Jobiba hiring network

Grc Manager Jobs

91 active opportunities · Updated for September 2026

Fresh results

15 shown

Explore current grc manager jobs. Use filters to narrow by work mode, employment type, experience and date posted.

B

GRC Manager

Exact match
Baseten
📍 San FranciscoFull-time
28 days ago

ABOUT BASETEN Baseten powers mission-critical inference for the world's most dynamic AI companies, like Cursor, Notion, OpenEvidence, Abridge, Clay, Gamma and Writer. By uniting applied AI research, flexible infrastructure, and seamless developer tooling, we enable companies operating at the frontier of AI to bring cutting-edge models into production. We're growing quickly and recently raised our $1.5B Series F , led by Altimeter Capital, Conviction Partners, and Spark Capital. Join us and help build the platform engineers turn to to ship AI products. THE ROLE We are seeking an experienced and detail-oriented GRC (Governance, Risk, and Compliance) Manager to build, support, and continuously enhance Baseten’s security governance, compliance, and privacy programs. As one of the early members of our security organization, you will play a key role in ensuring our platform meets and exceeds the highest standards for privacy, trust, and regulatory compliance. In this role, you’ll work cross-functionally with engineering, operations, legal, and leadership teams to develop policies, manage audits, and implement controls aligned with frameworks such as SOC 2, ISO 27001, ISO 27701, and FedRAMP. You’ll be instrumental in building scalable processes to manage risk, support customer assurance, and uphold Baseten’s commitment to security and compliance as we grow. RESPONSIBILITIES Governance & Policy Development: Design, implement, and maintain security governance frameworks, policies, and procedures that align with Baseten’s risk posture and industry best practices. Risk Management: Build and manage the company-wide risk assessment program, identifying, tracking, and mitigating key security and compliance risks. Compliance Operations: Lead efforts to achieve and maintain compliance with SOC 2, ISO 27001/27701, HIPAA, FedRAMP and other applicable standards and regulations. Audit & Certification Management: Coordinate external audits and certification processes, ensuring e

awsgcpmachine learning
View job →
O
OpenAI
📍 San FranciscoFull-timeRemote
14 days ago

About the Team Governance, Risk, and Compliance (GRC) is foundational to Security delivering mission outcomes at OpenAI. The GRC team provides security assurances and builds compliance for OpenAI’s technology, people, and products. We are technical in what we build but operational in how we do our work, and we partner deeply with Product, Security, Legal, Privacy, GTM, and Field Security to help OpenAI move quickly while maintaining trust with customers, auditors, regulators, and the public. About the Role We are looking for an experienced Product Lifecycle Assurance IC to help scale OpenAI’s GRC function across our product stack to ensure products address customer and regulatory compliance requirements at launch and regressions are detected promptly and corrected. You will partner closely with Product, Security, Legal, and Privacy teams to make sure OpenAI can move quickly while maintaining our security, privacy and compliance claims and giving customers, auditors, and regulators assurance about how OpenAI handles user data. You are responsible for product assurance end-to-end from inception to post-launch (continuous) monitoring. You leverage existing workflows, reviews, and data and enhance, augment and build the components needed to create an end-to-end product assurance program. This role is not about supporting SOC or ISO audits; it's a highly cross-functional and deeply technical operations role to ensure that OAI products meet the compliance bar at launch, regressions are prevented and detected, and our compliance state can be evidenced. This role also helps ensure that our product launch governance program operates effectively across key safety, privacy, legal and security stakeholders and lessons-learned from incidents and regressions are used to improve the program. You or in partnership with engineering teams, build key controls in our infrastructure stack, developer workflows and launch tooling to provide developers with guardrails, perform CI/CD confor

REMOTEawskubernetesci/cd
View job →
CV
Company via Lever
📍 New YorkFull-timeHybrid
29 days ago

A World-Changing Company Palantir builds the world’s leading software for data-driven decisions and operations. By bringing the right data to the people who need it, our platforms empower our partners to develop lifesaving drugs, forecast supply chain disruptions, locate missing children, and more. The Role As a GRC Program Manager, you are the engine behind Palantir's Governance, Risk, and Compliance programs. You partner with compliance engineers, security teams, and developers to design and scale the processes that keep our Commercial, International, and US Government businesses operating at the highest regulatory standards. You track and stabilize projects, remove roadblocks, and anticipate stakeholder needs to free up our specialists to focus on the problems they are best equipped to solve.

CV
Company via Lever
📍 SeattleFull-timeHybrid
29 days ago

A World-Changing Company Palantir builds the world’s leading software for data-driven decisions and operations. By bringing the right data to the people who need it, our platforms empower our partners to develop lifesaving drugs, forecast supply chain disruptions, locate missing children, and more. The Role As a GRC Program Manager, you are the engine behind Palantir's Governance, Risk, and Compliance programs. You partner with compliance engineers, security teams, and developers to design and scale the processes that keep our Commercial, International, and US Government businesses operating at the highest regulatory standards. You track and stabilize projects, remove roadblocks, and anticipate stakeholder needs to free up our specialists to focus on the problems they are best equipped to solve.

CV
Company via Lever
📍 WashingtonFull-timeHybrid
29 days ago

A World-Changing Company Palantir builds the world’s leading software for data-driven decisions and operations. By bringing the right data to the people who need it, our platforms empower our partners to develop lifesaving drugs, forecast supply chain disruptions, locate missing children, and more. The Role As a GRC Program Manager, you are the engine behind Palantir's Governance, Risk, and Compliance programs. You partner with compliance engineers, security teams, and developers to design and scale the processes that keep our Commercial, International, and US Government businesses operating at the highest regulatory standards. You track and stabilize projects, remove roadblocks, and anticipate stakeholder needs to free up our specialists to focus on the problems they are best equipped to solve.

About the Team OpenAI’s Governance, Risk, and Compliance team helps ensure security and privacy are grounded in how our products and systems actually operate. Assurance Operations partners with Security, Engineering, Infrastructure, Product, Privacy, and Legal to make controls provable, risk decisions explicit, and audit readiness a result of well-designed systems. About the Role We are hiring a technical, product-minded GRC builder who can own consequential audits while improving the control and evidence systems behind them. You will build a reusable common control framework, use Codex to automate assurance work, validate changing system scope, and turn repeated audit friction into measurable improvements. We are looking for someone who questions inherited assumptions, solves novel problems creatively, works closely with engineers, and makes the next audit easier by improving the underlying system. You’ll be responsible for: Lead external, internal, customer, and certification audit work from scoping through evidence review, fieldwork, remediation, and closeout. Build a common control framework linking risk, control intent, implementation, owner, system, environment, evidence, and applicable frameworks. Validate actual scope and ownership instead of assuming last year's controls, product boundaries, or evidence remain accurate. Use Codex to build and test evidence checks, control mappings, request triage, owner workflows, monitoring, and remediation reporting. Partner with engineers on cloud architecture, identity, logging, data flows, software changes, vulnerabilities, and control effectiveness. Design maintainable, permission-aware tools that preserve source provenance, human review, and evidence integrity. Reduce repeated requests and operational burden for control owners through measurable workflow improvements. Define roadmaps, decision rights, milestones, success metrics, and clear cross-functional escalations. We’re looking for someone with: Direct ownership

sqlawsrest
View job →
O
1mo ago

About the Team Governance, Risk, and Compliance (GRC) is foundational to Security delivering mission outcomes at OpenAI. We’re excited about building creative solutions to ambiguous security requirements and delivering new technologies to mission critical customers. The GRC team provides security and engineering expertise to ensure our customers’ most critical and stringent requirements are met. We are technical in what we build but are operational in how we do our work, and are committed to obtaining, expanding, and maintaining Authorizations to Operate (ATOs) for critical systems while fostering a collaborative and execution-driven culture. About the Role Our technologies support some of the most important and impactful work in the world, including our strategic and high-impact customers in the public sector. As a GRC Program Manager, you’ll play a pivotal role in achieving US government (USG) ATOs and compliance frameworks, including but not limited to FedRAMP and Department of War (DoW),for OpenAI products and support agency-specific ATOs for systems deployed in highly regulated and secure environments. You’ll work closely with engineers, internal stakeholders, and external assessors to design, document, and implement security controls that meet stringent compliance requirements. Your creativity and execution-focused approach will be critical in navigating complex challenges while maintaining the trust of our stakeholders. We’re looking for people who bring: Proven experience in obtaining and maintaining a FedRAMP ATO and agency specific ATOs in highly restricted environments, within government or regulated sectors. A deep understanding of USG security frameworks and policies (e.g., NIST, RMF, FedRAMP). Ability to communicate technical concepts to diverse audiences, including engineers and non-technical stakeholders. Exceptional technical program management skills, with the ability to multitask and deliver large complex programs under pressure. This role is base

awsazurekubernetes
View job →
AG
26 days ago

The Business Unit Cyber Lead will be responsible for leading and managing the cybersecurity strategy, execution, and risk management efforts within a specific business unit. This role serves as the primary point of contact for all cybersecurity-related matters within the business unit, ensuring that security risks are effectively identified, mitigated, and managed. The Business Unit Cyber Lead will work closely with business leaders, IT teams, and the enterprise cybersecurity function to ensure that cybersecurity initiatives are aligned with business objectives and effectively executed to protect the organization’s digital assets. Source: Adani Group | Job ID: 52026

S
Stripe
📍 RemoteFull-timeRemote
29 days ago

Who we are About Stripe Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world's largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career. About the team The Stripe Security team is dedicated to improving the security of Stripe and its users. Our users trust us with some of their most sensitive information, and we make security a first-class consideration in everything we do. Security concerns are ever-evolving, creating an extremely dynamic environment for the Security team. The Security Governance, Risk, and Compliance (SGRC) team at Stripe provides security governance, risk management, and compliance capabilities to allow Stripe to make strategic security decisions, measure our risk and control posture, and represent Stripe Security to internal and external entities. The successful operation of our organization accelerates Stripe by optimizing the communication and expectations of our security program. What you’ll do We're looking for a Security GRC Program Manager with deep expertise in security compliance to serve as the primary interface between Stripe's Security organization and external auditors, regulators, and compliance stakeholders. In this role, you'll represent the Security team in audit engagements, articulate how Stripe's security controls are designed and how they operate, and ensure that compliance obligations across a complex global regulatory landscape are met with consistency and rigor. In this role, you will act as a proxy between external entities like regulators and auditors, and our internal security teams, ensuring consistency in compliance responses and helping main

REMOTEaigorust
View job →
V
Vanta
📍 United StatesFull-time
28 days ago

At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. As Vanta expands upmarket, we have a unique opportunity to redefine how security and compliance programs are operated, while giving customers the flexibility to run their programs their way, especially in an AI-powered world. GRC Platform is a new team at the center of this effort, building the foundational capabilities that enable mid-market and enterprise customers to operate their GRC programs efficiently and at scale with Vanta. As the Senior Product Manager for GRC Platform, you will own core platform capabilities and primitives that customers rely on every day and that power critical GRC workflows—such as search, imports, exports, custom fields, and approval workflows. You will evolve these capabilities into more intelligent, agentic experiences that are increasingly flexible, automated, and adaptive, helping customers save time, reduce cognitive load, and focus on higher-value work. What you’ll do as a Senior Product Manager, GRC Platform at Vanta: Own the GRC Platform strategy and roadmap, delivering platform primitives and customer facing features leveraged across Vanta’s GRC product Distill complex problems and opportunities into clearly prioritized product goals, focus for your team, and high-quality execution in collaboration with stakeholders across the company. Partner closely with teams across GRC to develop a deep understanding of customer needs, identify opportunities for platform leverage, and translate those insights into intuitive, agentic experiences that solve critical user needs. Drive AI-first product redesigns, including defining model evaluation criteria and managing the transition from legacy experien

restaigo
View job →
C
Coinbase
📍 United StatesFull-timeRemoteFrom $194K/yr
15 days ago

Ready to do the most impactful work of your career? At Coinbase , we are uncompromising on our mission to increase economic freedom. The bar is high, the environment is intense, and we like it that way. This isn't a place for complacency, it’s a place to be pushed past your perceived limits. If you're ready to build the future of finance alongside people who refuse to settle for "good enough," you belong here. Coinbase is a remote-first, but not remote-only company. Expect to get together quarterly for intense in-person working sessions called “surges.” learn more about working at Coinbase . We're hiring a Manager, GRC to join our Technology Risk & Controls team within Security and lead second line of defense advisory coverage across critical technology and security domains. This team evaluates risk posture, improves control design, and helps engineering, infrastructure, and security leaders make better, risk-informed decisions. You'll both manage a team and directly own advisory coverage for domains that may include disaster recovery and resiliency, SDLC, artificial intelligence, identity and access management, and supply chain - building trusted partnerships that ensure Coinbase addresses its most critical risks in its most critical functions. What you'll do: Lead second line advisory coverage for key technology and security domains, assessing risk exposure, control effectiveness, policy alignment, and emerging issues across the business. Partner with engineering and technology teams to evaluate domain posture and identify where additional controls, remediation, or governance improvements are needed. Review and challenge the design of new and existing risks and their corresponding controls to ensure our mitigations are scalable, effective, and aligned to business, risk, and regulatory expectations. Drive coordination across risk, controls, policy, audit, and assurance teams to translate incidents, audit findings, and regulatory expectations i

REMOTEawsaigo
View job →
D
Datadog
📍 New YorkFull-timeFrom $192K/yr
29 days ago

As the Engineering Manager for Commercial Audit, you will lead a high-performing team responsible for scaling Datadog’s security and compliance posture through automation, tooling, and engineering excellence. Our GRC (Governance, Risk, and Compliance) function is a critical partner to the broader Security and Engineering organizations, ensuring that Datadog not only meets rigorous global regulatory standards but does so in a way that is efficient, scalable, and integrated into our cloud-native infrastructure. You will manage a team of engineers and analysts who are transitioning to a GRC engineering direction to treat compliance as a software problem, leveraging AI, custom tooling, CI/CD pipelines, and cloud-native services to turn complex regulatory requirements into actionable, automated controls. You will lead the strategy, roadmap, and execution of Datadog’s Commercial Audit initiatives. This is a high-impact leadership role where you will grow a team of engineers and analysts responsible for directly maintaining our compliance programs and related audits (e.g., SOC2, PCI, HIPAA, ISO) while looking to improve efficiency and effectiveness through platforms and tooling. You will act as a bridge between technical engineering, legal, and compliance, enabling the organization to move fast while maintaining a secure and compliant environment. You will champion a culture of "compliance-as-code," identifying opportunities to automate evidence collection, streamline control testing, and reduce manual toil for both your team and our partner engineering teams. At Datadog, we place value in our office culture - the relationships and collaboration it builds, and the creativity it brings to the table. We operate as a hybrid workplace to ensure our Datadogs can create a work-life harmony that best fits them. What You’ll Do: Lead the strategy, roadmap, and execution of Datadog’s commercial security compliance efforts, shifting from manual audit processes to automated, scalable

pythonawsazure
View job →
V
26 days ago

At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. As a Solutions Engineer, you'll serve as a trusted technical voice, guiding customers toward clarity, feasibility, and alignment on the end-to-end solution. Because Vanta is the platform our customers rely on to build and run their GRC programmes, this is a natural next step for GRC professionals, programme managers, auditors, and compliance practitioners who want to apply their domain expertise in a strategic, customer-facing pre-sales role. You’ll be an integral part of the Sales team, working to ensure technical fit and create innovative solutions for our customers. Your attention to detail, focused on customer needs, will ultimately improve retention and overall success. This role will be based from our London office or Dublin office with an office-centric hybrid schedule. The standard in-office days are Tuesday, Wednesday, and Thursday. GRC practitioners are especially encouraged to apply—whether you've managed GRC programmes in-house, audited them as an internal or external auditor, or helped customers meet their GRC programme needs at a GRC vendor, you'll bring exactly the customer empathy and domain fluency this role thrives on. What you’ll do as a Solutions Engineer at Vanta: Serve as a strategic sales partner, owning the technical relationship with prospects and customers. Strategic Discovery and Deal Qualification: Partner with Account Executives to uncover technical, operational, and business pain points, validating use cases and aligning solutions to measurable customer impact and urgency. Secure the Solution Win and Alignment: Validate technical feasibility, drive clarity on success criteria, and guide stakeholder

REMOTEjavascriptpythonjava
View job →

At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. As a Solutions Engineer, you'll serve as a trusted technical voice, guiding customers toward clarity, feasibility, and alignment on the end-to-end solution. Because Vanta is the platform our customers rely on to build and run their GRC programmes, this is a natural next step for GRC professionals, programme managers, auditors, and compliance practitioners who want to apply their domain expertise in a strategic, customer-facing pre-sales role. You’ll be an integral part of the Sales team, working to ensure technical fit and create innovative solutions for our customers. Your attention to detail, focused on customer needs, will ultimately improve retention and overall success. This role will be based from our London office or Dublin office with an office-centric hybrid schedule. The standard in-office days are Tuesday, Wednesday, and Thursday. GRC practitioners are especially encouraged to apply—whether you've managed GRC programmes in-house, audited them as an internal or external auditor, or helped customers meet their GRC programme needs at a GRC vendor, you'll bring exactly the customer empathy and domain fluency this role thrives on. What you’ll do as a Solutions Engineer at Vanta: Serve as a strategic sales partner, owning the technical relationship with prospects and customers. Strategic Discovery and Deal Qualification: Partner with Account Executives to uncover technical, operational, and business pain points, validating use cases and aligning solutions to measurable customer impact and urgency. Secure the Solution Win and Alignment: Validate technical feasibility, drive clarity on success criteria, and guide stakeholder

javascriptpythonjava
View job →
V
Vanta
📍 TorontoFull-time
28 days ago

At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. As an Engineering Manager leading our Reporting team, you will lead a newly structured team focused on a critical product area within GRC Program Orchestration. This role represents an exciting opportunity to shape the future of how Vanta customers understand, visualize, and operationalize their compliance and security programs. This team is focused on evolving Vanta’s reporting platform beyond dashboards into a scalable, AI-powered reporting experience. The team owns core initiatives across enterprise reporting, historical analytics, AI-assisted insights, and certified data infrastructure powering in-product experiences. This role sits at the intersection of data products, enterprise scalability, and product innovation. As reporting becomes increasingly foundational to enterprise growth, customer retention, and Vanta’s long-term AI strategy, this role will play a key role in shaping engineering execution, cross-functional alignment, and the long-term technical direction of one of Vanta’s critical product investments. Visit our Vanta Engineering Blog to learn more about what our team is working on! What you’ll do as an Engineering Manager at Vanta: Build and scale a high-performing team: lead, coach, and grow the team while hiring strategically, identifying operational gaps, and raising the engineering bar Drive execution across strategic initiatives: Deliver against a multi-quarter roadmap spanning reporting infrastructure, enterprise reporting capabilities, AI-powered insights, and scalable data foundations Shape technical and product strategy: Partner closely with Product and cross-functional engineering teams to define the

restairust
View job →
🔔

Get new grc manager jobs by email

Daily job updates · Unsubscribe anytime