Jobiba hiring network

Grc Manager Jobs

91 active opportunities · Updated for September 2026

Fresh results

15 shown

Explore current grc manager jobs. Use filters to narrow by work mode, employment type, experience and date posted.

V
Vanta
📍 United StatesFull-timeRemote
11 days ago

At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. This is not a back-office compliance role and it is not a generic sales-engineering role. You will operate as a named member of deal teams under our pod model: paired with Strategic and Enterprise Account Executives, embedded in their weekly cadences, engaged from first discovery through POC, onsite, close, and expansion. You will be the practitioner in the room that a buyer's CISO or GRC lead trusts — and the internal expert our AEs, SEs, and marketing team build around. What you’ll do as a Subject Matter Expert, GTM at Vanta: Serve as the dedicated GRC SME for a book of Strategic/Enterprise Account Executives: join discovery and qualification calls at the earliest deal stages, scope compliance programs against Vanta's platform, and support demos, POCs, workshops, and customer onsites across Compliance, Third-Party Risk Management, Risk Management, and Trust/Questionnaire Automation. Advise prospects on program architecture: multi-framework strategy, shared controls, business-unit and workspace scoping, custom frameworks, and audit sequencing. Answer field questions through our SME channels at customer-forwardable quality — including reviewing and validating AI-agent-generated answers before they reach customers. Our team runs AI-first: you'll use agents daily, act as the quality gate on their output, and (ideally) build tooling of your own. Design and deliver enablement: live sessions for GTM teams, bootcamp scenarios and mock-customer roleplay, async curriculum modules, and review of GRC marketing and SEO content. Own monthly alignment cadences with sales front-line managers; feed structured product feedback to our Product a

REMOTErestaigo
View job →
V
26 days ago

At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. As a Solutions Engineer, you'll serve as a trusted technical voice, guiding customers toward clarity, feasibility, and alignment on the end-to-end solution. Because Vanta is the platform our customers rely on to build and run their GRC programmes, this is a natural next step for GRC professionals, programme managers, auditors, and compliance practitioners who want to apply their domain expertise in a strategic, customer-facing pre-sales role. You’ll be an integral part of the Sales team, working to ensure technical fit and create innovative solutions for our customers. Your attention to detail, focused on customer needs, will ultimately improve retention and overall success. This role will be based from our London office or Dublin office with an office-centric hybrid schedule. The standard in-office days are Tuesday, Wednesday, and Thursday. GRC practitioners are especially encouraged to apply—whether you've managed GRC programmes in-house, audited them as an internal or external auditor, or helped customers meet their GRC programme needs at a GRC vendor, you'll bring exactly the customer empathy and domain fluency this role thrives on. What you’ll do as a Solutions Engineer at Vanta: Serve as a strategic sales partner, owning the technical relationship with prospects and customers. Strategic Discovery and Deal Qualification: Partner with Account Executives to uncover technical, operational, and business pain points, validating use cases and aligning solutions to measurable customer impact and urgency. Secure the Solution Win and Alignment: Validate technical feasibility, drive clarity on success criteria, and guide stakeholder

REMOTEjavascriptpythonjava
View job →
V
26 days ago

At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. As a Solutions Engineer, you'll serve as a trusted technical voice, guiding customers toward clarity, feasibility, and alignment on the end-to-end solution. Because Vanta is the platform our customers rely on to build and run their GRC programmes, this is a natural next step for GRC professionals, programme managers, auditors, and compliance practitioners who want to apply their domain expertise in a strategic, customer-facing pre-sales role. You’ll be an integral part of the Sales team, working to ensure technical fit and create innovative solutions for our customers. Your attention to detail, focused on customer needs, will ultimately improve retention and overall success. This role will be based from our London office or Dublin office with an office-centric hybrid schedule. The standard in-office days are Tuesday, Wednesday, and Thursday. GRC practitioners are especially encouraged to apply—whether you've managed GRC programmes in-house, audited them as an internal or external auditor, or helped customers meet their GRC programme needs at a GRC vendor, you'll bring exactly the customer empathy and domain fluency this role thrives on. What you’ll do as a Solutions Engineer at Vanta: Serve as a strategic sales partner, owning the technical relationship with prospects and customers. Strategic Discovery and Deal Qualification: Partner with Account Executives to uncover technical, operational, and business pain points, validating use cases and aligning solutions to measurable customer impact and urgency. Secure the Solution Win and Alignment: Validate technical feasibility, drive clarity on success criteria, and guide stakeholder

javascriptpythonjava
View job →

At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. As a Solutions Engineer, you'll serve as a trusted technical voice, guiding customers toward clarity, feasibility, and alignment on the end-to-end solution. Because Vanta is the platform our customers rely on to build and run their GRC programmes, this is a natural next step for GRC professionals, programme managers, auditors, and compliance practitioners who want to apply their domain expertise in a strategic, customer-facing pre-sales role. You’ll be an integral part of the Sales team, working to ensure technical fit and create innovative solutions for our customers. Your attention to detail, focused on customer needs, will ultimately improve retention and overall success. With this role being specific to support our DACH Market account teams and customers, having full German Language proficiency is a must for this successful candidate. This role will be based from our London office with an office-centric hybrid schedule. The standard in-office days are Tuesday, Wednesday, and Thursday. GRC practitioners are especially encouraged to apply—whether you've managed GRC programmes in-house, audited them as an internal or external auditor, or helped customers meet their GRC programme needs at a GRC vendor, you'll bring exactly the customer empathy and domain fluency this role thrives on. What you’ll do as a Solutions Engineer at Vanta: Own the technical relationship with our commercial prospects/customers Develop a deep understanding of our product capabilities, integrations, configurations messaging, partner ecosystem, and competitive landscape. Listen carefully to prospects and clients to provide market feedback to the product te

javascriptpythonjava
View job →
V
Vanta
📍 United StatesFull-timeRemote
19 days ago

At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. As a Director of Product on our Governance & Compliance team, you will own the product strategy and deliver key capabilities that enable Vanta’s GRC product to meet the needs of our largest enterprise customers. You will drive company-wide initiatives requiring deep partnerships across PMM, engineering, design, and go-to-market teams. You will help scale Vanta’s capabilities alongside our rapidly growing customer base and shape the culture and processes of the product team, all while growing the talented PMs you lead. This role reports directly to the VP of Product for Governance and Compliance. What you’ll do as a Director of Product at Vanta: Own the product strategy and roadmap for across trust, audit, and segmentation Inherit, lead and grow a product team: Hire and mentor product managers while establishing strong product thinking and execution. Evolve your area’s product strategy to an AI-first approach, enabling agentic workflows within the product and with the outside ecosystem Be accountable for critical business metrics, including: Revenue from products and add-ons under your purview. Enterprise customer adoption and satisfaction metrics. Collaborate cross-functionally to define a vision and roadmap that balances innovation, scalability, and customer impact. How to be successful in this role: 12+ years of product management experience in high-growth and complex environments. 5+ years of experience hiring, managing, and growing high-performing teams. A passion for scaling B2B SaaS products that serve SMB and enterprise customers alike. A track record of setting clear product vision and business strategies for comple

REMOTErestaigo
View job →
O
OpenAI
📍 WashingtonFull-timeRemote
11 days ago

About the Team OpenAI’s mission is to ensure that general-purpose artificial intelligence benefits all of humanity. We believe that achieving our goal requires effective engagement with public policy stakeholders and the broader community impacted by AI. Accordingly, our Global Affairs team builds authentic, collaborative relationships with public officials and the broader AI policymaking community to inform and support our shared work in these domains. We ensure that insights from policymakers inform our work and – in collaboration with our colleagues and external stakeholders – seek to shape policy so that it aligns with and supports our mission. About the Role As AI agents move from answering questions to taking action across the internet, the standards that govern identity, delegated authority, discovery, communications, agentic-commerce and payment interfaces, agent-facing web access, agent-specific provenance, and auditability will determine whether agents can operate safely, interoperably, and with clear accountability. OpenAI is looking for an Agent Standards Manager to lead execution of our external technical standards strategy for a defined set of agent standards workstreams. This role will work closely with Agent Security, Applied and Platform teams, Product, Legal, GRC, Global Affairs, and GTM to turn OpenAI’s technical architecture and controls into credible specifications, protocol profiles, assurance criteria, and implementation guidance—and to bring emerging external requirements back into product and security roadmaps before they become blockers. The positions developed here are technical standards positions, not broad public-policy positions. This is a builder’s role as much as an external-facing role. You will execute a prioritized standards plan, author and negotiate protocols, build coalitions, secure the right internal approvals, and represent OpenAI in assigned technical forums. You will also help create repeatable processes that let the compa

REMOTEawsrestai
View job →
G
Gusto
📍 San FranciscoFull-timeHybrid$221K – $247K/yr
29 days ago

About Gusto At Gusto, we're on a mission to grow the small business economy. We handle the hard stuff — payroll, health insurance, 401(k)s, and HR — so owners can focus on their craft and their customers. With teams in Denver, San Francisco, and New York, we support more than 500,000 small businesses nationwide and are building a workplace that reflects the people we serve. All full-time employees receive competitive base pay, benefits, and equity (RSUs) — because everyone who helps build Gusto should share in its success. Offer amounts are determined by role, level, and location. Learn more about our Total Rewards philosophy . AI is a fundamental part of how work gets done at Gusto. We expect all team members to actively engage with AI tools relevant to their role and grow their fluency as the technology evolves. AI experience requirements vary by role and will be assessed during the interview process. About the Role As a key member of Enterprise Applications IT (EAIT), the Legal Tech IT Product Manager owns the AI-first strategy, roadmap, and delivery of the enterprise applications supporting Gusto’s Legal & Compliance organization. This is an AI-forward product role: you will reimagine how legal and compliance work gets done by embedding generative AI, AI agents, and intelligent automation into systems like contract lifecycle management (CLM), matter and legal-spend management, e-signature, entity and corporate records management, legal hold and e-discovery, and governance, risk, and compliance (GRC) platforms. Acting as the primary interface between Legal & Compliance teams and EAIT delivery resources, you will translate business needs into well-defined, AI-enabled product requirements, guide solution design, and drive continuous improvement across core legal and compliance processes. In line with Gusto’s enterprise systems strategy, you will help shift legal operations from reactive, manual workflows to predictive, context-aware, an

reactaigo
View job →
R
Roblox
📍 San MateoFull-timeFrom $233.6K/yr
29 days ago

Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators. At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there. A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As a Senior Security Software Engineer for Infrastructure Security you will be a part of the Information Security organization and report to the Senior Manager of Infrastructure Security. You will help shape the future of Platform Security at Roblox. We work closely with Production IAM, Network Security, and Cloud Security at Roblox. You Will: Identify security gaps and threats in our cloud and on premise infrastructure, partnering with Governance Risk and Compliance teams to create standards and policies along the way. This will help Roblox meet regulatory and compliance requirements. Harden our infrastructure by introducing secure by default configurations, designs and guardrails for all developers at Roblox. Own and drive solutions that enable Roblox engineers to design, build, and use infrastructure securely at scale. Work closely with other InfoSec teams (AppSec, D&R, GRC, CorpSec, CloudSec, NetSec) and partner with engineering teams across Roblox, specifically the Infrastructure organization, to ensure the secure outcomes of security and product driven initiatives. You Have: 5+ years of experience writing code and/or relevant technical experience. Experience with

awskubernetesgit
View job →
R
Roblox
📍 San MateoFull-timeFrom $180.6K/yr
29 days ago

Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators. At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there. A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As a Senior Privacy Engineer on the Security and Privacy GRC team, you will shepherd and grow Roblox's Privacy Review Program, the technical and process backbone that ensures privacy is engineered into every product before it ships. You will join the Security and Privacy GRC team, reporting to the Sr Engineering Manager for Privacy Governance and Operations. This is a hands-on privacy engineering role: you'll set standards for privacy-enhancing technologies, act as the go-to SME for policy-as-code, and partner closely with Product teams, Trust & Safety, Legal, and Regulatory Compliance as part of Roblox's broader cross-functional privacy program. You will: Shepherd and evolve the Privacy Review Program, designing consistent intake workflows, evaluation criteria, and documentation to systematically assess privacy risk across new products, features, and infrastructure changes. Develop standards and guidelines that enable product teams to adopt privacy-enhancing technologies (PETs) such as differential privacy, k-anonymity, data minimization, and secure computation, with clear guidance on trade-offs and implementation patterns. Act as the Privacy SME for policy-as-code, translating privacy

awsgitai
View job →
R
Replit
📍 Foster CityFull-time
28 days ago

Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the role Replit is the agentic software creation platform that enables anyone to build applications using natural language. As we scale to support millions of developers and enterprise organizations, maintaining a robust, transparent, and technically sound Governance, Risk, and Compliance (GRC) program is critical. We are looking for a GRC Engineer to serve as a key technical contributor for our compliance and risk management ecosystem. You will architect the systems and processes that automate trust, partnering deeply across the organization. We need a pragmatic operator who understands that GRC exists to enable the business—balancing rigorous standards with the velocity of a high-growth startup. What You'll Do Technical Excellence & Architecture Technical Depth: Act as a technical subject matter expert for the GRC team. You will drive quality, technical depth, and operational efficiency in our security controls. Program Architecture: Own the technical vision for Replit’s GRC program, moving the team from manual workflows toward "Compliance-as-Code" and automated evidence collection. Thought Leadership: Champion a culture of security and privacy across the company, educating teams on why controls exist rather than just enforcing them. Cross-Functional Collaboration Engineering & Architecture: Partner with Architects and Engineering Leads to "bake in" compliance requirements early in the design phase. You will translate complex technical implementations into narratives that satisfy frameworks without slowing down development. Legal & Privacy: Work closely with Legal Counsel to interpret and implement requirements for Privacy (GDPR, CCPA) and emerging AI-specific regulations (e.g., EU AI Act). Sales &a

awsgcpai
View job →
S
Smartsheet
📍 -REMOTE, USA-Full-timeRemoteFrom $1.7M/yr
29 days ago

For over 20 years, Smartsheet has empowered teams to manage work seamlessly and scale solutions smarter. Now, in our most ambitious chapter yet, we are uniting human teams with AI agents. By orchestrating the work agents do best, automating manual tasks and uncovering insights at scale, we create the space for people to focus on what truly matters: judgment, creativity, and big thinking. That is magic at work, and it’s what we show up for every day. FedRAMP and GovRAMP (formerly StateRAMP) are transforming how Smartsheet serves government and regulated customers. We need a FedRAMP and GovRAMP subject matter expert to lead these programs—someone with real hands-on experience obtaining and maintaining ATO authorizations, navigating 3PAO assessments, and managing continuous monitoring requirements. In this role, you'll own Smartsheet's FedRAMP and GovRAMP certifications, manage relationships with our 3PAOs, drive annual assessment preparation, manage POA&M processes, and ensure we maintain authorizations at the highest level. You'll understand the nuances of federal compliance, speak fluently with government agencies and authorized assessors, and translate complex regulatory requirements into clear roadmaps for engineering and operations teams. You'll be the voice of federal compliance at Smartsheet and the trusted advisor to government customers on our security posture. You Will: Own FedRAMP and GovRAMP (formerly StateRAMP) certifications and roadmaps: Lead the overall strategy for obtaining and maintaining federal authorizations, including package management, compliance timelines, and authority coordination. Manage 3PAO relationships and assessments: Work with accredited third-party assessment organizations to conduct initial assessments and annual re-assessments. Coordinate scoping, evidence preparation, testing coordination, and results validation. Lead continuous monitoring (ConMon) execution: Oversee the delivery of monthly, annual, and event-driven Fed

REMOTEawsazuregcp
View job →
P
Pinterest
📍 San FranciscoFull-timeRemoteFrom $123.7K/yr
15 days ago

About Pinterest: Millions of people around the world come to our platform to find creative ideas, dream about new possibilities and plan for memories that will last a lifetime. At Pinterest, we’re on a mission to bring everyone the inspiration to create a life they love, and that starts with the people behind the product. Discover a career where you ignite innovation for millions, transform passion into growth opportunities, celebrate each other’s unique experiences and embrace the flexibility to do your best work. Creating a career you love? It’s Possible. At Pinterest, AI isn't just a feature, it's a powerful partner that augments our creativity and amplifies our impact, and we’re looking for candidates who are excited to be a part of that. To get a complete picture of your experience and abilities, we’ll explore your foundational skills and how you collaborate with AI. Through our interview process, what matters most is that you can always explain your approach, showing us not just what you know, but how you think. You can read more about our AI interview philosophy and how we use AI in our recruiting process here . Pinterest’s Security team (Pinfosec) is seeking an IC14 Security Engineer - Security Governance, Risk & Compliance (GRC Senior Analyst) to support and strengthen our security governance and assurance programs. This role is ideal for someone who is detail-oriented, collaborative, and motivated by building scalable security processes that help the business manage risk effectively. Reporting to the Interim Head of Security Governance, Risk & Compliance, this individual contributor will partner closely with Security, Engineering, IT, Legal, Internal Audit, and other cross-functional stakeholders to help maintain and improve Pinterest’s security control environment. The role will contribute to core GRC activities including risk management, policy governance, control testing, audit support, awareness tracking, and internal risk assessmen

REMOTEawsrestai
View job →
V
Vanta
📍 United StatesFull-time
28 days ago

At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. Vanta for Government (V4G) is how we bring that mission to the public sector. As federal compliance undergoes its biggest shift in a decade — FedRAMP 20x, machine-readable authorization, OSCAL — we're building the platform that turns federal frameworks into automated, continuously monitored product experiences. The GRC Subject Matter Experts on this team are the people who make that possible. As Vanta's GRC Subject Matter Expert for V4G , you'll own federal compliance content used by every customer pursuing or maintaining federal authorization on our platform. This is an interpretation-and-authoring role, not a compliance program administration role: your job is to interpret underlying control requirements, identify where FedRAMP modifies or constrains the NIST framework, and translate those interpretations into precise, technically testable guidance that engineering can build and customers can act on. The content you write ships as product — a five-person startup and a Fortune 100 CSP both receive it — so calibrating depth, precision, and universality is the core craft. You'll join Vanta's Security organization, which directly influences product development, facilitates the creation of automated GRC solutions for customers, and provides expert advisory services across the company. What you’ll do as a V4G GRC SME at Vanta: Build and own federal compliance frameworks — Lead the creation, enhancement, and lifecycle management of controls, evidence requirements, and implementation guidance for FedRAMP (Low/Moderate/High), NIST SP 800-53, NIST SP 800-171, CMMC, DFARS, and StateRAMP. Author clear control rationales, acceptance crite

awsazuregcp
View job →
R
28 days ago

Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the role: Replit’s ecosystem is powered by an expanding array of external services and essential AI model partners. As our lead for Security Vendor Risk & Contract Reviews, you will architect and execute a risk management program focused on substantive evaluation rather than just processing checklists. You’ll analyze SOC 2 documentation, security assessments, and system architectures to determine actual risk profiles, collaborating with our Legal team to secure necessary contractual protections. This role reports to the Head of Security GRC and involves high-impact partnerships across Legal, Engineering, and Product teams. What You'll Do Run substantive third-party risk management (TPRM), independently evaluating real risk, not just processing questionnaire responses Review SOC 2 reports, pen test findings, and architecture documentation to form an independent view of vendor risk, extending the same rigor to AI/model providers Partner with Legal on vendor and AI contract terms, including DPAs, subprocessor agreements, and AI-specific provisions Review contracts for non-standard security language when flagged by Legal or deal desk, and recommend redlines Maintain the vendor and AI/model risk register, feeding findings into the company's master risk register Enable sales through maturing the customer trust program Build the capability for continuous monitoring of vendor ecosystem Required Skills & Experience 8+ years in third-party/vendor risk management, security risk, or a related GRC role Demonstrated ability to independently assess vendor risk rather than relying on questionnaire responses alone, fluent in reading SOC 2 reports, ISO certificates, pen test summaries, and architecture documentation Experi

aigorust
View job →
R
Roblox
📍 San MateoFull-timeFrom $209.3K/yr
29 days ago

Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators. At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there. A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As a member of the Roblox Security Governance, Risk, and Compliance (GRC) team, you will play a key role in supporting the Security team’s mission. The GRC team is at the heart of Roblox's security organization — empowering every builder to make risk-informed decisions by establishing a portfolio of governing policies and standards, a repeatable and scalable method of assessing and quantifying risk, and a formal oversight process for GRC capabilities across Roblox. Our program takes a balanced, "right-sized" approach to security governance — combining qualitative and quantitative risk management methodologies, including Factor Analysis of Information Risk (FAIR), to assess and prioritize the security risks that matter most to Roblox. GRC partners closely with Engineering, Legal, Finance, and leadership — including providing regular reporting to the Board of Directors and the Audit & Compliance Committee — to ensure that security risk is visible, well-understood, and actioned appropriately. The team is in an exciting phase of growth and innovation. We are using engineering to drive automation across risk management, policy lifecycle management, supply chain risk, AI risk, and controls pr

awsgitai
View job →
🔔

Get new grc manager jobs by email

Daily job updates · Unsubscribe anytime