Senior Manager, Governance, Risk & Compliance
$193k - $220kAndersen
Senior Manager, Governance Risk & Compliance (GRC)
Andersen is scaling its information security function, and this is a critical hire for the program's next phase of maturity. The Senior Manager, Governance Risk & Compliance (GRC) will report directly to the Chief Information Security Officer (CISO) and own the build-out of the firm's governance, risk, and compliance program. The immediate mandate is significant – lead simultaneous SOC 2 Type II and ISO 27001 certification initiatives while establishing the policy and risk management infrastructure the firm will rely on long-term. This is a program-building role, and the right candidate will be energized by the opportunity to design systems rather than maintain them.
The Senior Manager, Governance Risk & Compliance (GRC) can expect to:
- Lead end-to-end certification programs for SOC 2 Type II and ISO 27001 simultaneously, from scoping through audit closure
- Define control environments, manage evidence collection, and serve as the primary liaison with external auditors and certification bodies
- Administer the firm's compliance automation platform and maintain continuous control monitoring and audit readiness
- Manage both programs through their full lifecycle, including observation periods, annual renewals, surveillance audits, and ISO recertification cycles
- Develop and maintain a comprehensive information security policy suite aligned to SOC 2, ISO 27001, and applicable regulatory requirements, with defined processes for ownership, annual review, and exception management
- Build and maintain an enterprise risk register using structured methodology (e.g., ISO 27005, NIST CSF) and lead annual and ad hoc risk assessments
- Communicate risk posture and policy compliance to the CISO and, where appropriate, to firm leadership and clients
- Develop and maintain an AI governance policy covering acceptable use of AI tools, agentic system deployments, and citizen developer activity, ensuring alignment with the firm's risk appetite and applicable regulatory requirements
- Serve as the firm's subject matter expert on GDPR, CCPA, and other applicable privacy and data protection requirements
- Monitor evolving regulatory obligations globally and translate them into actionable compliance programs
- Partner with Legal and Operations on data subject requests, privacy impact assessments, and breach notification procedures
- Advise the CISO on emerging compliance obligations relevant to a global professional services firm
- Design and operate the firm's third-party risk management program, including vendor tiering, security assessments, and remediation tracking
- Manage the firm's response program for client security questionnaires and due diligence requests
- Maintain a library of certification-aligned response language and track contractual security commitments across vendors and clients
- Own the firm's security awareness program, including curriculum design, platform administration, and completion tracking
- Develop role-specific content for high-risk populations and keep training current against the evolving threat landscape
- Develop and maintain training content addressing AI-related threats and responsible AI use, including risks from unsanctioned AI tools, citizen developer activity, and AI agents operating with access to firm data and systems
- Track and report program effectiveness to the CISO on a regular cadence
- Build collaborative relationships across Legal, IT, Operations, Audit, and client-facing teams to embed security and compliance into firm workflows
- Represent the information security function in client-facing conversations regarding the firm's security posture
The Requirements
- 8–12 years of progressive experience in information security GRC, with a demonstrated record of building programs, not just maintaining them
- Bachelor's degree in Information Security, Computer Science, Risk Analysis, or a related field
- Proven track record achieving and sustaining both SOC 2 Type II and ISO 27001 certifications, including scoping, control design, ISMS development, and auditor relationship management
- Operational knowledge of GDPR and CCPA, including hands-on implementation of compliance obligations
- Experience designing and operating third-party risk management programs
- Experience managing client security due diligence and responding to security questionnaires at scale
- Ability to build defensible, auditable policy frameworks and maintain structured enterprise risk registers
- Proficiency with GRC or compliance automation platforms
- Strong written and verbal communication skills, with the ability to translate technical risk into business language for non-technical audiences
- Understanding of the security and governance risks introduced by AI systems, including large language models, AI agents, and citizen developer platforms, and the ability to translate those risks into policy, training content, and risk register entries
Preferred
- Relevant certification such as CISA, CISM, or CRISC
- Background in professional services or consulting, where security posture is tied directly to client trust
- Familiarity with international privacy frameworks such as NDPA or DPDPA
- Working knowledge of the NIST Cybersecurity Framework as a risk management overlay
- Familiarity with AI governance frameworks such as NIST AI RMF, the EU AI Act, or ISO 42001, and awareness of emerging regulatory obligations affecting AI use in global professional services environments
- Experience managing or mentoring junior GRC staff
Compensation and Benefits
Our firm offers competitive base compensation, benefits package, and a discretionary employee bonus program for eligible employees based on individual and firm performance metrics per the defined program guidelines. For individuals hired to work in the United States, the expected salary range for this role is $193,000 to $220,000; the actual salary offer can vary based upon employee qualifications.
Benefits: Employees (and their families) are covered by medical, dental, vision, and basic life insurance. Employees are able to enroll in our firm's 401(k) plan upon hire. We offer paid time off, beginning at 160 hours annually and provides twelve paid holidays throughout the calendar year. For a full listing of benefit offerings, please visit
Compensation: In addition to competitive base compensation, our firm offers annual discretionary bonuses based on firm and individual performance, a discretionary long-term cash incentive program, and other forms of discretionary compensation that would be offered to the hired applicant in addition to their established salary range scale.
Applicants must be currently authorized to work in the United States on a full-time basis upon hire. Andersen will not consider candidates for this position who require sponsorship for employment visa status now or in the future (e.g., H-1B status).
Equal Opportunity
Andersen Tax is an equal opportunity employer committed to fostering an inclusive workplace. We evaluate all applicants and employees without regard to race, color, religion, national origin, ancestry, sex (including pregnancy, childbirth, and related medical conditions), sexual orientation, gender identity or expression, age, disability, genetic information, marital status, military or veteran status, or any other characteristic protected under applicable federal, state, or local law. All qualified applicants, including those with criminal histories, will be considered in a manner consistent with applicable law. We provide reasonable accommodations to qualified individuals with disabilities and to individuals with sincerely held religious beliefs, practices, or observances as required by law.
$193k - $220k
...scaling its information security function, and this is a critical hire for the program's next phase of maturity. The Senior Manager, Governance Risk & Compliance (GRC) will report directly to the Chief Information Security Officer (CISO) and own the build-out of the firm's...SeniorFull timeH1bLocal areaImmediate startWork visa$112k
...Sr Manager, InfoSec Governance Risk and Compliance (GRC) (San Francisco Bay Area, California, United States) Founded in 2000, Ivalua is a leading global provider of cloud-based procurement solutions. COMPANY OVERVIEW At Ivalua we are a global community of exceptional...SeniorWork at officeWorldwide- Sr Manager, InfoSec Governance Risk and Compliance (GRC) Founded in 2000, Ivalua is a leading global provider of cloud‑based procurement solutions. Company Overview We are a global community of professionals dedicated to digital transformation and resilient supply chains...SeniorWork at officeWorldwide3 days per week
$128k - $173k
...of consumers. Responsibilities JOB PURPOSE The Senior Manager, Investment and Risk Management plays a pivotal role in strengthening the... ...allocation, portfolio optimization, and enterprise risk governance. The role works cross‑functionally to ensure investment...SeniorFull timeTemporary workWork experience placement- ...related services. This individual will manage direct client project relationships... ...experience leading internal audit, corporate governance, enterprise risk management, and anti-fraud and ethics... ...experience managing and supervising senior and junior level staff resources in...SeniorWork experience placement
$127.3k - $240.1k
...financial institutions and government entities across more... ...'sPayment Ecosystem Risk and Control (PERC)... ...support across Visa's compliance, enforcement, and investigative... ..., and the ability to manage complex risk,... ...expectations are essential. The Senior Consultant must be...SeniorWork experience placementWork at officeLocal area$216k - $240k
...within the broader Finance Risk Management (FRM) organization and plays... ...operations. Our team designs and governs control frameworks that... ...Finance, Finance Systems, Compliance, and business operators to ensure... ...the Role We're seeking a Senior Manager, Financial Risk...SeniorWork at officeRelocation package$172.5k - $260.1k
...Salesforce. Job Title: Sr. Manager, Technology Risk and Controls (Revenue)... ...line of defense within our Governance pillar, dedicated to managing... ...IT control environment. The Senior Manager will be responsible... ...into clear, executable compliance activities to ensure timely...SeniorWork experience placement$123.6k - $185.4k
Stripe is seeking a Program Manager for Third Party Risk in San Francisco, CA. In this role, you will oversee the Global Third Party Risk Management... .... Candidates should have 4+ years of experience in risk/compliance, excellent communication skills, and experience with...Senior$216k - $240k
...function sits within the broader Finance Risk Management (FRM) organization and plays a key role... ...operations. Our team designs and governs the Internal Controls over Financial Reporting... ..., Accounting, Finance Platforms and Compliance to ensure processes are well-designed,...SeniorPermanent employmentWork at officeRelocation package- STV, Inc. is seeking a Commercial Manager to join their Major Commercial Project team in San Francisco. This hybrid position involves extensive... ...experience in commercial management, contract handling, and risk assessment to maximize project performance. Responsibilities...SeniorContract work
- ...Senior Manager, Risk Operation AI Enablement Airwallex is the only unified payments and financial... ..., Engineering, Data Science, and Compliance, ensuring alignment and effective... ...to regulatory requirements, internal governance standards, and best practices for responsible...SeniorWorldwide
- ...– with fully integrated solutions to manage everything from business accounts, payments... ...globally. What You'll Do As Senior Manager, Risk Operation Strategy, you will play a pivotal... ...with Product, Engineering, Risk and Compliance teams. This hybrid role is based in...SeniorWorldwide
$132.5k - $338.3k
...sustainability principles to enable comprehensive enterprise reinvention. About the Role As a Financial Crime Senior Manager in the Finance Risk Compliance team, you will be responsible for developing and executing financial crime strategies that address the complex challenges...SeniorWork at office- What you'll do As Senior Manager, Risk Operation Strategy, you will play a pivotal role in shaping Airwallex’s global risk management approach... ...in partnership with Product, Engineering, Risk and Compliance teams. This hybrid role is based in San Francisco, CA. Responsibilities...Senior
$155k - $190k
...That starts with you! Job Summary: Miller Kaplan’s Risk Advisory team is looking for a Senior Manager to join our Cybersecurity practice. The Senior... ...and risk assessments, network and security reviews, compliance, assessments, and system configuration review Lead...SeniorWork at officeLocal areaRemote workVisa sponsorshipWork visaFlexible hoursDay shift- ...on interviews) HIRING MANAGER NOTES: ~ Looking for top... ...years (current) experience as a Senior Technical Program Manager... ...Digital Accessibility, and Compliance ( implementing and building... ...Maranger leading Accessibility, Governance, Risk/Compliance, Process...Remote work2 days per week
$101.9k - $140.14k
...Collision and Safety is seeking an Environmental Health and Safety (EHS) Manager to oversee safety and risk programs at our San Diego facility. The role involves developing EHS programs, ensuring compliance with all safety regulations, and promoting a proactive safety...Senior- SOLANA FOUNDATION in Anchorage is seeking a Quantitative Financial Risk Manager to lead the development of analysis tools for risk management across credit, market, and liquidity sectors. The ideal candidate will possess 8+ years of experience in quantitative finance and...Senior
- ...The Global Investigations & Forensic Accounting Senior Managing Director role is an executive level position that sells,... ...forensic investigations, technical accounting research, fraud risk assessments, compliance reviews, forensic accounting audits, background interviews...SeniorRemote workFlexible hours
- Requirements 2+ years of experience in risk management, compliance, or a related field within financial services Hands-on experience with contract... ...) Experience working with Salesforce, or similar Governance, Risk, and Compliance (GRC) or contract management platforms...SeniorContract workLocal areaFlexible hours
- ...zone) Job Description:- As the Senior Cyber Risk Manager, you will be responsible for overseeing... ...teams, including IT, security, compliance, and business units, to develop and implement... ...laws, regulations, and guidelines governing technology risk management and...SeniorContract workRemote work
$203k - $250k
Socotra, Inc. is looking for a Sr Model Risk Manager in San Francisco, CA, to oversee model risk management, lead validations, and evolve their framework. The role requires a Master's degree in a quantitative field and at least 7 years of relevant experience. Ideal candidates...Senior$175k - $210k
Singular Builders is hiring a Compliance Manager in San Francisco. This role focuses on managing compliance, risk, and contracts within a fast-paced construction environment. The ideal candidate will have 7 to 12+ years of experience, strong skills in risk management and...Senior- A professional sports team is seeking a Risk Manager to oversee enterprise-wide risk, litigation management, and insurance procurement. The ideal candidate will have a Juris Doctor and 8-10 years of relevant experience, exceptional communication and project management...Senior
$203k - $250k
Sr Model Risk Manager Will report to the Head of Credit Risk. As the Sr Model Risk Manager... .... Serve as a trusted advisor on model governance, helping Earnest move fast while maintaining... ...into clear, actionable insights for senior stakeholders. Even Better: Experience...SeniorWork from homeHome office- Manager-level Risk consultants work closely with management of Fortune 500, mid-cap and start-up... ...process improvement projects, compliance and other assessments. Principal duties... ...accounting policies and procedures. Advises senior management regarding matters, such as...Senior
- DocuSign, Inc. is seeking a Senior Director, Security Governance, Risk, and Compliance (GRC) to lead their global GRC team. This role requires over 15 years of... ...security leadership, focusing on innovative risk management strategies. The ideal candidate will drive measurable...Senior
$175k - $235k
...Description Job Description TITLE: SENIOR DIRECTOR, GAMING COMPLIANCE RISK Location: REMOTE US... ...landscapes, strategic risk, and evolving governance standards. External Relations:... ..., regulatory affairs, or risk management, preferably within regulated gaming...SeniorRemote jobFull timeShift work$125k - $152k
...Waymo Insurance, you will work on the cutting edge of emerging risk and related issues surrounding our transformational autonomous driving... ...policy, safety, security and privacy experts to evaluate and manage risks for the autonomous driving world to come, advising on...SeniorFull timeRemote workRelocationRelocation package
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Manager, Governance, Risk & Compliance. Be the first to apply!
- governance manager San Francisco, CA
- risk management associate San Francisco, CA
- director credit risk San Francisco, CA
- risk management manager San Francisco, CA
- risk management specialist San Francisco, CA
- head of risk management San Francisco, CA
- enterprise risk manager San Francisco, CA
- operational risk manager San Francisco, CA
- senior risk manager San Francisco, CA
- director of risk management San Francisco, CA


