We're looking for a Communications Specialist with a uniquely hybrid role combining media relations support, executive thought leadership program development, project management, and communications operations for the marketing team. This role supports how executives communicate externally - whether through press, speaking or social media - and internally, with CMO internal communications and content development. With a unique set of responsibilities supporting executive comms, internal communications for the CMO and planning for the marketing team, this role is key in how the marketing organization stays aligned, prioritized and running efficiently day to day. Straddling both the comms team and the office of the CMO, you will seek opportunities that carry the Diligent executives’ voices while also helping run the operating rhythm of the marketing team itself. You would be joining Diligent at an exciting moment in the company’s history, as they unleash their new AI-powered GRC platform to help General Counsels, Chief Compliance Officers, Audit and Risk Leaders. This is the result of nearly three years of intense development of agentic workflows inside the Diligent platform, as well as MCP/plug-in access to Diligent offerings - providing a robust, differentiated experience for clients who need solutions that accelerate and action critical business objectives, not just static reporting. This is a high-visibility role for someone who wants exposure to media relations, executive communications and marketing team operations at once. You'll work closely with the CMO, the executive team, the broader marketing leadership team, corporate communications, and the People team to make sure the right message reaches the right audience — and marketing leadership stays focused on what matters most with internal and external alignment on strategic priorities. What You'll Do Executive Thoug
Jobiba hiring network
Grc Program Manager Jobs
127 active opportunities · Updated for October 2026
Fresh results
15 shown
Explore current grc program manager jobs. Use filters to narrow by work mode, employment type, experience and date posted.
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the role: Replit is building the security GRC function that will scale with an AI-native product. As the Risk & Compliance lead, you'll own our certification and audit program end to end: SOC 2, ISO 27001, and eventually ISO 42001 (AI management systems), while also owning the company's master security risk register and continuous compliance monitoring. You'll report to the Head of Security GRC, who retains overall accountability for the risk program, and work closely with Engineering to make sure controls hold up in practice, not just on paper. What You'll Do Own the end-to-end certification roadmap (SOC 2 Type II, ISO 27001, and future frameworks like ISO 42001) including scoping, gap assessments, remediation, and audit execution Manage relationships with external auditors and drive the annual audit calendar so certifications renew without last-minute scrambles Own and maintain the company's master security risk register including risk identification, scoring methodology, treatment plans, and residual risk reporting Build and maintain continuous compliance monitoring so control status reflects real-time state rather than point-in-time snapshots Own the core audit artifacts that back every certification including ISMS documentation, Statements of Applicability, risk assessments, and potentially FedRAMP System Security Plans (SSPs) Run regular audits and readiness assessments, and track remediation of findings and control gaps to closure Support GDPR and broader privacy compliance alongside the Legal/Privacy team, without owning the legal interpretation of requirements Partner with the GRC Engineer to define what evidence collection and control monitoring should be automated versus manually reviewed Track and
Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence. This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk. Position Overview: We are seeking a visionary Senior Director, Governance, Risk and Compliance (GRC) to lead and scale our world-class GRC Security organization. We don't view Governance, Risk, and Compliance (GRC) as a passive reporting function or an administrative checklist—we build engineering-forward, automated, and AI-driven GRC programs capable of operating in an evolving AI world. Reporting directly to Security Executive leadership, you will operate as a partner to the Senior Executives across Okta’s workforce, taking direct responsibility for cyber risk, data governance, security compliance and product certifications to enable Okta to ship world class, secure products. You will blend deep domain expertise across enterprise cyber risk, audit, and global compliance with a forward-thinking engineering mindset—pioneering continuous control monitoring, compliance-as-code, and robust AI governance for generative and agentic architectures. This is not just a leadership role. This is a builder’s role. Key Responsibilities: Drive AI-first Transformation: Execute a vision to integrate AI and agentic tools into daily GRC operations (automated evidence collection, automated risk scoring, intelligent policy mapping, and continuous audit readiness). Enterprise Risk & Governance: Operationalize Okta’s AI risk and governance framework—addressing training data protection, model risk management, responsible AI principles, and alignment with emerging
Position Overview As a Solutions Engineer at Diligent, you will partner closely with Sales to help organizations understand how our platform can transform the way they identify and mitigate risk, perform audits, strengthen controls, and operationalize broader GRC programs. You’ll independently lead the SE workstream on small to mid-sized opportunities, while partnering with more senior Solutions Engineers on complex, multi-pillar deals, acting as a trusted partner to customer stakeholders and helping translate Risk & Audit and broader GRC challenges into clear, compelling solutions that drive business value. If you enjoy combining domain expertise, storytelling, solution design, and customer interaction and are looking to build your career in a commercial, customer-facing environment, this is a strong next step. Key Responsibilities Customer & Commercial Partnership Partner with Sales to lead the full pre-sales lifecycle for small to mid-sized opportunities, helping customers understand how Diligent solves real-world risk, audit, and control management challenges. Deliver independent, well-prepared, tailored software demonstrations that clearly articulate business value, while seeking coaching and feedback from senior team members for continuous improvement. Engage confidently with stakeholders across Internal Audit, Risk, Compliance, IT, Controls, and Governance teams, owning day-to-day customer conversations and escalating to senior SEs for high-risk or complex topics as needed. Translate customer pain points into clear solution narratives, including outcomes and success criteria, to support deal progression and closure. Own the technical win for small to mid-sized opportunities, and contribute to the technical strategy on larger, multi-stakeholder deals in partnership with senior SEs. Solution Design & Thought Leadership Design and present solu
Position Overview As a Solutions Engineer at Diligent, you will partner closely with Sales to help organizations understand how our platform can transform the way they identify and mitigate risk, perform audits, strengthen controls, and operationalize broader GRC programs. You’ll independently lead the SE workstream on small to mid-sized opportunities, while partnering with more senior Solutions Engineers on complex, multi-pillar deals, acting as a trusted partner to customer stakeholders and helping translate Risk & Audit and broader GRC challenges into clear, compelling solutions that drive business value. If you enjoy combining domain expertise, storytelling, solution design, and customer interaction and are looking to build your career in a commercial, customer-facing environment, this is a strong next step. Key Responsibilities Customer & Commercial Partnership Partner with Sales to lead the full pre-sales lifecycle for small to mid-sized opportunities, helping customers understand how Diligent solves real-world risk, audit, and control management challenges. Deliver independent, well-prepared, tailored software demonstrations that clearly articulate business value, while seeking coaching and feedback from senior team members for continuous improvement. Engage confidently with stakeholders across Internal Audit, Risk, Compliance, IT, Controls, and Governance teams, owning day-to-day customer conversations and escalating to senior SEs for high-risk or complex topics as needed. Translate customer pain points into clear solution narratives, including outcomes and success criteria, to support deal progression and closure. Own the technical win for small to mid-sized opportunities, and contribute to the technical strategy on larger, multi-stakeholder deals in partnership with senior SEs. Solution Design & Thought Leadership Design and present solu
For over 20 years, Smartsheet has empowered teams to manage work seamlessly and scale solutions smarter. Now, in our most ambitious chapter yet, we are uniting human teams with AI agents. By orchestrating the work agents do best, automating manual tasks and uncovering insights at scale, we create the space for people to focus on what truly matters: judgment, creativity, and big thinking. That is magic at work, and it’s what we show up for every day. FedRAMP and GovRAMP (formerly StateRAMP) are transforming how Smartsheet serves government and regulated customers. We need a FedRAMP and GovRAMP subject matter expert to lead these programs—someone with real hands-on experience obtaining and maintaining ATO authorizations, navigating 3PAO assessments, and managing continuous monitoring requirements. In this role, you'll own Smartsheet's FedRAMP and GovRAMP certifications, manage relationships with our 3PAOs, drive annual assessment preparation, manage POA&M processes, and ensure we maintain authorizations at the highest level. You'll understand the nuances of federal compliance, speak fluently with government agencies and authorized assessors, and translate complex regulatory requirements into clear roadmaps for engineering and operations teams. You'll be the voice of federal compliance at Smartsheet and the trusted advisor to government customers on our security posture. You Will: Own FedRAMP and GovRAMP (formerly StateRAMP) certifications and roadmaps: Lead the overall strategy for obtaining and maintaining federal authorizations, including package management, compliance timelines, and authority coordination. Manage 3PAO relationships and assessments: Work with accredited third-party assessment organizations to conduct initial assessments and annual re-assessments. Coordinate scoping, evidence preparation, testing coordination, and results validation. Lead continuous monitoring (ConMon) execution: Oversee the delivery of monthly, annual, and event-driven Fed
About Pinterest: Millions of people around the world come to our platform to find creative ideas, dream about new possibilities and plan for memories that will last a lifetime. At Pinterest, we’re on a mission to bring everyone the inspiration to create a life they love, and that starts with the people behind the product. Discover a career where you ignite innovation for millions, transform passion into growth opportunities, celebrate each other’s unique experiences and embrace the flexibility to do your best work. Creating a career you love? It’s Possible. At Pinterest, AI isn't just a feature, it's a powerful partner that augments our creativity and amplifies our impact, and we’re looking for candidates who are excited to be a part of that. To get a complete picture of your experience and abilities, we’ll explore your foundational skills and how you collaborate with AI. Through our interview process, what matters most is that you can always explain your approach, showing us not just what you know, but how you think. You can read more about our AI interview philosophy and how we use AI in our recruiting process here . Pinterest’s Security team (Pinfosec) is seeking an IC14 Security Engineer - Security Governance, Risk & Compliance (GRC Senior Analyst) to support and strengthen our security governance and assurance programs. This role is ideal for someone who is detail-oriented, collaborative, and motivated by building scalable security processes that help the business manage risk effectively. Reporting to the Interim Head of Security Governance, Risk & Compliance, this individual contributor will partner closely with Security, Engineering, IT, Legal, Internal Audit, and other cross-functional stakeholders to help maintain and improve Pinterest’s security control environment. The role will contribute to core GRC activities including risk management, policy governance, control testing, audit support, awareness tracking, and internal risk assessmen
Figma is growing our team of passionate creatives and builders on a mission to make design accessible to all. Figma’s platform helps teams bring ideas to life—whether you're brainstorming, creating a prototype, translating designs into code, or iterating with AI. From idea to product, Figma empowers teams to streamline workflows, move faster, and work together in real time from anywhere in the world. If you're excited to shape the future of design and collaboration, join us! Figma's GRC team helps build and maintain trust with our users, regulators, business partners, and the organizations that rely on Figma every day. We partner across the company to strengthen security, manage risk, maintain compliance, and scale the programs that support our continued growth. We're growing our team and looking for security, risk, and compliance professionals across several disciplines. Whether your expertise is in compliance, risk management, governance, GRC tooling, or customer trust, you'll have the opportunity to build programs, improve processes, and help shape how Figma scales security and trust. Roles we hire for on this team: Compliance Management Lead compliance and certification programs across security and regulatory frameworks Manage audit cycles, partner with external assessors, and drive audit readiness initiatives Improve controls, processes, and evidence management practices across the organization <s
We believe that the way people interact with their finances will drastically improve in the next few years. We’re dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid’s network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam. The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s security organization, focused on enabling the business by proactively managing information security risks and maintaining effective controls. Our mission is to reduce the likelihood and impact of security risks while operating a robust assurance program that builds trust with our customers, consumers, and data partners. We own Plaid’s security compliance frameworks, run our audits and risk programs, and partner across the company to keep Plaid’s platform secure, resilient, and aligned with industry and regulatory expectations. GRC Engineering is how we make all of that scale — turning compliance into code, evidence into telemetry, and audits into a continuous, automated capability. The Role: You will own GRC Engineering at Plaid — a foundational, high-ownership role defining an emerging discipline from the ground up. Today most of our compliance work is manual and point-in-time; you will turn it into an engineered system that is continuous, data-driven, and scalable, and set the technical direction for the field. You will: Define the discipline and the architecture — how GRC Engineering works at Plaid, not just execute with
At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. Vanta is hiring for a Head of Design (VP) to lead our design organization — setting direction for a ~40-person team, shaping the next generation of AI-native product experiences, and building the quality systems that let great design ship at scale. The Design team at Vanta shapes how security and compliance teams experience Vanta — from a startup founder building their security program for the first time to an enterprise security team managing hundreds of controls. The org spans all areas of Vanta — GRC, Trust, Platform, Self-serve, and AI — and includes product designers, visual designers, design engineering, content designers, and a user researcher, led by experienced design directors. As AI fundamentally changes what products can do and how they get built, this team is at an inflection point: the right leader will define what it means for a design org to be genuinely AI-forward — enabling designers to move faster, ship more, and contribute to product direction and delivery in new ways. This is the right role for a design leader who leads with AI fluency, brings strong taste and craft across interaction design and visual design, and has the operational instincts to build the systems that make quality a consistent property of the whole org. What you’ll do as Head of Design at Vanta: Lead a team of ~40 designers and design directors across GRC, Trust, Platform, Self-serve, and AI — setting org-wide direction and enabling each leader to do their best work Lead the team building the next generation of agentic, AI-native product experiences — defining what great design looks like as Vanta’s products are increasingly shaped by AI E
Discord has a highly engaged community of millions of daily active users who use the platform for many different reasons, but there’s one thing that nearly everyone does: play video games. Discord plays a uniquely important role in the future of gaming, and we are focused on making it easier and more fun for people to hang out before, during, and after playing games. Discord's Legal team is growing its Security GRC function, and we're looking for a Security Analyst to help run and scale it. You'll own the day-to-day engine of the program: the questionnaires, risk tracking, analyses, tooling, and documentation that keep compliance moving. As we build, that's a mix of hands-on work today and the systems that shrink it over time, because we'd rather automate a control than babysit it. We care about the right level of compliance for Discord, our users, and our customers. You'll partner across Security, Engineering, IT, and Legal to make compliance feel friction-free, even invisible, rather than something teams have to fight. What you'll be doing Run the customer security questionnaire program end-to-end, from intake through response, and grow a reusable answer library that turns repeat questions into fast, near-self-service answers. Operate risk and control workflows: triage incoming risks, track gap closure and risk treatment through to completion, and keep the risk register accurate and current. You'll be the first point of contact for partner teams, resolving routine questions and escalating the ones that need senior judgment. Run GRC analyses that turn into decisions: how standards, procedures, and controls align to our policies and framework requirements; where the gaps are; and how mature and effective our controls actually are. Build and maintain the GRC toolchain and its automation: administer our GRC platform, ticketing, and knowledge bases, and design the integrations and workflows that collect evidence and check controls by default rather than by hand. Create
We believe that the way people interact with their finances will drastically improve in the next few years. We’re dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid’s network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam. About the Team: The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s security organization, focused on enabling the business by proactively managing information security risks and maintaining effective controls. Our mission is to reduce the likelihood and impact of security risks while operating a robust assurance program that builds trust with our customers, consumers, and data partners. We partner closely across the company to ensure Plaid’s platform remains secure, resilient, and aligned with industry and regulatory expectations. The Security Contracts workstream is a core part of our Security Assurance and Trust Enablement program — ensuring Plaid's contractual security obligations with customers and data partners are defensible, consistent, and never a bottleneck to deal velocity, all while building trust. About the Role You will own Plaid’s Security Contracts workstream end-to-end—the DRI for how security contract reviews get done, how fast they move, and how the program improves over time. You will review security provisions in customer MSAs, DPAs, and security addenda, identify unacceptable clauses, and provide Legal and GTM with the actionable security feedback they n
We're transforming the grocery industry At Instacart, we invite the world to share love through food because we believe everyone should have access to the food they love and more time to enjoy it together. Where others see a simple need for grocery delivery, we see exciting complexity and endless opportunity to serve the varied needs of our community. We work to deliver an essential service that customers rely on to get their groceries and household goods, while also offering safe and flexible earnings opportunities to Instacart Personal Shoppers. Instacart has become a lifeline for millions of people, and we’re building the team to help push our shopping cart forward. If you’re ready to do the best work of your life, come join our table. Instacart is a Flex First team There’s no one-size fits all approach to how we do our best work. Our employees have the flexibility to choose where they do their best work—whether it’s from home, an office, or your favorite coffee shop—while staying connected and building community through regular in-person events. Learn more about our flexible approach to where we work. Overview Instacart's Governance, Risk and Compliance (GRC) team sits at the intersection of security, data, and business impact — and we're building an automated, engineering-grade risk program that produces real-time risk scoring, quantified exposure models, and ROI-linked investment decisions that reach the CISO, executive leadership, and the board. We're looking for a Senior Risk & Compliance Engineer to help us get there. This is an engineering role with a data science expertise needed. You'll write production-level code, build signal ingestion pipelines, and develop probabilistic risk models that give our security organization a quantified, confidence-backed view of our risk posture — all in service of protecting Instacart's customers and products at scale. If you're energized by the challenge of transforming a manual, reactive discipline into a data-drive
We're transforming the grocery industry At Instacart, we invite the world to share love through food because we believe everyone should have access to the food they love and more time to enjoy it together. Where others see a simple need for grocery delivery, we see exciting complexity and endless opportunity to serve the varied needs of our community. We work to deliver an essential service that customers rely on to get their groceries and household goods, while also offering safe and flexible earnings opportunities to Instacart Personal Shoppers. Instacart has become a lifeline for millions of people, and we’re building the team to help push our shopping cart forward. If you’re ready to do the best work of your life, come join our table. Instacart is a Flex First team There’s no one-size fits all approach to how we do our best work. Our employees have the flexibility to choose where they do their best work—whether it’s from home, an office, or your favorite coffee shop—while staying connected and building community through regular in-person events. Learn more about our flexible approach to where we work. Overview Instacart's Governance, Risk and Compliance (GRC) team sits at the intersection of security, data, and business impact — and we're building an automated, engineering-grade risk program that produces real-time risk scoring, quantified exposure models, and ROI-linked investment decisions that reach the CISO, executive leadership, and the board. We're looking for a Senior Risk & Compliance Engineer to help us get there. This is an engineering role with a data science expertise needed. You'll write production-level code, build signal ingestion pipelines, and develop probabilistic risk models that give our security organization a quantified, confidence-backed view of our risk posture — all in service of protecting Instacart's customers and products at scale. If you're energized by the challenge of transforming a manual, reactive discipline into a data-drive
Who Are We? Postman is the world’s leading API platform, used by more than 45 million+ developers and 500,000 organizations, including 98% of the Fortune 500. Postman is helping developers and professionals across the globe build the API-first world by simplifying each step of the API lifecycle and streamlining collaboration—enabling users to create better APIs, faster. The company is headquartered in San Francisco and has offices in Boston, New York, Austin, Tokyo, London, and Bangalore - where Postman was founded. Postman is privately held, with funding from Battery Ventures, BOND, Coatue, CRV, Insight Partners, and Nexus Venture Partners. Learn more at postman.com or connect with Postman on X via @getpostman. P.S: We highly recommend reading The "API-First World" graphic novel to understand the bigger picture and our vision at Postman. About the Team The Information Security organization at Postman operates across three pillars: Governance Risk & Compliance (GRC), Product Security, and Security Operations. We are a team of builders, not checkbox-checkers. We hold active SOC 2 Type II, ISO 27001, ISO 42001, and HIPAA compliance postures, and we are pursuing FedRAMP High and CMMC Level 2 authorization. Our security stack includes Wiz, SentinelOne, Okta, Jamf, and 1Password, and we operate across a multi-cloud environment. The Offensive Security team is the "red" pulse of this organization. We don't just find bugs — we simulate the adversary to ensure our defenses hold up under real-world pressure. We focus on continuous security validation, AI-augmented adversary emulation, and offensive AI security research at Postman's scale. The Opportunity We are looking for a Principal Offensive Security Engineer who is as much a strategist as they are a hacker. You will own the strategic direction of Postman's offensive security program — including building out a dedicated Offensive AI Security capability from the ground up — and operat
Get new grc program manager jobs by email
Daily job updates · Unsubscribe anytime