Here’s a summary of the role: Every enterprise deal reaches the moment where someone in security says “prove it.” You’re the person who answers — quickly, accurately, and with the evidence to back it up. As an Analyst II on our Trust & Assurance team, you’ll own a live queue of security questionnaires, third-party due diligence assessments, RFP security sections and customer assurance requests. You’ll draft at speed using AI-assisted response tooling, then verify every answer against our approved answer library, current SOC 2 and ISO 27001 certifications and the underlying evidence before it leaves your hands. Accuracy is the whole game here: a wrong answer in a customer questionnaire is a commitment we didn’t mean to make. The best part is that you won’t just work the queue — you’ll shrink it. Every recurring question you turn into a published answer on our trust site is a ticket that never comes back. If you’ve spent two to four years in security GRC, compliance, IT audit or customer assurance, you’re precise under volume, and you like being measured on turnaround time and first-pass accuracy, you’ll do well here. Here’s a breakdown of what you’ll do (not all of it, just the important stuff): Own a high-volume queue of security questionnaires, due diligence assessments, RFP security sections and assurance requests, delivering accurate responses within SLA. Use AI-assisted response tooling to draft at speed, then verify every answer against the approved answer library, current certifications and underlying evidence before it goes out. Triage and route incoming requests using established playbooks — resolving the routine independently and escalating anything novel, contractual or architecturally complex. Maintain and expand the answer library by adding approved answers, retiring stale ones and flagging inconsistencies, so the same question never has to be researched twice. Build out trust site and customer-facing content, and show commercial teams how to
Jobiba hiring network
Grc Program Manager Jobs
127 active opportunities · Updated for October 2026
Fresh results
15 shown
Explore current grc program manager jobs. Use filters to narrow by work mode, employment type, experience and date posted.
Intern - GRC, EIS — Taipei - MTT office, Taiwan. Apply via Workday.
Cyber GRC Solutions Consultant — Virtual. Apply via Workday.
Strength in Trust OneTrust’s mission is to enable innovation through the responsible use of data and AI. We believe that ensuring data is trusted shouldn’t slow teams down—it should accelerate what’s possible. This led us to develop the first technology platform for responsible data use in 2016. Today, with AI representing the latest and most impactful expansion of data yet, OneTrust is once again redefining what responsible innovation looks like. OneTrust, the AI‑Ready Governance Platform™, unifies regulatory intelligence, automation, and connected governance workflows so businesses can continue to move at the speed of AI while ensuring good governance to prevent data misuse at scale. Trusted by thousands of organizations worldwide, OneTrust is shaping the future where trusted data becomes a transformative force for business and society. The Challenge We are looking for a dynamic Senior Information Security GRC Analyst to support IT and InfoSec by performing various governance, risk, and compliance activities as part of the OneTrust InfoSec GRC team. Your Mission Customer Security Assurance & Questionnaires Own a high volume of end-to-end completion of customer security questionnaires (CAQs) , RFP security sections, and other assurance artifacts (e.g., SIG, CAIQ, custom questionnaires). Provide accurate, consistent, and defensible responses by leveraging internal evidence repositories (SOC reports, ISO certificates, policies, standards, diagrams, pen test summaries, etc.). Partner with internal stakeholders (Sales, Marketing, Customer Success, Security, Engineering, Privacy, Legal, Compliance, Product) to validate responses and resolve gaps. Customer Engagement & Security Discussions Meet with customers and prospects to explain security controls, risk posture, and compliance commitments . Present security topics with confidence and clarity—tailoring depth for technical and non-technical audiences. Support Sales and Customer Success by addressin
Strength in Trust OneTrust’s mission is to enable innovation through the responsible use of data and AI. We believe that ensuring data is trusted shouldn’t slow teams down—it should accelerate what’s possible. This led us to develop the first technology platform for responsible data use in 2016. Today, with AI representing the latest and most impactful expansion of data yet, OneTrust is once again redefining what responsible innovation looks like. OneTrust, the AI‑Ready Governance Platform™, unifies regulatory intelligence, automation, and connected governance workflows so businesses can continue to move at the speed of AI while ensuring good governance to prevent data misuse at scale. Trusted by thousands of organizations worldwide, OneTrust is shaping the future where trusted data becomes a transformative force for business and society. The Challenge We are looking for a Senior Technical Architect (GRC) to join our Technical Advisory team (part of Customer Success). This is a customer-facing role for someone who combines strong GRC expertise with attention to details, and the ability to build trust with customers. You will work with risk leaders, compliance teams, audit, control owners, procurement, and technology stakeholders to understand business objectives and challenges, assess maturity and platform adoption, and provide clear recommendations to unlock business outcomes. You will act as a trusted advisor and product expert without owning hands-on implementation or configuration. Your Mission Lead outcome-focused discovery, advisory engagements, workshops, and expert sessions with customers. Apply your GRC expertise to understand customer objectives, processes, pain points, constraints, and desired outcomes before recommending a path forward. Guide customers across relevant capabilities such as IT risk management, compliance automation, enterprise policy management, audit and compliance management, third-party risk, and related GRC workflows. Expl
Most security assurance work is reactive: a customer asks, a team scrambles, an answer goes out. This role exists to end that cycle. As a Senior Staff Analyst, you’ll own a named portfolio of our most significant customers from a security perspective, and get ahead of what they need — their regulatory environment, their audit calendar, their risk appetite, their control expectations — well enough to have the evidence ready before the request arrives. You’ll lead customer security audits hands-on, sit across from customer security teams as a peer rather than a form-filler, and build account security plans that make the next assessment predictable instead of painful. This is deliberately a hands-on senior individual contributor role. You’ll spend your time in audits, in customer conversations, and in the detail of controls and evidence — not in a management chain. If you’ve got deep SOC 2 and ISO 27001 knowledge, real technical range across cloud architecture, identity and vulnerability management, and the presence to hold a room with a sceptical CISO, this is a portfolio you can genuinely own. Here’s a breakdown of what you’ll do (not all of it, just the important stuff): Own a portfolio of strategic accounts as their dedicated security point of contact, building durable relationships with their security, risk, compliance and procurement teams. Lead customer security audits and assessments hands-on — scoping, preparing evidence, running the sessions, defending control design and driving findings to closure with internal owners. Build and maintain an account security plan for each account: their frameworks and regulators, audit and reassessment cycles, known concerns, open items and the roadmap commitments they care about. Anticipate requirements before they’re raised, tracking regulatory change, industry expectations and each account’s compliance calendar so documentation and evidence are staged in advance. Act
The Business Unit Cyber Lead will be responsible for leading and managing the cybersecurity strategy, execution, and risk management efforts within a specific business unit. This role serves as the primary point of contact for all cybersecurity-related matters within the business unit, ensuring that security risks are effectively identified, mitigated, and managed. The Business Unit Cyber Lead will work closely with business leaders, IT teams, and the enterprise cybersecurity function to ensure that cybersecurity initiatives are aligned with business objectives and effectively executed to protect the organization’s digital assets. Source: Adani Group | Job ID: 52026
Solutions Consultant (GRC & Cyber Risk) – DACH — Germany - Virtual. Apply via Workday.
Ready to do the most impactful work of your career? At Coinbase , we are uncompromising on our mission to increase economic freedom. The bar is high, the environment is intense, and we like it that way. This isn't a place for complacency, it’s a place to be pushed past your perceived limits. If you're ready to build the future of finance alongside people who refuse to settle for "good enough," you belong here. Coinbase is a remote-first, but not remote-only company. Expect to get together quarterly for intense in-person working sessions called “surges.” learn more about working at Coinbase . We're hiring a Manager, GRC to join our Technology Risk & Controls team within Security and lead second line of defense advisory coverage across critical technology and security domains. This team evaluates risk posture, improves control design, and helps engineering, infrastructure, and security leaders make better, risk-informed decisions. You'll both manage a team and directly own advisory coverage for domains that may include disaster recovery and resiliency, SDLC, artificial intelligence, identity and access management, and supply chain - building trusted partnerships that ensure Coinbase addresses its most critical risks in its most critical functions. What you'll do: Lead second line advisory coverage for key technology and security domains, assessing risk exposure, control effectiveness, policy alignment, and emerging issues across the business. Partner with engineering and technology teams to evaluate domain posture and identify where additional controls, remediation, or governance improvements are needed. Review and challenge the design of new and existing risks and their corresponding controls to ensure our mitigations are scalable, effective, and aligned to business, risk, and regulatory expectations. Drive coordination across risk, controls, policy, audit, and assurance teams to translate incidents, audit findings, and regulatory expectations i
Sr. GRC Analyst — Hyderabad - Phoenix Aquila, India. Apply via Workday.
Drata is building the trust layer between great companies - automating compliance, managing risk, and helping organizations prove trust continuously as they scale. We're Dratanauts: a global crew of 600+ professionals united by a culture that rewards integrity, ownership, and raising the bar, no matter where in the world we're working from. Why Join the Drata Team? At Drata, you're not maintaining legacy compliance software - you're building the agentic AI platform defining what trust looks like for the next generation of companies. Here's what makes the work itself worth showing up for: Problems without a playbook: You'll work at the edge of AI and security, building agentic governance, continuous compliance, and real-time trust verification to solve problems that don't have an established answer yet. You're writing it as you go. Real ownership, not just process: Our values center on owning outcomes and raising the bar, not checking boxes. You're expected to have opinions and back them. A seat at the table: Your perspective is unique and valued. Open debate and diverse viewpoints are built into how decisions actually get made here, at every level. Growth at rocketship speed: Drata is scaling fast, which means scope grows fast too. High performers get more ownership, visibility, and experience. A crew, not just coworkers: Dratanauts consistently describe a "come as you are" culture with sharp, curious people—the kind of team that makes hard problems genuinely fun to solve. See what they say here and follow us on LinkedIn for company news, employee stories, and career updates. Job Summary: The Staff Software Engineer serves as a technical leader across multiple small teams. They design and build scalable systems, guide architectural decisions, and tackle complex challenges that span codebases and domains. They work closely with Product and Engineering leadership to shape the technical roadmap, ensure systems are reliable and secure, and drive key cross-team initiativ
Come join our legal team to work on the most exciting legal, policy, and operational issues at the leading edge of AI. We're seeking strong product lawyers with specialized expertise in intellectual property law. As product counsel, you will advise on all legal aspects of product development, launch, and operations - including regulatory compliance, user terms, and risk management - while bringing deep expertise in your specialized legal area. The ideal candidate will have deep subject matter expertise in intellectual property law, a technology background, and a demonstrable history of providing practical product counsel to solve complex, time-sensitive problems in close partnership with cross-functional teams. This role reoprts to the Associate General Counsel, IP & Product. You will: Strategic Product Advice: Lead IP strategy for product development, embedding IP protection into the full product lifecycle from conception to commercialization, while also advising on related product and regulatory matters in collaboration with the broader legal team. Cross-Functional Collaboration: Partner with Research, Product, Engineering, Operations, Communications, and Marketing teams to mitigate IP risks in product development, data licensing, and open-source governance. IP Counsel: Support management of Scale's worldwide IP portfolio including patents and trademarks; assist with patent prosecution and trademark registration and enforcement. Risk Mitigation: Advise on third-party, synthetic, and open-source data and models, ensuring compliance with licensing requirements; design open-source governance policies. Agreements: Support drafting and negotiation of commercial agreement provisions involving intellectual property. Specialized Expertise: Provide counsel on machine learning, robotics, and other technical areas, with ability to engage effectively with technical teams on complex engineering and product issues. Training: Develop and deliver IP and data licensing trainin
Position Overview Diligent is looking for an experienced GRC Advisor to join the team and work on Key accounts to drive adoption and retention and identify areas for expansion within our platform. This position will leverage our GTM, and value drivers established through combining people, process, and technology. If you are anything like the talented GRC Advisors at Diligent then this feeling you have, might be the desire to serve others- but you are blinded by the limits placed on you in your current role. The Client Success Advisor role is key to Diligent’s Customer Success retention strategy. Key Responsibilities Provide guidance and best practices on configuring, customizing, and optimizing the functionality of the GRC platform and modules to align with clients’ business processes and objectives. Conduct in-depth assessments of clients’ GRC requirements, objectives, and challenges to recommend tailored solutions to address their business needs and goals. Collaborate with clients on internal roadmaps, governance, risk, and compliance requirements to be implemented within Diligent’s platform. Ensure proper understanding and adoption of the platform solutions to identify at-risk clients and help increase usage of the software and modules. Partner closely with internal Product, Customer Success, Support, and Sales teams to drive continuous improvement of the platform based on client use cases. Monitor industry trends, regulatory developments, and emerging best practices in the GRC landscape to proactively share insights and recommendations with clients from a subject matter expert perspective. Required Experience/Skills Minimum of 5-7 years of experience in a client-facing role within the legal, compliance, and entity management or subsidiary governance industry. Adaptive mindset and ability to drive out a meaningful path to how our customers see tangible business value. Ability to build relationships both internally and externally to understand the underpinni
For over 20 years, Smartsheet has empowered teams to manage work seamlessly and scale solutions smarter. Now, in our most ambitious chapter yet, we are uniting human teams with AI agents. By orchestrating the work agents do best, automating manual tasks and uncovering insights at scale, we create the space for people to focus on what truly matters: judgment, creativity, and big thinking. That is magic at work, and it’s what we show up for every day. Smartsheet's customers in Europe, the Middle East, and Africa expect our Customer Trust team to understand their compliance challenges, speak their language, and respond quickly to security assessments. We're looking for a Sr. Security Engineer I to lead Customer Trust operations across EMEA—responding to security questionnaires, managing vendor risk assessments, and building trusted relationships with enterprise customers in these regions. You will be responsible for questionnaire triage, completion, and queue management for EMEA customers. You'll work closely with EMEA sales teams, understand regional compliance requirements (GDPR, EU data protection, sector-specific frameworks), and ensure Smartsheet maintains a strong reputation for responsiveness and technical credibility in these high-value markets. You will work remotely from the UK and report to our Sr. Director, GRC Engineering, based in the US You Have 5+ years of experience in customer trust, vendor risk management, security assessment, or customer-facing security roles at SaaS or cloud platform companies. Proven experience completing and responding to customer security questionnaires, vendor assessments, and RFIs. Strong understanding of GDPR, EU data protection, and regional compliance requirements: Familiarity with data residency, data processing agreements, DPIAs, and how cloud services operate within EU regulatory frameworks. Knowledge of GRC frameworks: Working knowledge of SOC 2, ISO 27001, and compliance standards commonly referenced in EMEA asse
Agents have changed the game for software delivery and efficacy. Diligent is the leading GRC platform in the world, and we are racing ahead to take the agents show on the road and work with the customers where they work . The FDE function will lead the change on how we embed AI agents into some of the world’s most complex governance, risk and compliance environments. This is not a support or consultancy role. It is a builder role, for someone who is equally comfortable reading a failing agent trace, running a discovery workshop with a bank’s internal audit team, and translating what they find into a production-grade agentic solution. You will be building AI agents for GRC professionals , not assistants that surface suggestions, but agents that own complex, multi-step workflows end to end . Agents that customers can hand a task to and trust it will come back done. Closing the gap between a promising prototype and something a company Board and ELT depends on is a completely . Here’s a breakdown of what you’ll do Embed directly with major enterprise customers (global banks, regulated corporates) across EU and US ; sitting wi th internal audit teams, risk functions, compliance and governance professionals to understand their real workflows and devise agentic solutions to intelligently automate them creating tremendous efficacy and efficiencies for our customers. Run agent-focused discovery workshops, rapidly prototype agentic solutions, and test them with practitioners; distinguishing between workflows that need an agent and those that need a button. Source, integrate, and move data between enterprise systems as part of live customer implementations — understanding the real data landscape customers operate in and building reliable pipelines to support it . Take agents from prototype t
Get new grc program manager jobs by email
Daily job updates · Unsubscribe anytime