Governance, Risk & Compliance (GRC) Manager
$190k - $215kSigma
Sigma is seeking an experienced GRC Manager to lead and scale our governance, risk, and compliance programs. This role is based in our San Francisco office or upcoming New York office and reports to the General Counsel. You'll have the opportunity to build a strategic, enterprise‑wide GRC function that enables business growth while managing organizational risk. What You’ll Do Governance Design and implement governance frameworks, including reporting, policy governance, and control oversight Establish and maintain enterprise policies, standards, and procedures across technology, security, privacy, and operational functions Build and lead a governance committee structure that provides appropriate oversight and decision‑making Create governance dashboards and metrics to provide visibility into program maturity and effectiveness Partner with leadership to align governance activities with business strategy and risk appetite Risk Management Develop and operate a comprehensive Enterprise Risk Management (ERM) program Conduct regular enterprise‑wide risk assessments and maintain a dynamic risk register Build and maintain business continuity and disaster recovery programs, including regular testing and tabletop exercises Implement third‑party risk management processes, including vendor risk assessments, contract reviews, and ongoing monitoring Create risk treatment plans and track remediation activities across the organization Facilitate risk‑informed decision‑making at all levels of the organization Coordinate with functional leaders to ensure risks across all business areas are identified and managed appropriately Compliance Own audit and certification programs including SOC 2, ISO 27001, HIPAA, and other relevant standards Develop and maintain compliance monitoring programs to track regulatory changes and work with the legal team to assess impact Partner with HR and Legal to support labor & employment compliance programs, including workplace safety, anti‑discrimination, wage and hour requirements, and multi‑jurisdictional employment regulations Monitor and ensure adherence to industry‑specific regulatory requirements relevant to Sigma’s business operations Manage security awareness training programs enterprise‑wide Conduct internal audits and assessments to validate control effectiveness Coordinate external audits and assessments with third‑party auditors Business Enablement Support sales and customer success teams with compliance documentation and security inquiries Develop customer‑facing materials that articulate Sigma’s risk management and compliance posture Complete and manage responses to customer security questionnaires and assessments (VSAs, SIGs, custom questionnaires) Enable efficient deal cycles by maintaining ready‑to‑use compliance artifacts, trust center content, and documentation Partner with Sales Engineering and Solutions teams to address prospect security and compliance requirements What You Bring Required 4+ years of experience in governance, risk management, and/or compliance roles, preferably in SaaS or technology companies Demonstrated experience building or significantly maturing a GRC program from the ground up Track record of successfully leading certification audits (SOC 2, ISO 27001, HIPAA, or similar) Experience implementing risk management frameworks (COSO, ISO 31000, NIST RMF, or similar) Strong knowledge of data privacy regulations and their practical application (GDPR, CCPA, etc.) Experience developing and maintaining information security and privacy policies, procedures, and control frameworks Strong business acumen with ability to translate risk and compliance requirements into business value Excellent communication skills with ability to influence stakeholders at all levels, including leadership Proven ability to manage multiple priorities and stakeholders in a fast‑paced, high‑growth environment Collaborative mindset and commitment to enabling business success while managing risk Preferred Experience with GRC platforms (ServiceNow GRC, Archer, LogicGate, or similar) Hands‑on experience with cloud environments (GCP, AWS, Azure) from a compliance and security perspective Experience with labor & employment compliance or cross‑functional collaboration with HR on regulatory matters Familiarity with multi‑state or international employment regulations Experience with continuous compliance automation tools (Vanta, Drata, Secureframe, Tugboat, or similar) Professional certifications such as CRISC, CISA, CISM, CGEIT, CISSP, or CIPP Experience in high‑growth SaaS or technology companies Background in both technical and operational risk management Experience working in organizations with distributed or remote teams Familiarity with security frameworks such as NIST CSF, CIS Controls, or OWASP Why Join Sigma This is an opportunity to build a world‑class GRC program that doesn’t just check boxes but genuinely enables the business to pursue opportunities with confidence. You’ll work across the entire organization, have direct access to the General Counsel, and make a tangible impact on how Sigma manages risk and creates value for customers. Additional Job Details The base salary range for this position is $190k - $215k annually. Compensation may vary outside of this range depending on a number of factors, including a candidate’s qualifications, skills, competencies and experience. Base pay is one part of the Total Package that is provided to compensate and recognize employees for their work at Sigma. This role is eligible for stock options, as well as a comprehensive benefits package. About Us Sigma is the AI Apps and agentic analytics platform built on the cloud data warehouse. Business and technical teams use Sigma to explore live data, build intelligent applications, and automate critical workflows all without moving data or breaking governance. Sigma supports a spreadsheet interface, SQL, Python, and native AI in a single governed workspace, giving every team the speed to act and IT the control to scale. Sigma is trusted by more than 2,000 customers, including AMD, Duolingo, Colgate‑Palmolive, and JPMorgan Chase. Sigma announced its $80M in Series E financing in May 2026. The round was led by Princeville Capital, with new strategic investors Databricks Ventures, ServiceNow Ventures, and Workday Ventures participating alongside returning investors Altimeter Capital, Avenir Growth Capital, D1 Capital Partners, K5 Global, NewView Capital, Spark Capital, Sutter Hill Ventures, and XN. This milestone follows Sigma reaching $200M in annual recurring revenue in April 2026, with more than 100% year‑over‑year growth and 1.1 million new active users added in the latest fiscal year. Benefits For Our Full‑Time Employees Equity Generous health benefits Flexible time off policy. Take the time off you need! Paid bonding time for all new parents Traditional and Roth 401k Commuter and FSA benefits Lunch Program Dog friendly office Sigma is an equal opportunity employer. We are committed to building a smart and strong team regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender, gender identity or expression, veteran, or any other protected status. We look forward to learning how your experience can enable all of us to grow. Note: We have an in‑office work environment in all our offices in SF, NYC, London and Sydney. Our Privacy Practices When you submit a job application on this site, Sigma processes your personal data for the purposes of evaluating your candidacy for employment at Sigma and as otherwise needed throughout the recruitment and hiring process. Please review Sigma’s Candidate Privacy Notice for more details. Please note that your personal data may be transferred to a country other than the one in which it was provided (including to the USA, the UK, and Canada, Australia). Sigma’s Use of AI This hiring process utilizes artificial intelligence tools to assist in candidate screening and assessment. Our AI tools are designed to complement, not replace, human decision‑making. #J-18808-Ljbffr Sigma
$130k - $160k
...Alumni Ventures is seeking a Senior GRC Analyst to operate and mature governance, risk, compliance, and audit readiness programs. This role involves collaboration across departments to ensure effective compliance practices. Ideal candidates have 5+ years in GRC and experience...SuggestedRemote workFlexible hours$190k - $215k
Governance, Risk & Compliance (GRC) Manager New York City, NY Sigma is seeking an experienced GRC Manager to lead and scale our governance, risk, and compliance programs. This role is based in our San Francisco office or upcoming New York office and reports to the General...SuggestedFull timeContract workWork at officeRemote workFlexible hours- Radar is hiring a Senior GRC Analyst in New York City to enhance security and compliance programs, focusing on third-party risk and SaaS governance. You will work with various teams to evaluate... ...Trust Lead. A passion for risk management and emerging tech is essential for...Suggested
$130k - $160k
...Department Engineering Team & Role As a Senior GRC Analyst at Benepass, you will help operate and mature the governance, risk, compliance, audit readiness, and customer assurance... ...auditor coordination, and audit response management. Control Testing: Maintain recurring...SuggestedFull timeWork at officeRemote workWork from homeFlexible hours$125k - $135k
GRC Analyst job at Suzy. Remote. Suzy puts the voice of the consumer at your fingertips. Whether you're a novice... ...backed by data-driven decisions. Learn more at The Governance, Risk, Compliance (GRC) Analyst will manage policies, procedures, and standards to govern the...SuggestedRemote jobWork experience placementImmediate start- A security consulting company in the United States is looking for a GRC Analyst II to support governance programs for clients. In this role, you will onboard customers, perform gap assessments, and develop security policies. The ideal candidate will have 2-3 years in information...
- Medium is seeking a GRC Analyst to deliver day-to-day Governance, Risk, and Compliance services as part of their Managed GRC offering. This role involves operational execution, coordination of compliance, security assurance, and governance activities, supporting clients...
- Senior Governance, Risk, Compliance (GRC) Analyst job at Oura. New York, NY. At Oura, our mission is to empower every person to own their inner potential... ...for efficiency and automation. Policy & Procedure Management - Analyze, draft, update, and maintain security and...Work at officeLocal areaRemote workFlexible hours
$212k - $230k
Director, Governance, Risk, and Compliance (GRC) Remote - USA At Clover, the Business Enablement team leads our technological advancement while ensuring... .... We deliver user-friendly corporate applications, manage complex data ecosystems, and provide efficient tech solutions...Temporary workFixed term contractWork at officeImmediate startRemote workFlexible hoursShift work- A leading provider of procurement solutions is seeking a Manager for InfoSec Governance Risk and Compliance (GRC) in New York City. This role involves leading a team to manage the GRC program, ensuring compliance with certifications, and serving as a subject matter expert...
- A growing fintech company is seeking a GRC Program Manager to lead governance, risk, and compliance initiatives. The role encompasses managing audits like SOC 1 and SOC 2, developing compliance frameworks, and collaborating with different teams to ensure operational integrity...Remote workFlexible hours
- Pfizer Belgium is seeking a Director of GRC Technology and Metrics to lead its cybersecurity governance, risk, and compliance technology initiatives. This strategic role involves... ...automation, and enabling data-driven risk management across the enterprise. The ideal candidate...
$240k - $270k
A leading healthcare company is seeking a Director of Compliance and Regulatory to shape its Governance, Risk, and Compliance strategy. You will manage regulatory risks, develop compliance frameworks, and guide product initiatives to ensure adherence to regulations like...Remote jobFlexible hours$212k - $230k
...technology company in the United States is seeking a Director of Governance, Risk, and Compliance (GRC) to define and execute security governance strategies. This role requires strong expertise in managing compliance, overseeing third-party risks, and leading audits....Remote job- ...is seeking a senior leader to transform their InfoSec Governance, Risk, and Compliance (GRC) program. This role will drive strategic initiatives to... ...with strong leadership skills and a proven record in risk management. This position offers a competitive salary range in New...
$161.6k - $202k
...that responsibility demands a security and compliance program that scales with the business. We're building out our dedicated GRC team to improve and mature our program!... ...HITRUST, SOC 2, PCI-DSS, HIPAA), third-party risk management, security awareness training, and...Work from homeFlexible hours- ...About the role We’re hiring a Senior GRC Analyst to help scale Radar’s security and compliance programs, with a focus on third‑party risk and modern SaaS governance. You’ll partner with Engineering,... ...teams to evaluate vendors, manage risk, and help shape a practical,...Work at officeRemote work
- ...us. The Role Rogo is hiring a GRC Analyst to support our customer... ..., security assurance, and compliance programs as we scale globally.... ...teams to ensure Rogo’s controls, risk posture, and security practices... ...to detail and the ability to manage multiple parallel requests without...
- ...Hotman Group is seeking an Entry Level GRC Analyst to work remotely in the USA. The role involves assessing client security, developing risk frameworks, and translating technical requirements into actionable steps. Candidates should possess a relevant degree and 1-2 years...Remote work
$91k - $114k
Early Warning Services LLC is seeking a Security Governance, Risk & Compliance Analyst based in New York. The role focuses on managing security governance, overseeing risk assessments, and ensuring compliance with various regulatory requirements. The ideal candidate will...$205k - $225k
...commercial acumen, and a human touch. Reporting directly to the Firm's Director of Information Security, the Security Governance, Risk, and Compliance (GRC) Manager is considered an essential position in safeguarding our Firm's data and meeting clients' security requirements....Full timeWork at officeOverseas$90k - $150k
Governance, Risk, and Compliance Supervisor or Manager Job Category: Advisory Requisition Number: GOVER002831 Posted: November 12, 2025 Full-Time Hybrid Locations... ...York City-based Governance, Risk, and Compliance (GRC) practice is looking for an ambitious Supervisor or...Full timeWork at officeFlexible hours3 days per week- ...Services LLC based in New York is searching for a Security Governance, Risk & Compliance Analyst. The role involves supporting various security... ...work in a hybrid environment, allowing collaboration while managing essential audits and compliance programs. Qualified...
- ...cybersecurity firm is looking for a detail-oriented Entry-Level GRC Analyst to join their remote team. In this role, you'll work... ...closely with senior members to strengthen client cybersecurity and compliance programs. You'll be involved in assessing controls, developing...Remote job
- 6AM City, LLC is seeking a Policy Assessor (GRC Analyst / Third Party Risk Management) to work in Atlanta, GA, on a hybrid basis. The role involves reviewing regulatory requirements and assessing compliance documents, requiring a strong background in information security...
- Job Description Job Title: Policy Assessors (GRC Analyst / Third Party Risk Management) Work Location: Atlanta, GA 30308 (Hybrid) Duration: Long Term... ...and artifacts) to determine validity as proof of compliance with requirement(s) Work directly with SMEs/providers...
$95k - $115k
...tech company specializing in identity verification is looking for an Analyst in GRC for the public sector. This role involves enhancing governance, risk, and compliance operations, managing vulnerability remediation, and collaborating with various teams for regulatory compliance...Remote job- ...winning team.Job Description:We are looking for a Security Governance, Risk, and Compliance (GRC) Analyst to support and mature our security and... ...maintaining security policies, strengthening vendor risk management, supporting CMMC Level 2 compliance, and helping build...For contractors
$95k - $115k
...from top banks and fintechs to government agencies—we solve real, high... ...is seeking an Analyst, GRC - Public Sector to execute and... ...enhance the company’s governance, risk, and compliance operations for its public... ...and audit readiness by managing vulnerability remediation, continuous...Permanent employmentFull timeContract workRemote work- We are seeking a talented Senior Governance, Risk, and Compliance (GRC) Analyst / Engineer to join our innovative team focused on advancing robotic... ...using BI tools like PowerBI or Looker Excellent project management skills with the ability to prioritize in a fast-paced...Remote workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Governance, Risk & Compliance (GRC) Manager. Be the first to apply!
- governance manager New York, NY
- data governance director New York, NY
- data governance manager New York, NY
- risk management specialist New York, NY
- risk analytics manager New York, NY
- senior risk manager New York, NY
- director of risk management New York, NY
- enterprise risk manager New York, NY
- risk management manager New York, NY
- risk management associate New York, NY

