At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. As the Sr. Manager, Commercial Customer Success, East Region you will lead a team of commercial Customer Success Managers to deliver successful onboarding, healthy adoption, advocacy and retention for our commercial customers in Vanta’s rapidly expanding customer base. You will develop a high performing team of CSMs who are customer value focused and results driven. You will be responsible for influencing the design of our upmarket CS strategy, developing a repeatable methodology to guide our customers in using Vanta as the foundation of their modern GRC program. Partnering closely with Sales, Product and Account Management leaders to represent your team and customers will be key to success in this role. You will be at the forefront of delivering Vanta’s GRC value and a key leader in executing our upmarket strategy. What you’ll do as a Sr. Manager, Commercial Customer Success at Vanta: Hire, mentor and develop a team of expert CSMs and a culture of customer centricity, high performance and accountability Influence strategy and design of the customer success methodology including implementation, adoption, customer value and risk management Define strategies and coach your team to achieve KPIs including revenue retention and customer health Through coaching your team, drive adoption of effec
Jobiba hiring network
Grc Program Manager Jobs
127 active opportunities · Updated for October 2026
Fresh results
15 shown
Explore current grc program manager jobs. Use filters to narrow by work mode, employment type, experience and date posted.
Who Are We HALA is a leading fintech player in the MENAP region that aims to redefine financial services and build the future bank of SMEs. HALA aims at empowering SMEs to start, run, and grow their businesses by providing them with cutting-edge financial and technological tools. HALA currently holds multiple entities in UAE, Saudi Arabia and Egypt (including HALA Payments and HALA Logistics) and offers solutions that enable merchants to digitize their payments as well as manage their sales and operations. Founded in 2017, HALA is currently licensed by the Saudi Arabian Central Bank. Responsibilities Governance & Strategy: Develop, implement, and continuously improve the organization's Information Security Governance framework, policies, standards, and procedures. Lead the creation and execution of the Cyber Security Strategy in alignment with the company's overall business goals. Providing regular reports to the Board of Directors and executive management on the state of cybersecurity. Establish and manage a security metrics and Key Performance Indicator (KPI) program to measure the effectiveness of the security program and report on progress. Oversee the information security budget, ensuring resources are allocated effectively to manage risk. Risk Management: Design and manage a comprehensive enterprise-wide Cyber Security Risk Management program. Conduct regular risk assessments, including Business Impact Analysis (BIA), to identify, analyze, and evaluate information security risks. Facilitate risk treatment planning with business and technology owners, ensuring appropriate mitigation, acceptance, or transfer strategies are implemented. Manage the vendor risk management program, assessing the security posture of
ABOUT BASETEN Baseten powers mission-critical inference for the world's most dynamic AI companies, like Cursor, Notion, OpenEvidence, Abridge, Clay, Gamma and Writer. By uniting applied AI research, flexible infrastructure, and seamless developer tooling, we enable companies operating at the frontier of AI to bring cutting-edge models into production. We're growing quickly and recently raised our $1.5B Series F , led by Altimeter Capital, Conviction Partners, and Spark Capital. Join us and help build the platform engineers turn to to ship AI products. THE ROLE We are seeking an experienced and detail-oriented GRC (Governance, Risk, and Compliance) Manager to build, support, and continuously enhance Baseten’s security governance, compliance, and privacy programs. As one of the early members of our security organization, you will play a key role in ensuring our platform meets and exceeds the highest standards for privacy, trust, and regulatory compliance. In this role, you’ll work cross-functionally with engineering, operations, legal, and leadership teams to develop policies, manage audits, and implement controls aligned with frameworks such as SOC 2, ISO 27001, ISO 27701, and FedRAMP. You’ll be instrumental in building scalable processes to manage risk, support customer assurance, and uphold Baseten’s commitment to security and compliance as we grow. RESPONSIBILITIES Governance & Policy Development: Design, implement, and maintain security governance frameworks, policies, and procedures that align with Baseten’s risk posture and industry best practices. Risk Management: Build and manage the company-wide risk assessment program, identifying, tracking, and mitigating key security and compliance risks. Compliance Operations: Lead efforts to achieve and maintain compliance with SOC 2, ISO 27001/27701, HIPAA, FedRAMP and other applicable standards and regulations. Audit & Certification Management: Coordinate external audits and certification processes, ensuring e
The Assurance, Risk and Compliance (ARC) Initiatives team at MongoDB owns the governance and delivery of key cross-functional security risk and compliance initiatives. The team designs and executes programs that support compliance audits, risk assessments, common control frameworks, operating cadences, and executive reporting that strengthen the organization’s assurance, risk management and compliance objectives. The policy and controls governance pillar is responsible for the structure, standards and operating mechanisms that keep MongoDB’s security policies, standards, procedures, and controls governance processes current, aligned, auditable and scalable across the organization. This includes ownership of the policy lifecycle, common controls framework governance, issue management, and the review cadences and cross-functional coordination needed to maintain strong governance maturity and audit readiness. This role sits under the Assurance, Risk and Compliance function within the Global Security Office and reports to the Director of ARC Initiatives. This role will be based remotely in the United States Responsibilities: Scope of Ownership Policy governance program ownership, including policy lifecycle management, documentation standards, review and approval cadences, change tracking, and exception governance Controls governance ownership, including common controls framework lifecycle management, control harmonization, framework mapping, and processes that support audit readiness and scalable control oversight Governance over supporting systems and workflows, including Jira, GRC tooling, documentation repositories, and reporting structures, that enable consistent execution and visibility Issue management and remediation governance, including intake, triage, tracking, and reporting for timely closure of findings Executive-ready reporting and metrics for policy health, controls maturity, policy exceptions and broader program effectiveness Program Leadership Own
Figma is growing our team of passionate creatives and builders on a mission to make design accessible to all. Figma’s platform helps teams bring ideas to life—whether you're brainstorming, creating a prototype, translating designs into code, or iterating with AI. From idea to product, Figma empowers teams to streamline workflows, move faster, and work together in real time from anywhere in the world. If you're excited to shape the future of design and collaboration, join us! Figma's Security team is growing, and we're looking for a Security Operations Manager to lead the strategy and execution of our security operations program. In this role, you'll build and scale the systems, processes, and tooling that help protect Figma and our community. You'll partner closely with Security Engineering, Platform Security, IT, GRC, and Legal to strengthen our detection and response capabilities, improve operational resilience, and help shape the future of our DART and SOC functions. This is a full time role that can be held from one of our US hubs or remotely in the United States. What you'll do at Figma: Own Figma's security monitoring and incident response program, from detection engineering through post-incident review and continuous improvement Build and automate security operations workflows, including alert triage, enrichment, investigation, and response actions using SOAR and custom tooling Develop and maintain incident response run books, escalation procedures, and communication plans for security events of varying severity Lead incident response preparedness initiatives, including tabletop exercises, red team engagements, and response capability assessments Improve the effectiveness of our SIEM and SOAR platforms by reducing noise, increasing signal fidelity, and closing detection coverage gaps Build and operationalize threat intelligence capabilities to identify adversary behaviors, prioritize investments, and strengthen detection and response programs Partner wi
At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. This is not a back-office compliance role and it is not a generic sales-engineering role. You will operate as a named member of deal teams under our pod model: paired with Strategic and Enterprise Account Executives, embedded in their weekly cadences, engaged from first discovery through POC, onsite, close, and expansion. You will be the practitioner in the room that a buyer's CISO or GRC lead trusts — and the internal expert our AEs, SEs, and marketing team build around. What you’ll do as a Subject Matter Expert at Vanta: Serve as the dedicated GRC SME for a book of Strategic/Enterprise Account Executives: join discovery and qualification calls at the earliest deal stages, scope compliance programs against Vanta's platform, and support demos, POCs, workshops, and customer onsites across Compliance, Third-Party Risk Management, Risk Management, and Trust/Questionnaire Automation. Advise prospects on program architecture: multi-framework strategy, shared controls, business-unit and workspace scoping, custom frameworks, and audit sequencing. Answer field questions through our SME channels at customer-forwardable quality — including reviewing and validating AI-agent-generated answers before they reach customers. Our team runs AI-first: you'll use agents daily, act as the quality gate on their output, and (ideally) build tooling of your own. Design and deliver enablement: live sessions for GTM teams, bootcamp scenarios and mock-customer roleplay, async curriculum modules, and review of GRC marketing and SEO content. Own monthly alignment cadences with sales front-line managers; feed structured product feedback to our Product and PM
At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. This is not a back-office compliance role and it is not a generic sales-engineering role. You will operate as a named member of deal teams under our pod model: paired with Strategic and Enterprise Account Executives, embedded in their weekly cadences, engaged from first discovery through POC, onsite, close, and expansion. You will be the practitioner in the room that a buyer's CISO or GRC lead trusts — and the internal expert our AEs, SEs, and marketing team build around. What you’ll do as a Subject Matter Expert, GTM at Vanta: Serve as the dedicated GRC SME for a book of Strategic/Enterprise Account Executives: join discovery and qualification calls at the earliest deal stages, scope compliance programs against Vanta's platform, and support demos, POCs, workshops, and customer onsites across Compliance, Third-Party Risk Management, Risk Management, and Trust/Questionnaire Automation. Advise prospects on program architecture: multi-framework strategy, shared controls, business-unit and workspace scoping, custom frameworks, and audit sequencing. Answer field questions through our SME channels at customer-forwardable quality — including reviewing and validating AI-agent-generated answers before they reach customers. Our team runs AI-first: you'll use agents daily, act as the quality gate on their output, and (ideally) build tooling of your own. Design and deliver enablement: live sessions for GTM teams, bootcamp scenarios and mock-customer roleplay, async curriculum modules, and review of GRC marketing and SEO content. Own monthly alignment cadences with sales front-line managers; feed structured product feedback to our Product a
Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators. At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there. A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As a Senior Privacy Engineer on the Security and Privacy GRC team, you will shepherd and grow Roblox's Privacy Review Program, the technical and process backbone that ensures privacy is engineered into every product before it ships. You will join the Security and Privacy GRC team, reporting to the Sr Engineering Manager for Privacy Governance and Operations. This is a hands-on privacy engineering role: you'll set standards for privacy-enhancing technologies, act as the go-to SME for policy-as-code, and partner closely with Product teams, Trust & Safety, Legal, and Regulatory Compliance as part of Roblox's broader cross-functional privacy program. You will: Shepherd and evolve the Privacy Review Program, designing consistent intake workflows, evaluation criteria, and documentation to systematically assess privacy risk across new products, features, and infrastructure changes. Develop standards and guidelines that enable product teams to adopt privacy-enhancing technologies (PETs) such as differential privacy, k-anonymity, data minimization, and secure computation, with clear guidance on trade-offs and implementation patterns. Act as the Privacy SME for policy-as-code, translating privacy
At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. As Vanta expands upmarket, we have a unique opportunity to redefine how security and compliance programs are operated, while giving customers the flexibility to run their programs their way, especially in an AI-powered world. GRC Platform is a new team at the center of this effort, building the foundational capabilities that enable mid-market and enterprise customers to operate their GRC programs efficiently and at scale with Vanta. As the Senior Product Manager for GRC Platform, you will own core platform capabilities and primitives that customers rely on every day and that power critical GRC workflows—such as search, imports, exports, custom fields, and approval workflows. You will evolve these capabilities into more intelligent, agentic experiences that are increasingly flexible, automated, and adaptive, helping customers save time, reduce cognitive load, and focus on higher-value work. What you’ll do as a Senior Product Manager, GRC Platform at Vanta: Own the GRC Platform strategy and roadmap, delivering platform primitives and customer facing features leveraged across Vanta’s GRC product Distill complex problems and opportunities into clearly prioritized product goals, focus for your team, and high-quality execution in collaboration with stakeholders across the company. Partner closely with teams across GRC to develop a deep understanding of customer needs, identify opportunities for platform leverage, and translate those insights into intuitive, agentic experiences that solve critical user needs. Drive AI-first product redesigns, including defining model evaluation criteria and managing the transition from legacy experien
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the role Replit is the agentic software creation platform that enables anyone to build applications using natural language. As we scale to support millions of developers and enterprise organizations, maintaining a robust, transparent, and technically sound Governance, Risk, and Compliance (GRC) program is critical. We are looking for a GRC Engineer to serve as a key technical contributor for our compliance and risk management ecosystem. You will architect the systems and processes that automate trust, partnering deeply across the organization. We need a pragmatic operator who understands that GRC exists to enable the business—balancing rigorous standards with the velocity of a high-growth startup. What You'll Do Technical Excellence & Architecture Technical Depth: Act as a technical subject matter expert for the GRC team. You will drive quality, technical depth, and operational efficiency in our security controls. Program Architecture: Own the technical vision for Replit’s GRC program, moving the team from manual workflows toward "Compliance-as-Code" and automated evidence collection. Thought Leadership: Champion a culture of security and privacy across the company, educating teams on why controls exist rather than just enforcing them. Cross-Functional Collaboration Engineering & Architecture: Partner with Architects and Engineering Leads to "bake in" compliance requirements early in the design phase. You will translate complex technical implementations into narratives that satisfy frameworks without slowing down development. Legal & Privacy: Work closely with Legal Counsel to interpret and implement requirements for Privacy (GDPR, CCPA) and emerging AI-specific regulations (e.g., EU AI Act). Sales &a
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the role: Replit’s ecosystem is powered by an expanding array of external services and essential AI model partners. As our lead for Security Vendor Risk & Contract Reviews, you will architect and execute a risk management program focused on substantive evaluation rather than just processing checklists. You’ll analyze SOC 2 documentation, security assessments, and system architectures to determine actual risk profiles, collaborating with our Legal team to secure necessary contractual protections. This role reports to the Head of Security GRC and involves high-impact partnerships across Legal, Engineering, and Product teams. What You'll Do Run substantive third-party risk management (TPRM), independently evaluating real risk, not just processing questionnaire responses Review SOC 2 reports, pen test findings, and architecture documentation to form an independent view of vendor risk, extending the same rigor to AI/model providers Partner with Legal on vendor and AI contract terms, including DPAs, subprocessor agreements, and AI-specific provisions Review contracts for non-standard security language when flagged by Legal or deal desk, and recommend redlines Maintain the vendor and AI/model risk register, feeding findings into the company's master risk register Enable sales through maturing the customer trust program Build the capability for continuous monitoring of vendor ecosystem Required Skills & Experience 8+ years in third-party/vendor risk management, security risk, or a related GRC role Demonstrated ability to independently assess vendor risk rather than relying on questionnaire responses alone, fluent in reading SOC 2 reports, ISO certificates, pen test summaries, and architecture documentation Experi
As the Engineering Manager for Commercial Audit, you will lead a high-performing team responsible for scaling Datadog’s security and compliance posture through automation, tooling, and engineering excellence. Our GRC (Governance, Risk, and Compliance) function is a critical partner to the broader Security and Engineering organizations, ensuring that Datadog not only meets rigorous global regulatory standards but does so in a way that is efficient, scalable, and integrated into our cloud-native infrastructure. You will manage a team of engineers and analysts who are transitioning to a GRC engineering direction to treat compliance as a software problem, leveraging AI, custom tooling, CI/CD pipelines, and cloud-native services to turn complex regulatory requirements into actionable, automated controls. You will lead the strategy, roadmap, and execution of Datadog’s Commercial Audit initiatives. This is a high-impact leadership role where you will grow a team of engineers and analysts responsible for directly maintaining our compliance programs and related audits (e.g., SOC2, PCI, HIPAA, ISO) while looking to improve efficiency and effectiveness through platforms and tooling. You will act as a bridge between technical engineering, legal, and compliance, enabling the organization to move fast while maintaining a secure and compliant environment. You will champion a culture of "compliance-as-code," identifying opportunities to automate evidence collection, streamline control testing, and reduce manual toil for both your team and our partner engineering teams. At Datadog, we place value in our office culture - the relationships and collaboration it builds, and the creativity it brings to the table. We operate as a hybrid workplace to ensure our Datadogs can create a work-life harmony that best fits them. What You’ll Do: Lead the strategy, roadmap, and execution of Datadog’s commercial security compliance efforts, shifting from manual audit processes to automated, scalable
At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. Vanta for Government (V4G) is how we bring that mission to the public sector. As federal compliance undergoes its biggest shift in a decade — FedRAMP 20x, machine-readable authorization, OSCAL — we're building the platform that turns federal frameworks into automated, continuously monitored product experiences. The GRC Subject Matter Experts on this team are the people who make that possible. As Vanta's GRC Subject Matter Expert for V4G , you'll own federal compliance content used by every customer pursuing or maintaining federal authorization on our platform. This is an interpretation-and-authoring role, not a compliance program administration role: your job is to interpret underlying control requirements, identify where FedRAMP modifies or constrains the NIST framework, and translate those interpretations into precise, technically testable guidance that engineering can build and customers can act on. The content you write ships as product — a five-person startup and a Fortune 100 CSP both receive it — so calibrating depth, precision, and universality is the core craft. You'll join Vanta's Security organization, which directly influences product development, facilitates the creation of automated GRC solutions for customers, and provides expert advisory services across the company. What you’ll do as a V4G GRC SME at Vanta: Build and own federal compliance frameworks — Lead the creation, enhancement, and lifecycle management of controls, evidence requirements, and implementation guidance for FedRAMP (Low/Moderate/High), NIST SP 800-53, NIST SP 800-171, CMMC, DFARS, and StateRAMP. Author clear control rationales, acceptance crite
We believe that the way people interact with their finances will drastically improve in the next few years. We’re dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid’s network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam. Team: The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s security organization, focused on enabling the business by proactively managing information security risks and maintaining effective controls. Our mission is to reduce the likelihood and impact of security risks while operating a robust assurance program that builds trust with our customers, consumers, and data partners.We partner closely across the company to ensure Plaid’s platform remains secure, resilient, and aligned with industry and regulatory expectations. Third-party ecosystem risk is a core part of how we keep Plaid safe—we vet the security of both the vendors we rely on and the customers and partners who connect to our platform, so trust runs in both directions. Role: You will run security risk assessments for Plaid’s third parties end-to-end—from intake and questionnaire through risk rating, findings, and tracked exceptions. You will assess the security posture of customers and partners onboarding to the platform with the same rigor we apply to vendors. You will keep the third-party risk lifecycle moving—risk tiering, reassessment cadence, remediation follow-through, and a clean, current risk register. You
Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators. At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there. A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As a member of the Roblox Security Governance, Risk, and Compliance (GRC) team, you will play a key role in supporting the Security team’s mission. The GRC team is at the heart of Roblox's security organization — empowering every builder to make risk-informed decisions by establishing a portfolio of governing policies and standards, a repeatable and scalable method of assessing and quantifying risk, and a formal oversight process for GRC capabilities across Roblox. Our program takes a balanced, "right-sized" approach to security governance — combining qualitative and quantitative risk management methodologies, including Factor Analysis of Information Risk (FAIR), to assess and prioritize the security risks that matter most to Roblox. GRC partners closely with Engineering, Legal, Finance, and leadership — including providing regular reporting to the Board of Directors and the Audit & Compliance Committee — to ensure that security risk is visible, well-understood, and actioned appropriately. The team is in an exciting phase of growth and innovation. We are using engineering to drive automation across risk management, policy lifecycle management, supply chain risk, AI risk, and controls pr
Get new grc program manager jobs by email
Daily job updates · Unsubscribe anytime