GRC Program Manager
$90,000–$160,000 year
On-siteNew York, United States
Job Summary
Design and continuously improve compliance processes and frameworks to scale GRC operations across Commercial, International, and US Government environments. Serve as connective tissue across teams, translating regulatory requirements into actionable workflows and ensuring accountability at every stage of the compliance lifecycle. Coordinate across internal and external audit cycles (FedRAMP, SOC 2, ISO 27001, etc.), ensuring evidence collection, remediation tracking, and stakeholder communication stay on schedule. Keep a broad state of all project-related items, including audit timelines and control implementation status, while pre-empting and resolving issues that may steer projects off-course. Enhance cross-team collaboration across engineering, legal, and customer-facing teams to drive key GRC deliverables through the entire software development and compliance lifecycle. Synthesize concrete compliance goals from product and regulatory vision, mapping global strategy to granular team tasks and issues. Work with customer-facing engineering teams on adoption, roll out, and support of compliance-related product features and certifications. This role requires working from the country listed on the posting and being within a commutable distance of the local office; U.S. security clearance eligibility is preferred.
Required Qualifications
- Demonstrated success managing compliance programs for an enterprise software company, startup or other company
- Experience with multiple GRC frameworks and standards, such as SOC 2, ISO 27001, IRAP or ENS
- Experience in USG-specific frameworks: FedRAMP, NIST 800-53, DoD CC SRG, FISMA, or CMMC
- Excellent judgment and composure in high-pressure situations, including during active audits or compliance incidents
- A creative approach to project management centered around lightweight frameworks that enable rapid iteration, while operating in harmony with a larger development and compliance organization
- An ability to develop strong relationships with key internal stakeholders (including customer-facing teams), auditors, and regulators, with a high level of empathy for our end-users' needs
- Meticulous attention to detail, including holding tightly to your team's compliance and product quality bar
- A proven track record of building and scaling compliance processes from the ground up, particularly in USG-regulated environments
- Experience with risk management methodologies, including maintaining risk registers, conducting risk assessments, and managing third-party or vendor risk programs
- Willingness and eligibility to obtain a U.S. security clearance
Desired Qualifications
- Willingness and eligibility to obtain a U.S. security clearance preferred
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.