Jobiba hiring network

Grc Program Manager Jobs

127 active opportunities · Updated for October 2026

Fresh results

14 shown

Explore current grc program manager jobs. Use filters to narrow by work mode, employment type, experience and date posted.

O
OpenAI
📍 San Francisco• Full-time• Remote
1mo ago

About the Team Governance, Risk, and Compliance (GRC) is foundational to Security delivering mission outcomes at OpenAI. The GRC team provides security assurances and builds compliance for OpenAI’s technology, people, and products. We are technical in what we build but operational in how we do our work, and we partner deeply with Product, Security, Legal, Privacy, GTM, and Field Security to help OpenAI move quickly while maintaining trust with customers, auditors, regulators, and the public. About the Role We are looking for an experienced Product Lifecycle Assurance IC to help scale OpenAI’s GRC function across our product stack to ensure products address customer and regulatory compliance requirements at launch and regressions are detected promptly and corrected. You will partner closely with Product, Security, Legal, and Privacy teams to make sure OpenAI can move quickly while maintaining our security, privacy and compliance claims and giving customers, auditors, and regulators assurance about how OpenAI handles user data. You are responsible for product assurance end-to-end from inception to post-launch (continuous) monitoring. You leverage existing workflows, reviews, and data and enhance, augment and build the components needed to create an end-to-end product assurance program. This role is not about supporting SOC or ISO audits; it's a highly cross-functional and deeply technical operations role to ensure that OAI products meet the compliance bar at launch, regressions are prevented and detected, and our compliance state can be evidenced. This role also helps ensure that our product launch governance program operates effectively across key safety, privacy, legal and security stakeholders and lessons-learned from incidents and regressions are used to improve the program. You or in partnership with engineering teams, build key controls in our infrastructure stack, developer workflows and launch tooling to provide developers with guardrails, perform CI/CD confor

REMOTEawskubernetesci/cd
View job →
PE
Private Employer
📍 New York• Full-time• Hybrid
1mo ago

A World-Changing Company Palantir builds the world’s leading software for data-driven decisions and operations. By bringing the right data to the people who need it, our platforms empower our partners to develop lifesaving drugs, forecast supply chain disruptions, locate missing children, and more. The Role As a GRC Program Manager, you are the engine behind Palantir's Governance, Risk, and Compliance programs. You partner with compliance engineers, security teams, and developers to design and scale the processes that keep our Commercial, International, and US Government businesses operating at the highest regulatory standards. You track and stabilize projects, remove roadblocks, and anticipate stakeholder needs to free up our specialists to focus on the problems they are best equipped to solve.

PE
Private Employer
📍 Seattle• Full-time• Hybrid
1mo ago

A World-Changing Company Palantir builds the world’s leading software for data-driven decisions and operations. By bringing the right data to the people who need it, our platforms empower our partners to develop lifesaving drugs, forecast supply chain disruptions, locate missing children, and more. The Role As a GRC Program Manager, you are the engine behind Palantir's Governance, Risk, and Compliance programs. You partner with compliance engineers, security teams, and developers to design and scale the processes that keep our Commercial, International, and US Government businesses operating at the highest regulatory standards. You track and stabilize projects, remove roadblocks, and anticipate stakeholder needs to free up our specialists to focus on the problems they are best equipped to solve.

PE
Private Employer
📍 Washington• Full-time• Hybrid
1mo ago

A World-Changing Company Palantir builds the world’s leading software for data-driven decisions and operations. By bringing the right data to the people who need it, our platforms empower our partners to develop lifesaving drugs, forecast supply chain disruptions, locate missing children, and more. The Role As a GRC Program Manager, you are the engine behind Palantir's Governance, Risk, and Compliance programs. You partner with compliance engineers, security teams, and developers to design and scale the processes that keep our Commercial, International, and US Government businesses operating at the highest regulatory standards. You track and stabilize projects, remove roadblocks, and anticipate stakeholder needs to free up our specialists to focus on the problems they are best equipped to solve.

About the Team OpenAI’s Governance, Risk, and Compliance team helps ensure security and privacy are grounded in how our products and systems actually operate. Assurance Operations partners with Security, Engineering, Infrastructure, Product, Privacy, and Legal to make controls provable, risk decisions explicit, and audit readiness a result of well-designed systems. About the Role We are hiring a technical, product-minded GRC builder who can own consequential audits while improving the control and evidence systems behind them. You will build a reusable common control framework, use Codex to automate assurance work, validate changing system scope, and turn repeated audit friction into measurable improvements. We are looking for someone who questions inherited assumptions, solves novel problems creatively, works closely with engineers, and makes the next audit easier by improving the underlying system. You’ll be responsible for: Lead external, internal, customer, and certification audit work from scoping through evidence review, fieldwork, remediation, and closeout. Build a common control framework linking risk, control intent, implementation, owner, system, environment, evidence, and applicable frameworks. Validate actual scope and ownership instead of assuming last year's controls, product boundaries, or evidence remain accurate. Use Codex to build and test evidence checks, control mappings, request triage, owner workflows, monitoring, and remediation reporting. Partner with engineers on cloud architecture, identity, logging, data flows, software changes, vulnerabilities, and control effectiveness. Design maintainable, permission-aware tools that preserve source provenance, human review, and evidence integrity. Reduce repeated requests and operational burden for control owners through measurable workflow improvements. Define roadmaps, decision rights, milestones, success metrics, and clear cross-functional escalations. We’re looking for someone with: Direct ownership

sqlawsrest
View job →
O
1mo ago

About the Team Governance, Risk, and Compliance (GRC) is foundational to Security delivering mission outcomes at OpenAI. We’re excited about building creative solutions to ambiguous security requirements and delivering new technologies to mission critical customers. The GRC team provides security and engineering expertise to ensure our customers’ most critical and stringent requirements are met. We are technical in what we build but are operational in how we do our work, and are committed to obtaining, expanding, and maintaining Authorizations to Operate (ATOs) for critical systems while fostering a collaborative and execution-driven culture. About the Role Our technologies support some of the most important and impactful work in the world, including our strategic and high-impact customers in the public sector. As a GRC Program Manager, you’ll play a pivotal role in achieving US government (USG) ATOs and compliance frameworks, including but not limited to FedRAMP and Department of War (DoW),for OpenAI products and support agency-specific ATOs for systems deployed in highly regulated and secure environments. You’ll work closely with engineers, internal stakeholders, and external assessors to design, document, and implement security controls that meet stringent compliance requirements. Your creativity and execution-focused approach will be critical in navigating complex challenges while maintaining the trust of our stakeholders. We’re looking for people who bring: Proven experience in obtaining and maintaining a FedRAMP ATO and agency specific ATOs in highly restricted environments, within government or regulated sectors. A deep understanding of USG security frameworks and policies (e.g., NIST, RMF, FedRAMP). Ability to communicate technical concepts to diverse audiences, including engineers and non-technical stakeholders. Exceptional technical program management skills, with the ability to multitask and deliver large complex programs under pressure. This role is base

awsazurekubernetes
View job →
S
Stripe
📍 Remote• Full-time• Remote
1mo ago

Who we are About Stripe Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world's largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career. About the team The Stripe Security team is dedicated to improving the security of Stripe and its users. Our users trust us with some of their most sensitive information, and we make security a first-class consideration in everything we do. Security concerns are ever-evolving, creating an extremely dynamic environment for the Security team. The Security Governance, Risk, and Compliance (SGRC) team at Stripe provides security governance, risk management, and compliance capabilities to allow Stripe to make strategic security decisions, measure our risk and control posture, and represent Stripe Security to internal and external entities. The successful operation of our organization accelerates Stripe by optimizing the communication and expectations of our security program. What you’ll do We're looking for a Security GRC Program Manager with deep expertise in security compliance to serve as the primary interface between Stripe's Security organization and external auditors, regulators, and compliance stakeholders. In this role, you'll represent the Security team in audit engagements, articulate how Stripe's security controls are designed and how they operate, and ensure that compliance obligations across a complex global regulatory landscape are met with consistency and rigor. In this role, you will act as a proxy between external entities like regulators and auditors, and our internal security teams, ensuring consistency in compliance responses and helping main

REMOTEaigorust
View job →
SA
Scale AI
📍 San Francisco• Full-time• From $164.8K/yr
14 days ago

At Scale, we are driving the future of AI and Machine Learning across a variety of industries. As the Program Manager for Compliance, you will play a pivotal role in the continued success of Scale. Your role will be instrumental in ensuring the effective operation of our Compliance department and our GRC function, allowing us to maintain the highest standards in our industry. Reporting to the Director & Associate General Counsel, Compliance, you will be a dedicated program manager for Scale's enterprise compliance program and the person who turns policy into practice across anti-bribery and anti-corruption, gifts and entertainment, conflicts of interest, third-party risk and sanctions, policy lifecycle, and company-wide training. This is a hands-on builder, not a maintenance role. You will support Commercial, Public Sector, and international business lines, working closely with Legal, Procurement, Finance, Security, and go-to-market teams. You will: Help build, design, improve, and streamline Scale's core compliance programs, including anti-bribery and anti-corruption (ABAC), gifts and entertainment, conflicts of interest, and third-party risk and sanctions screening. Collaborate with stakeholders across the company to improve compliance policies, processes, and procedures. Monitor regulatory developments relevant to Scale's business, translate them into concrete policy and process changes, and track compliance obligations flowing out of customer contracts. Partner with leadership to build, mature, and operationalize the company's enterprise risk management (ERM) framework, identifying and assessing key business risks. Build the reporting layer: metrics and periodic reporting that give Legal & GRC leadership a defensible picture of program health. Flex into audit and assurance work during peak certification periods, and own inbound customer and investor compliance diligence questionnaires. Ideally you'd have: 5+ years building or operating ethics and c

awsrestmachine learning
View job →
F
Figma
📍 Ca New York• Full-time• From $169K/yr
1mo ago

Figma is growing our team of passionate creatives and builders on a mission to make design accessible to all. Figma’s platform helps teams bring ideas to life—whether you're brainstorming, creating a prototype, translating designs into code, or iterating with AI. From idea to product, Figma empowers teams to streamline workflows, move faster, and work together in real time from anywhere in the world. If you're excited to shape the future of design and collaboration, join us! Figma's Information Security team is growing and looking for a Strategic Program Manager to drive strategic initiatives and engagement across the organization. This is a fast-moving role that will help build and mature security practices and partnerships across the organization, working closely with GRC, Security Operations, Security Engineering, Internal Audit, Legal, People, Product, Sales, and business teams as a trusted security partner. You will work closely with security leadership to design programs, manage portfolios, and drive results that scale with our growing business. If you thrive on taking initiative, finding clarity in ambiguity, and driving impactful programs and relationships, we'd love to hear from you! This is a full time role that can be held from one of our US hubs or remotely in the United States. What you'll do at Figma: Lead strategic security programs from planning through execution, coordinating priorities, dependencies, risks, and accountability across security and business teams Partner with teams across Figma to identify and address security risks, align stakeholders, and translate security priorities into practical guidance and action plans Define and track security program metrics, OKRs, risk registers, and reporting that give leadership visibility into program health, priorities, and risk posture Identify and coordinate the remediation of security gaps by partnering with control owners, security specialists, and business stakeholders to drive issues to reso

O
OpenAI
📍 San Francisco• Full-time• Remote
20 days ago

About the Team OpenAI’s Legal team helps advance our mission by tackling novel legal issues in AI. Our team brings together professionals across technology, privacy, intellectual property, corporate, employment, tax, regulatory, and litigation. Our regulatory compliance work turns legal requirements into practical programs that support responsible AI development and deployment. About the Role As a Legal Program Manager focused on regulatory compliance, you will build and manage cross-functional programs that translate counsel’s guidance into practical, sustainable operations. Your initial focus may include content moderation and/or frontier AI governance, with the mix shaped by team priorities and your strengths. You will partner with internal and external counsel, other legal program managers, and technical and business teams to coordinate implementation, evidence collection, reporting, and ongoing compliance. You’ll build repeatable systems that scale across regulations, products, and jurisdictions, helping teams navigate emerging requirements with clarity and sound judgment. This full-time role is based in San Francisco, CA, or New York, NY. In this role, you will: Lead regulatory compliance programs end to end: define scope, owners, milestones, dependencies, risks, and escalation paths, and drive execution with counsel and cross-functional partners. Translate counsel’s regulatory guidance into repeatable workflows, controls, and documentation. Depending on your portfolio, this may include content moderation disclosures, transparency reporting, reporting and appeals workflows, or frontier AI model launch readiness, evaluation and risk-management evidence, and incident reporting. Build strong partnerships across Product, Engineering, User Operations, Governance, Risk and Compliance (GRC), Global Affairs, Communications, and Go-to-Market to align program priorities and deliverables. Support regulatory inquiries, audits and investigations with counsel, organizing ev

REMOTEsqlawsrest
View job →
V
Vanta
📍 United States• Full-time
1mo ago

At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. As an Engineering Manager leading our Reporting team, you will lead a newly structured team focused on a critical product area within GRC Program Orchestration. This role represents an exciting opportunity to shape the future of how Vanta customers understand, visualize, and operationalize their compliance and security programs. This team is focused on evolving Vanta’s reporting platform beyond dashboards into a scalable, AI-powered reporting experience. The team owns core initiatives across enterprise reporting, historical analytics, AI-assisted insights, and certified data infrastructure powering in-product experiences. This role sits at the intersection of data products, enterprise scalability, and product innovation. As reporting becomes increasingly foundational to enterprise growth, customer retention, and Vanta’s long-term AI strategy, this role will play a key role in shaping engineering execution, cross-functional alignment, and the long-term technical direction of one of Vanta’s critical product investments. Visit our Vanta Engineering Blog to learn more about what our team is working on! What you’ll do as an Engineering Manager at Vanta: Build and scale a high-performing team: lead, coach, and grow the team while hiring strategically, identifying operational gaps, and raising the engineering bar Drive execution across strategic initiatives: Deliver against a multi-quarter roadmap spanning reporting infrastructure, enterprise reporting capabilities, AI-powered insights, and scalable data foundations Shape technical and product strategy: Partner closely with Product and cross-functional engineering teams to define the

restairust
View job →
V
Vanta
📍 Toronto• Full-time
1mo ago

At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. As an Engineering Manager leading our Reporting team, you will lead a newly structured team focused on a critical product area within GRC Program Orchestration. This role represents an exciting opportunity to shape the future of how Vanta customers understand, visualize, and operationalize their compliance and security programs. This team is focused on evolving Vanta’s reporting platform beyond dashboards into a scalable, AI-powered reporting experience. The team owns core initiatives across enterprise reporting, historical analytics, AI-assisted insights, and certified data infrastructure powering in-product experiences. This role sits at the intersection of data products, enterprise scalability, and product innovation. As reporting becomes increasingly foundational to enterprise growth, customer retention, and Vanta’s long-term AI strategy, this role will play a key role in shaping engineering execution, cross-functional alignment, and the long-term technical direction of one of Vanta’s critical product investments. Visit our Vanta Engineering Blog to learn more about what our team is working on! What you’ll do as an Engineering Manager at Vanta: Build and scale a high-performing team: lead, coach, and grow the team while hiring strategically, identifying operational gaps, and raising the engineering bar Drive execution across strategic initiatives: Deliver against a multi-quarter roadmap spanning reporting infrastructure, enterprise reporting capabilities, AI-powered insights, and scalable data foundations Shape technical and product strategy: Partner closely with Product and cross-functional engineering teams to define the

restairust
View job →
V
Vanta
📍 United States• Full-time
1mo ago

At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. As Vanta's Customer Success Manager, Strategic, you will serve as a trusted advisor to Vanta's largest and most complex customers—organizations with 10,000+ employees navigating sophisticated security and compliance landscapes. Unlike traditional CSM roles managing 20-30 accounts, you'll own a focused book of 5-10 strategic accounts, driving deep customer relationships, multi-quarter projects, and high-impact business outcomes. The Strategic CS team plays a defining role in proving Vanta can serve the enterprise at scale. You'll partner closely with Strategic Account Executives and Account Managers to execute land and expand strategies, manage complex implementations, and guide executive stakeholders through their GRC program maturity journeys. Your work will directly influence Vanta's upmarket growth, product roadmap, and strategic positioning in the market. What you’ll do as a Customer Success Manager, Strategic at Vanta: Serve as the primary trusted advisor for 5-10 of Vanta's most strategic customers, each with 10,000+ employees and highly complex organizational structures Lead enterprise-scale implementations, configurations, and optimizations of Vanta's Trust Management Platform across multi-business-unit, multi-geography organizations Build and maintain deep, multi-threaded executive relationships with CISOs, CIOs, Chief Compliance Officers, and other C-level stakeholders Partner closely with Strategic Account Executives and Account Managers to identify expansion opportunities, develop account growth strategies, and execute on land and expand motions Manage complex, multi-quarter projects that require coordination across

restaigo
View job →
D
Discord
📍 San Francisco Bay Area• Full-time• From $180K/yr
1mo ago

Discord has a highly engaged community of millions of daily active users who use the platform for many different reasons, but there’s one thing that nearly everyone does: play video games. Discord plays a uniquely important role in the future of gaming, and we are focused on making it easier and more fun for people to hang out before, during, and after playing games. Discord's Internal Audit team exists to demonstrate effective risk management, process optimization, and adherence to relevant regulations — through a mix of independent assurance and advisory work that helps teams strengthen our overall control environment. This Technology Risk Audit Manager role owns the technical side of that mission — IT SOX/ITGC, system controls, and domains centered around consumer trust — that protect hundreds of millions of our users worldwide. You'll have the opportunity to help build our internal audit function from the ground up: shaping the frameworks and processes with an AI-native approach from day one, rather than bolting AI on after the fact. Your first few months will focus on learning Discord's financial-reporting systems landscape, understanding the company's GRC program structure, and evaluating AI-powered testing solutions — setting the foundation for a function that's built to scale as Discord grows toward enterprise readiness. This person will report to the Vice President of Internal Audit. What You'll Be Doing Lead IT SOX/ITGC strategy and continuous improvement across financial-reporting-relevant systems Extend risk and controls assessment and assurance into consumer trust domains such as privacy, security, and trust & safety Partner with the Engineering organization to ensure proper access controls, segregation of duties, change management, and CI/CD integrity are in place Guide control design through system implementations, migrations, and platform changes Manage teams and projects related to IT controls and technical audits, including external contractors

ci/cdrestai
View job →
🔔

Get new grc program manager jobs by email

Daily job updates · Unsubscribe anytime