis of any status protected under federal, state, or local law. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or other applicable legally protected characteristics. Women, minorities, individuals with disabilities, and protected veterans are encouraged to apply. SpyCloud complies with applicable state and local laws governing nondiscrimination in employment. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training. SpyCloud expressly prohibits any form of workplace harassment. Improper interference with the ability of SpyCloud's employees to perform their job duties may result in discipline up to and including discharge. SpyCloud shares the right to work and participates in the E-Verify program in all locations. If you need assistance or accommodation due to a disability, you may contact us. Our Culture: Our culture is something really special. We're all driven to disrupt the cybercriminal economy as we keep customer accounts safe from compromise. We support a truly worthy and serious mission, but we have fun doing it together. If you are driven, inventive, and collaborative, you'll fit right in. SpyCloud's Recruitment Policy: We will never ask an applicant for sensitive or personal financial information during the recruitment process. We advise all applicants seeking employment with SpyCloud to review available information on recruitment fraud. Anyone who suspects that they have been contacted by someone falsely representing SpyCloud should email View email address on click.appcast.io. Compensation Transparency Policy: At SpyCloud, we believe in transparency and fairness in compensation. We strive to ensure that all employees are fairly compensated for their contributions, and we openly discuss our compensation philosophy and structure. We are committed to providing competitive salaries and benefits packages to attract and retain top talent, and we encourage open dialogue and feedback regarding compensation matters. Learn more and apply: SpyCloud Careers SpyCloud is not sponsoring visas at this time. For applicants residing in California, please click here to read SpyCloud's CCPA Notice. For applicants residing in the UK, please click here to read SpyCloud's Employee Privacy Notice.
- ...Sr. Manager IT Governance, Risk and Compliance (GRC) The Sr. Manager in IT Governance, Risk and Compliance (GRC) leads our IT compliance and risk management initiatives. This role will be responsible for overseeing IT SOX audit readiness and execution, managing IT risk...SuggestedWork at officeLocal areaRelocation
$112k
...Sr Manager, InfoSec Governance Risk and Compliance (GRC) (San Francisco Bay Area, California, United States) Founded in 2000, Ivalua is a leading global provider of cloud-based procurement solutions. COMPANY OVERVIEW At Ivalua we are a global community of exceptional...SuggestedWork at officeWorldwide- ...Information Security Governance, Risk, Compliance (GRC) Supervisor Schedule: Monday - Friday (40 hrs/wk) 8:00 AM - 5:00 PM Department: IT General... ..., healthcare regulatory requirements, and the NIST Risk Management Framework. This role serves as a critical bridge between...SuggestedWork at officeMonday to Friday
$190k - $215k
...Governance, Risk & Compliance (GRC) Manager Sigma is seeking an experienced GRC Manager to lead and scale our governance, risk, and compliance programs. This role is based in our San Francisco office or upcoming New York office and reports to the General Counsel. You...SuggestedFull timeContract workWork at officeRemote workFlexible hours- ...GRC Role at Antithesis We are looking for our first dedicated... ...You will build and run our compliance program end-to-end — not as a... ...architecture or vulnerability management — but you will need strong... ...customer-side reviews of us Risk Management Maintain...Suggested
$121.1k - $181.13k
Following the implementation of the Governance, Risk Management, and Compliance (GRC) program and Enterprise Risk Management (ERM) Assessment in the U.S., this role will support the U.S. Ethics & Compliance (E&C) operational audit program and risk management activities...Full timeTemporary workLocal areaWorldwideFlexible hours$133.2k - $199.8k
...than themselves. Our Team. Our Passion. Our Approach. Position Summary We are seeking an experienced Senior Manager, Cybersecurity Governance, Risk & Compliance (GRC) to lead and mature our enterprise cybersecurity governance, risk management, compliance, and security...Full timeLocal area- ...Description Job Description CFGI is seeking a Cybersecurity GRC & AI Governance Subject Matter Expert to lead and deliver strategic... ...that strengthen clients’ security governance, risk management, compliance posture, AI governance programs, and privacy programs....
$140k - $175k
...Director Of Grc Operational Risk Management Live Nation Entertainment is the world's leading live entertainment company, comprised of global... ...environments while reinforcing resilience and regulatory compliance. Lead end-to-end third-party risk management (TPRM) lifecycle...Local areaRemote workWorldwideFlexible hours- ...Job Title: GRC Enterprise Risk Management Director Location: CityScape What you'll do: As an ERM GRC Director you... ...wide programs, including Integrated Risk Management/ Governance Risk and Compliance (GRC) and Policy Framework. The GRC Director is responsible...
$108k - $180k
...Summary SHEIN Global Security & Risk Management is a global security organization that... ..., risk management, data privacy, governance and regulatory compliance across SHEIN’s global footprint. It... ...our common values and vision. The GRC Risk Manager, a thought leader residing...Temporary workWork at officeFlexible hours- ...join our organization as the Director of Cybersecurity Governance, Risk, and Compliance (GRC) as we continue to grow our team. As a leader in the Cybersecurity... ...Headquarters in Dallas, TX. Leadership and Management: Provide operational oversight and serve as the...
- ...Workiva Customer Success Managers (CSM) are a critical part of our customer-facing team. CSMs serve as the primary point of contact for... ...relationships throughout customer organizations Identify risks within named accounts & take appropriate actions to manage and/...Work at officeRemote workFlexible hours
- ...The Director of Governance, Risk & Compliance (GRC) is responsible for building and operating an AI-enabled, modern cybersecurity GRC program that... ...risk trade-offs. Enterprise, Product & Portfolio Risk Management Own the cybersecurity risk management framework, including...For contractorsWorldwide
- ...The Senior Director GRC at Infor will lead enterprise GRC at a global high-... ...and enterprise SaaS. You'll shape the governance, risk, and compliance strategy for a complex, multi-cloud product... ...GRC organization spanning risk management, compliance, audit, policy, and third...WorldwideShift work
- ...Director of Governance, Risk & Compliance (GRC) (Volunteer) PromiseShield | Security Governance, Risk Management & Compliance Organization: Mentor A Promise (MAP) Division: PromiseShield Location: Remote / Hybrid (NYC Collaboration as Needed) Type: Volunteer...Remote work10 hours per week
$122.6k - $263.7k
...Lead Adobe's Security Risk and Governance program by advancing the security... ...organization's risk landscape. Manage Adobe's Security Management... ..., prioritization, and compliance with regulatory changes.... ...collaboration and growth. Optimize GRC platforms (e.g., ServiceNow...Temporary workLocal areaWorldwide$140k - $170k
...Technology Job Description: As the Sr. Manager, AI Risk Governance you will be the primary operator of... ...AI / Data Science teams Legal and Compliance Vendor Management ~ Coordinate... ...NIST CSF, SOC 2 ~ Experience with GRC tools (Archer, ServiceNow, OneTrust)...Full timeTemporary workWork at officeRemote workHome officeFlexible hours$146k - $200k
...paid time off. Job Summary Senior Manager Cyber Risk & Governance leads Alliant Energy’s cybersecurity... ...and governance frameworks, ensuring compliance with regulatory frameworks and... ...supervisory experience. ~ Experience with GRC Platforms, vendor risk tools, and...Work at office- ...Description: We are seeking a highly motivated and experienced IT GRC Manager to join our team. In this role, you will be responsible for maintaining and improving our IT governance, risk, and compliance (GRC) program, with a focus on SOX compliance, application and...Work experience placementLocal areaWorldwideFlexible hours
$190k - $275k
...Role Join Decagon as a Compliance Manager and play a critical role in... ...repeatable processes to scale our GRC operations to hundreds of... ...Establish vendor risk management programs to assess... ...CCPA, GDPR, and emerging AI governance frameworks ~ Strong project...Full timeFor contractorsWork at officeLocal area$205k - $225k
...Security Governance Risk and Compliance Manager - Hybrid Genesis10 is currently seeking a Security Governance Risk and Compliance Manager - Hybrid... ...controls Provide senior guidance and awareness of the GRC program to partnering departments (e.g., Risk, Procurement...Full time$193k - $220k
...information security function, and this is a critical hire for the program's next phase of maturity. The Senior Manager, Governance Risk & Compliance (GRC) will report directly to the Chief Information Security Officer (CISO) and own the build-out of the firm's governance...Full timeH1bLocal areaImmediate startWork visa- ...Job Title: IT Manager II - IT Governance, Risk and Controls Location: Block 23 What you'll do: The IT Manager... ...manage technology risks, ensuring compliance with regulatory expectations and internal... ..., and reporting of IT KRIs within GRC and Workfront platforms to provide timely...
$110k - $130k
...our dynamic Cybersecurity team as a Manager, Cybersecurity Policy, Risk & Governance. This position will report... ...groups (HR, Legal, Privacy, Trade Compliance, EHS, etc.) to standardize and evolve... ...Expertise in designing and delivering GRC programs and cybersecurity...Work at officeLocal areaRemote work- ...Manager, Cybersecurity Governance and Risk, Washington, DC The Manager, Cybersecurity Governance and Risk will lead IT risk management (ITRM)... ...practices. - Understanding of governance, risk and compliance (GRC) practices and technologies across governance, process...
- ...Job Title : IT Security Risk and Audit Manager - Governance Risk Compliance (GRC) Analyst Location : Tolls Data Center in Boca Raton, FL. This is an onsite position, not remote. Job Summary: The IT Security Risk and Audit Manager at the Florida Turnpike...Work experience placement
- ...Cyber Governance, Risk & Compliance (GRC) Manager Here at Discount Tire, we celebrate the spirit of our people with extraordinary pride and enthusiasm. Our business has been growing for more than 60 years and now is the best time in our history to join us. We are opening...Work at officeLocal area
- ...for your future. Position Title:Manager of Enterprise Risk Systems Business Unit:Risk - Operational... ...for the corporation's Enterprise Governance, Risk, and Compliance platform, delivering capabilities... ...Governance, Risk, and Compliance (GRC) platform, delivering capabilities...Contract workWork at office
$142.6k - $261.5k
...change. And with change comes risk. As a Risk Technology... ..., application security, risk management technology enablement, continuous... ...support risk management and governance. With rapid growth across our... ...and transparency of risk and compliance to stakeholders, and automate...Work experience placementSummer holidayFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Manager of Governance, Risk and Compliance (GRC). Be the first to apply!
- data governance director United States
- governance manager United States
- data governance manager United States
- senior risk manager United States
- security risk manager United States
- energy risk manager United States
- safety risk manager United States
- risk management associate United States
- director credit risk United States
- risk management specialist United States


