Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Remote GRC Lead

GrabJobs

About WorkOS
WorkOS builds modern developer tools and APIs that make it easy for companies to become Enterprise Ready. Our platform powers authentication, identity, authorization, and other critical infrastructure that developers need to securely scale their products to large organizations.

We recently raised a $100M Series C, valuing the company at $2B, led by Meritech and Sapphire with participation from Greenoaks, Craft, Abstract, and Audacious. WorkOS powers enterprise features for many of the fastest-growing AI companies, including OpenAI, Cursor, and Perplexity, Vercel, and Plaid.

As AI reshapes software, WorkOS is at the frontier of Human and Agent Authentication, Identity, and Access Control—helping companies answer a new critical question: who are your agents, and what are they allowed to do? Our fast-growing customer base includes hundreds of modern software companies building the next generation of enterprise-ready products.

About the Security Team

The Security team at WorkOS is responsible for keeping the data and identities of hundreds of millions of users secure. Security is fundamental to our products, and customer trust is the foundation of our success.
We are a highly collaborative group with a strong technical mindset. Our security program is shaped by hands-on experience attacking and defending systems, and applying lessons from across the industry. We embrace the latest advancements in practices and tooling that make modern security teams effective.
Today, our team spans product security, cloud security, and detection & response. We are expanding our internal GRC function to scale our compliance, risk, and customer trust programs as we grow.

About the Role

We are looking for a

GRC Lead

to build and own our Governance, Risk, and Compliance program.
WorkOS has foundational compliance in place; SOC 2, HIPAA, GDPR, PCI-DSS SAQ D, and a growing set of customer and regulatory obligations. What we are looking for now is a leader for our compliance function: someone who can build on the trust our enterprise customers have placed in us, own our existing frameworks, and drive us into the next tier of certifications.
You will work with security leadership to navigate our GRC program. You will help set the strategy, shape the roadmap, and build the systems and culture that make compliance a byproduct of how we build software.
This is a remote position, open to candidates based in Canada or the United States.

What Youll Do

Own our compliance function.

Frameworks, policies, controls, and audits are yours. Make compliance part of how we build and ship, not a separate track.

Build the GRC culture.

Own security awareness, internal education, and the cross-functional work that makes compliance a shared responsibility across the company.

Lead our next certifications.

Drive readiness and on-going compliance for future frameworks like ISO 27001, EU-US DPF, FedRAMP; scoping the controls, documentation, and collaborating across the organization to make it happen.

Partner directly with customers.

Be the voice of our compliance program to our customers. Support audits, enable sales on compliance-gated deals, and build on the trust weve established with the companies that depend on us.

Own risk across WorkOS.

Run our risk and third-party risk programs. Identify risks as they emerge, drive remediation, and surface signal to leadership.

Scale through automation.

Reduce manual toil wherever it hides. Design processes, tooling, and AI-assisted workflows so the compliance function scales without scaling headcount.

Who You Are

A trusted advisor, internally and externally.

You work fluidly with customers, engineering, legal, sales, and auditors. You can explain a control, defend a design decision, manage a difficult customer conversation, and communicate clearly, in writing.

A pragmatic, forward-thinker.

You spot audit tight spots before they arrive, have the experience to work through them, and how to future-proof against them. You reason systematically about real-world impact, and ensure we reduce risk over checking boxes.

A strong partner to engineering.

You build trust by understanding engineers priorities and making the compliant path the easiest path. You act as the bridge between auditor asks and engineering work with the ability to translate between the two.

Framework-fluent.

You have hands-on experience implementing and auditing SOC 2 and other major frameworks (ISO 27001, PCI DSS, NIST 800-53, FedRAMP), and you can reason about new frameworks from first principles.

A builder, not just an operator.

You see manual, repetitive GRC work as tech debt and look for ways to design it away: through process, tooling, AI, or partnering with engineering to build whats needed. You are not looking for a role where you chase screenshots and manage spreadsheets.

Qualifications

5+ years in a GRC or compliance role, with demonstrated ownership of cross-functional compliance projects, from scoping through delivery, at a cloud-native company.

Hands-on experience implementing or auditing SOC 2 plus one other major framework (ISO 27001, PCI DSS, NIST 800-53).

Experience building or significantly maturing a GRC function at a high-growth company; you have seen the zero-to-one arc, not just maintained a mature program.

Experience with GRC automation platforms (Vanta, Drata, or similar); migrating into, configuring, and building in them.

Strong written and verbal communication, particularly customer-facing advisory: explaining controls, handling objections, and managing audit and enterprise-deal conversations.

Bonus:
Privacy regulations (GDPR, CCPA, HIPAA) and PII classification; we have employees and customers across multiple jurisdictions.

FedRAMP experience as implementer or auditor.

Proficiency in a programming or scripting language (Python, TypeScript, Go, or similar); you can read code, write automation, and leverage AI in day-to-day work.

GRC-as-code / compliance-as-code practices; version-controlled policies, automated control testing, or CI-integrated evidence collection.

Familiarity with authentication and identity (SAML, OIDC, SCIM); highly relevant given our product.

Benefits and Perks

( US Only)
At WorkOS, we offer resources that emphasize personal and familial well-being. We offer healthcare coverage for you and your family, including medical, dental, and vision. We offer parental leave, paid-time off and fully remote working arrangements.
Benefits include:
- Competitive pay
- Substantial equity grants
- Healthcare insurance (Medical, Dental and Vision) for you and your family
- 401k matching
- Wellness and fitness monthly allowances
- PTO + paid holidays + unlimited sick leave
- Unlimited token usage
Please inquire directly with our recruiting team for benefits available to those working outside the US.
Equal Opportunity Employer
WorkOS is an equal opportunity employer, committed to diversity and inclusiveness. We will consider all qualified applicants without regard to race, color, nationality, gender, gender identity or expression, sexual orientation, religion, disability or age.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Vacancy posted 21 hours ago
Similar jobs that could be interesting for youBased on the Remote GRC Lead in United States vacancy
  • $120k - $156k

     ...Clearsulting LLC is seeking a Consulting Manager for Governance, Risk & Compliance in Dallas, TX. You will lead implementations of Workiva GRC, manage project delivery, and engage with clients to assess their needs. This role requires 6+ years of relevant experience, strong... 
    Remote work
    Flexible hours

    Clearsulting

    Dallas, TX
    3 days ago
  • $153.6k - $192k

     ...expertise with technical execution. As a Senior GRC Engineer, you will drive critical GRC...  ...have up to four weeks per year of fully remote work! Responsibilities Manage and...  ...partners by producing documentation and leading training sessions Evangelize best practices... 
    Remote work
    Work at office
    Immediate start
    Work from home
    3 days per week

    Brex

    San Francisco, CA
    3 days ago
  •  ...and our Online Peer to Peer Events - Volunteer Opportunity | Remote | Human Health Project DETAILS Available Times: Weekdays...  ...of a credible compliance program before they sign. The GRC Lead makes that evidence real. This role sits inside the CISO organization... 
    Remote work
    Worldwide
    Flexible hours
    Afternoon shift
    Weekday work

    Human Health Project Inc

    Los Angeles, CA
    21 hours ago
  • $172.5k - $260.1k

    Salesforce, Inc. is seeking a Security GRC Senior Lead in San Francisco to oversee compliance for global CCaaS initiatives. The role involves defining compliance strategy, monitoring regulations, and liaising with Product Management. Ideal candidates will have over 8 years... 
    Remote job

    Salesforce, Inc.

    San Francisco, CA
    3 days ago
  • A leading consulting firm seeks a Governance, Risk, and Compliance (GRC) leader to advance their programs. This remote role requires 5-7 years of experience in GRC with relevant certifications like CISSP or CISM. The successful candidate will lead policy development, perform... 
    Remote job

    Franklin Fitch

    New York, NY
    2 days ago
  • Docker, Inc is looking for a Senior GRC Analyst to lead the company's risk management program. This role requires experience in Information...  ...and performing risk assessments. The position offers flexible remote work, competitive compensation, and multiple benefits... 
    Remote job
    Flexible hours

    Docker, Inc

    New Bremen, OH
    4 days ago
  • $120k - $156k

     ...in Governance, Risk & Compliance with Workiva. The role involves leading project implementations, managing stakeholder communications,...  ...environment. Candidates should have 6+ years of experience with Workiva GRC, project management skills, and the ability to engage with... 
    Remote job

    Clearsulting LLC

    Columbus, OH
    3 days ago
  •  ...years of experience in cloud alliances and a strong understanding of hyperscaler co-sell models. This position offers competitive compensation and a remote-friendly work environment, focusing on innovation in risk and compliance solutions. #J-18808-Ljbffr LockThreat GRC
    Remote work

    LockThreat GRC

    New York, NY
    2 days ago
  •  ...role involves identifying security risks, leading assessments, and ensuring compliance as...  ...candidates will have over 8 years in Security GRC, a startup mindset, and proficiency in...  ..., combining office collaboration with remote work flexibility. #J-18808-Ljbffr Stripe
    Remote work
    Work at office

    Stripe

    New York, NY
    1 day ago
  • $125k - $175k

    Savant Wealth Management is seeking a GRC Lead in Chicago. This role offers the opportunity to design and own the governance, risk, and...  ...$125,000 - $175,000 and a comprehensive benefits package, with a flexible remote work model. #J-18808-Ljbffr Savant Wealth Management
    Remote job
    Flexible hours

    Savant Wealth Management

    Chicago, IL
    21 hours ago
  •  ...LLC is seeking a Consulting Manager focused on Governance, Risk & Compliance in Chicago, IL. In this role, you will lead the implementation of Workiva GRC, ensuring quality delivery and managing project timelines. The ideal candidate has over 6 years of experience with... 
    Remote job

    Clearsulting LLC

    Chicago, IL
    21 hours ago
  •  ...GRC Lead At Brain Co., we focus on applying frontier AI to real institutional challenges, working alongside governments, healthcare systems, and critical industries to modernize how essential services operate. We are looking for leaders who want to help bring new technology... 
    Remote work
    Worldwide
    Day shift

    BRAIN CORP

    United States
    21 hours ago
  •  ...candidate will have over 6 years of experience with Workiva GRC implementations, lead project delivery, and manage client communications...  ...implementation support. The position offers a flexible hybrid or remote working model as well as a comprehensive benefits package,... 
    Remote job
    Flexible hours

    Clearsulting

    Columbus, OH
    1 day ago
  •  ...GRC & Cybersecurity Lead Tokyo, Japan About Paidy Inc. Paidy is Japan's pioneer and leading BNPL service company. At Paidy we believe...  ...growing organization. Cross-functional collaboration. Flexible remote work options available. Competitive salary and benefits.... 
    Remote work
    Ongoing contract
    Local area
    Flexible hours

    Paidy

    United States
    1 day ago
  • $155k

     ...Job Posting Title: Cybersecurity GRC Team Lead ---- Hiring Department: Information Security Office ---- Position Open To...  ...AUSTIN, TX ---- Job Details: General Notes This is a remote-eligible opportunity offering flexible work arrangements,... 
    Remote work
    Full time
    For contractors
    Work at office
    Immediate start
    Flexible hours

    The University of Texas at Austin

    Austin, TX
    1 day ago
  • $155k

     ...Cybersecurity GRC Team Lead This is a remote-eligible opportunity offering flexible work arrangements, competitive benefits, and the chance to lead a highly impactful team within the Information Security Office (ISO) at UT Austin. The Cybersecurity Governance, Risk,... 
    Remote work
    Full time
    Work at office
    Flexible hours

    The University of Texas at Austin Staff

    United States
    2 days ago
  •  ...operational leader to drive the success of our CMMC GRC practice. In this role, you will bridge...  ...goals and tactical execution. You will lead the CMMC readiness Service Delivery...  ...manage the schedule for both on‑site and remote engagements. Strategic vCISO Advisory Executive... 
    Remote work

    The ProActive Technology Group

    New York, NY
    1 day ago
  • Neier Inc. is hiring a Principal GRC Analyst to lead the build-out of compliance and risk programs in a rapidly evolving environment. The role...  ...possess relevant certifications. The position is primarily remote, with a preference for candidates near Los Angeles, CA,... 
    Remote job

    Neier Inc

    California, MO
    3 days ago
  • $125k - $175k

    GRC Lead Build the program. Own the outcome. Shape what comes next. Savant is hiring a GRC Lead to design, build, and own our governance...  ...high‑impact activities. How You’ll Work Primarily remote, with flexibility to meet in person at Chicagoland regional offices... 
    Remote work
    Summer work
    Immediate start
    Work visa
    Flexible hours
    1 day per week

    Savant Wealth Management

    Chicago, IL
    21 hours ago
  •  ...GRC Lead Ibexa is a European marketing orchestration platform that empowers organisations to deliver seamless, data-driven customer experiences across the entire digital journey. By unifying content management, customer data, engagement, product information, and interactive... 
    Remote work

    Quable

    United States
    2 days ago
  •  ...Campus-Umgebungen seiner Kunden. Aufgaben Als Lead Consultant spielen Sie eine bedeutende und...  ...und strategische Weiterentwicklung des GRC-Bereichs Unterstützung des Vertriebs bei...  ...Unternehmen Dienstsitz: Raum Ingolstadt, remote Einstellungsdatum: schnellst möglich Gehalt... 
    Remote job
    Flexible hours

    PSC Pro Search Consulting GmbH Unternehmensberatung

    New Bremen, OH
    3 days ago
  • Neier Inc. is seeking a highly skilled GRC Privacy Senior Analyst to lead privacy initiatives and ensure compliance with global data protection regulations. The role involves conducting Privacy Impact Assessments, developing Records of Processing, and managing Data Subject... 
    Remote job

    Neier Inc.

    Brooklyn, NY
    4 days ago
  •  ...seeking a Senior Governance, Risk, Compliance (GRC) Analyst to join the Security Team in New York City. This role involves leading GRC initiatives, managing compliance...  ...packages, health insurance, and a flexible remote work model for East Coast candidates. #J-188... 
    Remote work
    Flexible hours

    Itlearn360

    New York, NY
    3 days ago
  •  ...Job Description: Job Title: GRC Security Compliance Leader Location: Remote Duration: 12+ Months (Contract) Work Time zone: PST Hours Responsibilities: ~ Support implementing and managing Information -Security Management Systems by ISO27001 standards... 
    Remote work
    Contract work
    Work at office
    Early shift

    Avant Digital Inc

    San Francisco, CA
    4 days ago
  • A leading digital security firm is seeking a GRC Security Compliance Leader for a remote position. Candidates should have 8-10 years of experience in Information Security and Compliance, with expertise in ISO 27001 and other relevant standards. Responsibilities include... 
    Remote job

    Avantdigitalnow

    San Francisco, CA
    2 days ago
  • A technology consulting firm is seeking an Infosec or GRC Leader to implement and manage Information Security Management Systems and...  ...and supporting supply chain risk management. The role is available remotely for a duration of 6+ months. #J-18808-Ljbffr Avantdigitalnow
    Remote job

    Avantdigitalnow

    San Francisco, CA
    3 days ago
  • BitMEX is looking for a Security Risk Lead to bootstrap its Security Assurance practice. The role involves architecting security policies...  ..., and excellent communication skills. This position offers remote work flexibility and numerous employee benefits, aiming to foster... 
    Remote job

    Framework Ventures

    New York, NY
    2 days ago
  • A healthcare organization is seeking a Cybersecurity GRC Manager to lead their governance, risk, and compliance initiatives. This leadership role involves managing a team, ensuring HIPAA compliance, and overseeing cybersecurity audits. The ideal candidate has extensive... 
    Remote job
    Flexible hours

    Froedtert Health

    Menomonee Falls, WI
    4 days ago
  • A leading staffing and recruiting firm in Boston is seeking a seasoned cybersecurity compliance professional to strengthen risk management...  ...frameworks and auditing complex systems. The company offers remote work and flexible schedules, fostering a highly innovative... 
    Remote job
    Flexible hours

    ExperTech Inc.

    Boston, MA
    11 hours ago
  • $75 - $80 per hour

    Crystal Equation Corporation is seeking a highly experienced Security Governance, Risk, and Compliance (GRC) Program Manager to lead the Risk Organization. This remote position involves driving strategic risk initiatives, shaping the security posture, and ensuring... 
    Remote job
    Hourly pay

    Crystal Equation Corporation

    California, MO
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Remote GRC Lead. Be the first to apply!