Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Manager, Governance, Risk & Compliance

$193k - $220k

Andersen Tax, LLC

Application Notice We encourage you to apply thoughtfully by selecting one position that best matches your qualifications and interests. You may submit up to two active applications at a time. Please consider your location choice carefully-we recommend applying where you envision building your future. The Firm Unlock the Boundless Horizons of Tax, Valuation, and Business Expertise with Andersen! At Andersen, we don't just offer a career; we provide a thrilling expedition into the world of Tax, Valuation, and Business Advisory. We stand as a trailblazing force with the most extensive global presence among professional services organizations. You'll embark on a journey that transcends the ordinary, working with extraordinary clients spanning every industry, regardless of their size, because at Andersen, we are free from independence-related constraints that may hinder other firms. But that's not all; we're more than just a company; we're a community that thrives on diversity, inclusivity, and collaboration. Our focus is on your development helping you flourish as leaders, colleagues and trusted advisors. We equip you with world-class education, immersive experiences, and invaluable mentorship to support your rise to the top. We believe in your potential and invest in it to build a legacy that extends beyond your wildest dreams. Bring your ambition, your entrepreneurial spirit, and your burning desire to be the best. Your future mirrors the limitless possibilities of our future. Join us at Andersen, and together, let's write the story of your success! The Role Andersen is scaling its information security function, and this is a critical hire for the program's next phase of maturity. The Senior Manager, Governance Risk & Compliance (GRC) will report directly to the Chief Information Security Officer (CISO) and own the build-out of the firm's governance, risk, and compliance program. The immediate mandate is significant - lead simultaneous SOC 2 Type II and ISO 27001 certification initiatives while establishing the policy and risk management infrastructure the firm will rely on long-term. This is a program-building role, and the right candidate will be energized by the opportunity to design systems rather than maintain them. The Senior Manager, Governance Risk & Compliance (GRC) can expect to: SOC 2 Type II & ISO 27001 Certification * Lead end-to-end certification programs for SOC 2 Type II and ISO 27001 simultaneously, from scoping through audit closure * Define control environments, manage evidence collection, and serve as the primary liaison with external auditors and certification bodies * Administer the firm's compliance automation platform and maintain continuous control monitoring and audit readiness * Manage both programs through their full lifecycle, including observation periods, annual renewals, surveillance audits, and ISO recertification cycles Policy & Risk Management * Develop and maintain a comprehensive information security policy suite aligned to SOC 2, ISO 27001, and applicable regulatory requirements, with defined processes for ownership, annual review, and exception management * Build and maintain an enterprise risk register using structured methodology (e.g., ISO 27005, NIST CSF) and lead annual and ad hoc risk assessments * Communicate risk posture and policy compliance to the CISO and, where appropriate, to firm leadership and clients * Develop and maintain an AI governance policy covering acceptable use of AI tools, agentic system deployments, and citizen developer activity, ensuring alignment with the firm's risk appetite and applicable regulatory requirements Privacy & Regulatory Compliance * Serve as the firm's subject matter expert on GDPR, CCPA, and other applicable privacy and data protection requirements * Monitor evolving regulatory obligations globally and translate them into actionable compliance programs * Partner with Legal and Operations on data subject requests, privacy impact assessments, and breach notification procedures * Advise the CISO on emerging compliance obligations relevant to a global professional services firm Third-Party Risk & Client Due Diligence * Design and operate the firm's third-party risk management program, including vendor tiering, security assessments, and remediation tracking * Manage the firm's response program for client security questionnaires and due diligence requests * Maintain a library of certification-aligned response language and track contractual security commitments across vendors and clients Security Awareness & Training * Own the firm's security awareness program, including curriculum design, platform administration, and completion tracking * Develop role-specific content for high-risk populations and keep training current against the evolving threat landscape * Develop and maintain training content addressing AI-related threats and responsible AI use, including risks from unsanctioned AI tools, citizen developer activity, and AI agents operating with access to firm data and systems * Track and report program effectiveness to the CISO on a regular cadence Team & Stakeholder Leadership * Build collaborative relationships across Legal, IT, Operations, Audit, and client-facing teams to embed security and compliance into firm workflows * Represent the information security function in client-facing conversations regarding the firm's security posture The Requirements * 8-12 years of progressive experience in information security GRC, with a demonstrated record of building programs, not just maintaining them * Bachelor's degree in Information Security, Computer Science, Risk Analysis, or a related field * Proven track record achieving and sustaining both SOC 2 Type II and ISO 27001 certifications, including scoping, control design, ISMS development, and auditor relationship management * Operational knowledge of GDPR and CCPA, including hands-on implementation of compliance obligations * Experience designing and operating third-party risk management programs * Experience managing client security due diligence and responding to security questionnaires at scale * Ability to build defensible, auditable policy frameworks and maintain structured enterprise risk registers * Proficiency with GRC or compliance automation platforms * Strong written and verbal communication skills, with the ability to translate technical risk into business language for non-technical audiences * Understanding of the security and governance risks introduced by AI systems, including large language models, AI agents, and citizen developer platforms, and the ability to translate those risks into policy, training content, and risk register entries Preferred * Relevant certification such as CISA, CISM, or CRISC * Background in professional services or consulting, where security posture is tied directly to client trust * Familiarity with international privacy frameworks such as NDPA or DPDPA * Working knowledge of the NIST Cybersecurity Framework as a risk management overlay * Familiarity with AI governance frameworks such as NIST AI RMF, the EU AI Act, or ISO 42001, and awareness of emerging regulatory obligations affecting AI use in global professional services environments * Experience managing or mentoring junior GRC staff Compensation and Benefits Our firm offers competitive base compensation, benefits package, and a discretionary employee bonus program for eligible employees based on individual and firm performance metrics per the defined program guidelines. For individuals hired to work in the United States, the expected salary range for this role is $193,000 to $220,000; the actual salary offer can vary based upon employee qualifications. Benefits: Employees (and their families) are covered by medical, dental, vision, and basic life insurance. Employees are able to enroll in our firm's 401(k) plan upon hire. We offer paid time off, beginning at 160 hours annually and provides twelve paid holidays throughout the calendar year. For a full listing of benefit offerings, please visit Compensation: In addition to competitive base compensation, our firm offers annual discretionary bonuses based on firm and individual performance, a discretionary long-term cash incentive program, and other forms of discretionary compensation that would be offered to the hired applicant in addition to their established salary range scale. Applicants must be currently authorized to work in the United States on a full-time basis upon hire. Andersen will not consider candidates for this position who require sponsorship for employment visa status now or in the future (e.g., H-1B status). Equal Opportunity Andersen Tax welcomes and encourages workforce diversity. We are an equal opportunity employer. Applicants and employees are considered for positions and are evaluated without regard to race, color, national origin, ancestry, religion, sexual orientation (including gender identity and gender expression), mental disability, physical disability, sex/gender (including pregnancy, childbirth, and related medical conditions), age, marital status, military status, veteran status, genetic information, or any other characteristic protected by federal, state or local laws or regulations. All qualified individuals, including those with criminal histories, will be considered in a manner consistent with the requirements of applicable state and local laws. Additionally, we make every effort to provide reasonable accommodations to qualified individuals with disabilities.

Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Senior Manager, Governance, Risk & Compliance in San Francisco, CA vacancy
  • $112k

     ...Sr Manager, InfoSec Governance Risk and Compliance (GRC) (San Francisco Bay Area, California, United States) Founded in 2000, Ivalua is a leading global provider of cloud-based procurement solutions. COMPANY OVERVIEW At Ivalua we are a global community of exceptional... 
    Senior
    Work at office
    Worldwide

    Ivalua

    San Francisco, CA
    1 day ago
  • $112k

    Manager, InfoSec Governance Risk and Compliance (GRC) Manager, InfoSec Governance Risk and Compliance (GRC) Founded in 2000, Ivalua is a leading global provider of cloud-based procurement solutions. Company Overview At Ivalua we are a global community of exceptional professionals... 
    Senior
    Worldwide

    Ivalua

    San Francisco, CA
    4 days ago
  • Sr Manager, InfoSec Governance Risk and Compliance (GRC) Founded in 2000, Ivalua is a leading global provider of cloud‑based procurement solutions. Company Overview We are a global community of professionals dedicated to digital transformation and resilient supply chains... 
    Senior
    Work at office
    Worldwide
    3 days per week

    Ivalua

    San Francisco, CA
    4 days ago
  • $128k - $173k

     ...of consumers. Responsibilities JOB PURPOSE The Senior Manager, Investment and Risk Management plays a pivotal role in strengthening the...  ...allocation, portfolio optimization, and enterprise risk governance. The role works cross‑functionally to ensure investment... 
    Senior
    Full time
    Temporary work
    Work experience placement

    Pattern Energy Group

    San Francisco, CA
    21 days ago
  • $127.3k - $240.1k

     ...financial institutions and government entities across more...  ...'sPayment Ecosystem Risk and Control (PERC)...  ...support across Visa's compliance, enforcement, and investigative...  ..., and the ability to manage complex risk,...  ...expectations are essential. The Senior Consultant must be... 
    Senior
    Work experience placement
    Work at office
    Local area

    Visa

    San Francisco, CA
    14 days ago
  • $216k - $240k

     ...within the broader Finance Risk Management (FRM) organization and plays...  ...operations. Our team designs and governs control frameworks that...  ...Finance, Finance Systems, Compliance, and business operators to ensure...  ...the Role We're seeking a Senior Manager, Financial Risk... 
    Senior
    Work at office
    Relocation package

    OpenAI

    San Francisco, CA
    21 hours ago
  • $123.6k - $185.4k

    Stripe is seeking a Program Manager for Third Party Risk in San Francisco, CA. In this role, you will oversee the Global Third Party Risk Management...  .... Candidates should have 4+ years of experience in risk/compliance, excellent communication skills, and experience with... 
    Senior

    Stripe

    San Francisco, CA
    1 day ago
  • $172.5k - $222.5k

     ...Fraud Risk Management Leader Circle (NYSE: CRCL) is one of the world's leading internet financial...  ...with relevant stakeholders (e.g., Compliance, Legal, Finance, Talent, Security) to...  ...identified, mitigated, and reported to senior management and regulators where required... 
    Senior
    Local area
    Flexible hours

    Circle

    San Francisco, CA
    1 day ago
  •  ...This role sits within the Risk & Compliance function and reports to the...  ...responsible for developing and managing the enterprise-wide regulatory...  ...teams. This is a hands-on senior role. We expect the work to...  ...in risk, compliance, governance, audit, legal or commercial... 
    Senior
    Temporary work
    Relocation
    Flexible hours

    IREN

    San Francisco, CA
    4 days ago
  • $155k - $190k

     ...That starts with you! Job Summary: Miller Kaplan’s Risk Advisory team is looking for a Senior Manager to join our Cybersecurity practice. The Senior...  ...and risk assessments, network and security reviews, compliance, assessments, and system configuration review Lead... 
    Senior
    Work at office
    Local area
    Remote work
    Visa sponsorship
    Work visa
    Flexible hours
    Day shift

    Miller Kaplan Arase LLP

    San Francisco, CA
    22 days ago
  • What you'll do As Senior Manager, Risk Operation Strategy, you will play a pivotal role in shaping Airwallex’s global risk management approach...  ...in partnership with Product, Engineering, Risk and Compliance teams. This hybrid role is based in San Francisco, CA. Responsibilities... 
    Senior

    Airwallex Pty Ltd.

    San Francisco, CA
    21 hours ago
  • $175k - $235k

     ...Description Job Description TITLE: SENIOR DIRECTOR, GAMING COMPLIANCE RISK Location: REMOTE US...  ...landscapes, strategic risk, and evolving governance standards. External Relations:...  ..., regulatory affairs, or risk management, preferably within regulated gaming... 
    Senior
    Remote job
    Full time
    Shift work

    Bing Recruitment

    San Francisco, CA
    29 days ago
  • $101.9k - $140.14k

     ...Collision and Safety is seeking an Environmental Health and Safety (EHS) Manager to oversee safety and risk programs at our San Diego facility. The role involves developing EHS programs, ensuring compliance with all safety regulations, and promoting a proactive safety... 
    Senior

    CEI Fleet Collision and Safety

    San Francisco, CA
    21 hours ago
  •  ...The Global Investigations & Forensic Accounting Senior Managing Director role is an executive level position that sells,...  ...forensic investigations, technical accounting research, fraud risk assessments, compliance reviews, forensic accounting audits, background interviews... 
    Senior
    Remote work
    Flexible hours

    Ankura Consulting Group, LLC

    San Francisco, CA
    2 days ago
  • Requirements 2+ years of experience in risk management, compliance, or a related field within financial services Hands-on experience with contract...  ...) Experience working with Salesforce, or similar Governance, Risk, and Compliance (GRC) or contract management platforms... 
    Senior
    Contract work
    Local area
    Flexible hours

    Lending Club

    San Francisco, CA
    3 days ago
  • $216k - $240k

    OpenAI is seeking a Senior Manager, Financial Risk Management in San Francisco to lead risk and controls across finance-critical domains. This role requires 10+ years of experience in financial risk management, operational risk, or internal controls, with a focus on designing... 
    Senior

    OpenAI

    San Francisco, CA
    21 hours ago
  •  ...zone) Job Description:- As the Senior Cyber Risk Manager, you will be responsible for overseeing...  ...teams, including IT, security, compliance, and business units, to develop and implement...  ...laws, regulations, and guidelines governing technology risk management and... 
    Senior
    Contract work
    Remote work

    Avant Digital Inc

    San Francisco, CA
    2 days ago
  • A professional sports team is seeking a Risk Manager to oversee enterprise-wide risk, litigation management, and insurance procurement. The ideal candidate will have a Juris Doctor and 8-10 years of relevant experience, exceptional communication and project management... 
    Senior

    49ers

    San Francisco, CA
    4 days ago
  • DocuSign, Inc. is seeking a Senior Director, Security Governance, Risk, and Compliance (GRC) to lead their global GRC team. This role requires over 15 years of...  ...security leadership, focusing on innovative risk management strategies. The ideal candidate will drive measurable... 
    Senior

    DocuSign, Inc.

    San Francisco, CA
    21 hours ago
  • Manager-level Risk consultants work closely with management of Fortune 500, mid-cap and start-up...  ...process improvement projects, compliance and other assessments. Principal duties...  ...accounting policies and procedures. Advises senior management regarding matters, such as... 
    Senior

    Regal Executive Search

    San Francisco, CA
    2 days ago
  • $190k - $275k

     ...About the Role Join Decagon as a Compliance Manager and play a critical role in securing customer...  ...standards Establish vendor risk management programs to assess and monitor...  ...including CCPA, GDPR, and emerging AI governance frameworks ~ Strong project management... 
    Full time
    For contractors
    Work at office
    Local area

    Decagon

    San Francisco, CA
    4 days ago
  • $140k - $200k

     ...Health and Benefits Financial/Actuarial Senior Director, you will serve as the financial...  ...solutions. You will apply your financial management and data analytics expertise to solve complex...  ...additional actuarial, financial, and/or risk solutions Provides consulting quality... 
    Senior
    Temporary work
    Work at office
    Local area
    Visa sponsorship
    Work visa
    Flexible hours

    Willis Towers Watson

    San Francisco, CA
    1 day ago
  • $190k - $215k

     ...Governance, Risk & Compliance (GRC) Manager Sigma is seeking an experienced GRC Manager to lead and scale our governance, risk, and compliance programs. This role is based in our San Francisco office or upcoming New York office and reports to the General Counsel. You... 
    Full time
    Contract work
    Work at office
    Remote work
    Flexible hours

    Sigma Computing

    San Francisco, CA
    6 days ago
  • $125k - $150k

    Shipt is seeking a Program Manager for Responsible AI based in San Francisco or other locations. The role focuses on executing AI governance, managing privacy and data protection across teams, and ensuring legal compliance. Ideal candidates will have experience in data... 

    Shipt

    San Francisco, CA
    4 days ago
  • $146.2k - $233.7k

     ..., merchants, financial institutions and government entities across more than 200 countries...  ...adoption and business scale up of Visa's Risk Solutions for A2A (money movement, ACH,...  ...domain. This includes the responsibility of managing solutioning for the region, designing... 
    Work experience placement
    Work at office
    Local area

    Visa

    San Francisco, CA
    21 hours ago
  • $129k - $161k

     ...enterprise and operational risk programs, promoting an...  ...required by various governance committees and the...  ...issues with business unit management and second line of...  ...reporting and updates to senior management, risk...  ...Legal/paralegal or Compliance experience Certification... 
    Senior
    Temporary work
    Work at office
    Visa sponsorship
    Work visa

    Early Warning Services, LLC

    San Francisco, CA
    6 days ago
  •  ...Principal Product Manager – Risk & Compliance Location: San Fransisco, California  Working Structure: Hybrid, 2 days onsite a week Salary + Bonus + Stock Options + Health Benefits About the Role The Principal Product Manager – Risk & Compliance will own the... 
    Remote work
    Flexible hours
    2 days per week

    Veem

    San Francisco, CA
    16 days ago
  • $100 - $120 per hour

     ...We are seeking an experience Quality Risk Management proffesional to join a growing biotech organization...  ...We are seeking an experienced Senior Manager, Quality Risk Management (QRM)...  ...experience in pharmaceutical Quality, Compliance, Clinical Operations, or other GxP-regulated... 
    Senior
    Permanent employment

    Astrix Inc

    South San Francisco, CA
    3 days ago
  •  ...Technology Risk Manager The Technology Risk Manager is a senior individual contributor responsible for driving Hinge Health's technology risk posture...  ...plans meet agreed SLAs. Regulatory Compliance & Governance (SOX & HIPAA). Serve as a primary interface... 
    Work at office
    Local area
    Remote work
    Worldwide
    3 days per week

    Hinge Health

    San Francisco, CA
    4 days ago
  • $160k - $170k

     ...join us. Responsibilities and Duties The Risk Manager is responsible for the day-to-day...  ...evaluate Certificates of Insurance for compliance and risk transfer adequacy. Conduct enterprise...  ...exposure, reserves, and outcomes to senior leadership. Public Interaction & Stakeholder... 
    Work at office
    Night shift
    Weekend work

    49ers

    San Francisco, CA
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Manager, Governance, Risk & Compliance. Be the first to apply!