About the Team OpenAI’s Governance, Risk, and Compliance team helps ensure security and privacy are grounded in how our products and systems actually operate. Assurance Operations partners with Security, Engineering, Infrastructure, Product, Privacy, and Legal to make controls provable, risk decisions explicit, and audit readiness a result of well-designed systems. About the Role We are hiring a technical, product-minded GRC builder who can own consequential audits while improving the control and evidence systems behind them. You will build a reusable common control framework, use Codex to automate assurance work, validate changing system scope, and turn repeated audit friction into measurable improvements. We are looking for someone who questions inherited assumptions, solves novel problems creatively, works closely with engineers, and makes the next audit easier by improving the underlying system. You’ll be responsible for: Lead external, internal, customer, and certification audit work from scoping through evidence review, fieldwork, remediation, and closeout. Build a common control framework linking risk, control intent, implementation, owner, system, environment, evidence, and applicable frameworks. Validate actual scope and ownership instead of assuming last year's controls, product boundaries, or evidence remain accurate. Use Codex to build and test evidence checks, control mappings, request triage, owner workflows, monitoring, and remediation reporting. Partner with engineers on cloud architecture, identity, logging, data flows, software changes, vulnerabilities, and control effectiveness. Design maintainable, permission-aware tools that preserve source provenance, human review, and evidence integrity. Reduce repeated requests and operational burden for control owners through measurable workflow improvements. Define roadmaps, decision rights, milestones, success metrics, and clear cross-functional escalations. We’re looking for someone with: Direct ownership
Jobiba hiring network
Lead Grc Program Manager Jobs
6,876 active opportunities · Updated for October 2026
Fresh results
15 shown
Explore current lead grc program manager jobs. Use filters to narrow by work mode, employment type, experience and date posted.
Figma is growing our team of passionate creatives and builders on a mission to make design accessible to all. Figma’s platform helps teams bring ideas to life—whether you're brainstorming, creating a prototype, translating designs into code, or iterating with AI. From idea to product, Figma empowers teams to streamline workflows, move faster, and work together in real time from anywhere in the world. If you're excited to shape the future of design and collaboration, join us! Figma's Information Security team is growing and looking for a Strategic Program Manager to drive strategic initiatives and engagement across the organization. This is a fast-moving role that will help build and mature security practices and partnerships across the organization, working closely with GRC, Security Operations, Security Engineering, Internal Audit, Legal, People, Product, Sales, and business teams as a trusted security partner. You will work closely with security leadership to design programs, manage portfolios, and drive results that scale with our growing business. If you thrive on taking initiative, finding clarity in ambiguity, and driving impactful programs and relationships, we'd love to hear from you! This is a full time role that can be held from one of our US hubs or remotely in the United States. What you'll do at Figma: Lead strategic security programs from planning through execution, coordinating priorities, dependencies, risks, and accountability across security and business teams Partner with teams across Figma to identify and address security risks, align stakeholders, and translate security priorities into practical guidance and action plans Define and track security program metrics, OKRs, risk registers, and reporting that give leadership visibility into program health, priorities, and risk posture Identify and coordinate the remediation of security gaps by partnering with control owners, security specialists, and business stakeholders to drive issues to reso
About the Team OpenAI’s Legal team helps advance our mission by tackling novel legal issues in AI. Our team brings together professionals across technology, privacy, intellectual property, corporate, employment, tax, regulatory, and litigation. Our regulatory compliance work turns legal requirements into practical programs that support responsible AI development and deployment. About the Role As a Legal Program Manager focused on regulatory compliance, you will build and manage cross-functional programs that translate counsel’s guidance into practical, sustainable operations. Your initial focus may include content moderation and/or frontier AI governance, with the mix shaped by team priorities and your strengths. You will partner with internal and external counsel, other legal program managers, and technical and business teams to coordinate implementation, evidence collection, reporting, and ongoing compliance. You’ll build repeatable systems that scale across regulations, products, and jurisdictions, helping teams navigate emerging requirements with clarity and sound judgment. This full-time role is based in San Francisco, CA, or New York, NY. In this role, you will: Lead regulatory compliance programs end to end: define scope, owners, milestones, dependencies, risks, and escalation paths, and drive execution with counsel and cross-functional partners. Translate counsel’s regulatory guidance into repeatable workflows, controls, and documentation. Depending on your portfolio, this may include content moderation disclosures, transparency reporting, reporting and appeals workflows, or frontier AI model launch readiness, evaluation and risk-management evidence, and incident reporting. Build strong partnerships across Product, Engineering, User Operations, Governance, Risk and Compliance (GRC), Global Affairs, Communications, and Go-to-Market to align program priorities and deliverables. Support regulatory inquiries, audits and investigations with counsel, organizing ev
At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. As an Engineering Manager leading our Reporting team, you will lead a newly structured team focused on a critical product area within GRC Program Orchestration. This role represents an exciting opportunity to shape the future of how Vanta customers understand, visualize, and operationalize their compliance and security programs. This team is focused on evolving Vanta’s reporting platform beyond dashboards into a scalable, AI-powered reporting experience. The team owns core initiatives across enterprise reporting, historical analytics, AI-assisted insights, and certified data infrastructure powering in-product experiences. This role sits at the intersection of data products, enterprise scalability, and product innovation. As reporting becomes increasingly foundational to enterprise growth, customer retention, and Vanta’s long-term AI strategy, this role will play a key role in shaping engineering execution, cross-functional alignment, and the long-term technical direction of one of Vanta’s critical product investments. Visit our Vanta Engineering Blog to learn more about what our team is working on! What you’ll do as an Engineering Manager at Vanta: Build and scale a high-performing team: lead, coach, and grow the team while hiring strategically, identifying operational gaps, and raising the engineering bar Drive execution across strategic initiatives: Deliver against a multi-quarter roadmap spanning reporting infrastructure, enterprise reporting capabilities, AI-powered insights, and scalable data foundations Shape technical and product strategy: Partner closely with Product and cross-functional engineering teams to define the
At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. As an Engineering Manager leading our Reporting team, you will lead a newly structured team focused on a critical product area within GRC Program Orchestration. This role represents an exciting opportunity to shape the future of how Vanta customers understand, visualize, and operationalize their compliance and security programs. This team is focused on evolving Vanta’s reporting platform beyond dashboards into a scalable, AI-powered reporting experience. The team owns core initiatives across enterprise reporting, historical analytics, AI-assisted insights, and certified data infrastructure powering in-product experiences. This role sits at the intersection of data products, enterprise scalability, and product innovation. As reporting becomes increasingly foundational to enterprise growth, customer retention, and Vanta’s long-term AI strategy, this role will play a key role in shaping engineering execution, cross-functional alignment, and the long-term technical direction of one of Vanta’s critical product investments. Visit our Vanta Engineering Blog to learn more about what our team is working on! What you’ll do as an Engineering Manager at Vanta: Build and scale a high-performing team: lead, coach, and grow the team while hiring strategically, identifying operational gaps, and raising the engineering bar Drive execution across strategic initiatives: Deliver against a multi-quarter roadmap spanning reporting infrastructure, enterprise reporting capabilities, AI-powered insights, and scalable data foundations Shape technical and product strategy: Partner closely with Product and cross-functional engineering teams to define the
Discord has a highly engaged community of millions of daily active users who use the platform for many different reasons, but there’s one thing that nearly everyone does: play video games. Discord plays a uniquely important role in the future of gaming, and we are focused on making it easier and more fun for people to hang out before, during, and after playing games. Discord's Internal Audit team exists to demonstrate effective risk management, process optimization, and adherence to relevant regulations — through a mix of independent assurance and advisory work that helps teams strengthen our overall control environment. This Technology Risk Audit Manager role owns the technical side of that mission — IT SOX/ITGC, system controls, and domains centered around consumer trust — that protect hundreds of millions of our users worldwide. You'll have the opportunity to help build our internal audit function from the ground up: shaping the frameworks and processes with an AI-native approach from day one, rather than bolting AI on after the fact. Your first few months will focus on learning Discord's financial-reporting systems landscape, understanding the company's GRC program structure, and evaluating AI-powered testing solutions — setting the foundation for a function that's built to scale as Discord grows toward enterprise readiness. This person will report to the Vice President of Internal Audit. What You'll Be Doing Lead IT SOX/ITGC strategy and continuous improvement across financial-reporting-relevant systems Extend risk and controls assessment and assurance into consumer trust domains such as privacy, security, and trust & safety Partner with the Engineering organization to ensure proper access controls, segregation of duties, change management, and CI/CD integrity are in place Guide control design through system implementations, migrations, and platform changes Manage teams and projects related to IT controls and technical audits, including external contractors
At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. As Vanta's Customer Success Manager, Strategic, you will serve as a trusted advisor to Vanta's largest and most complex customers—organizations with 10,000+ employees navigating sophisticated security and compliance landscapes. Unlike traditional CSM roles managing 20-30 accounts, you'll own a focused book of 5-10 strategic accounts, driving deep customer relationships, multi-quarter projects, and high-impact business outcomes. The Strategic CS team plays a defining role in proving Vanta can serve the enterprise at scale. You'll partner closely with Strategic Account Executives and Account Managers to execute land and expand strategies, manage complex implementations, and guide executive stakeholders through their GRC program maturity journeys. Your work will directly influence Vanta's upmarket growth, product roadmap, and strategic positioning in the market. What you’ll do as a Customer Success Manager, Strategic at Vanta: Serve as the primary trusted advisor for 5-10 of Vanta's most strategic customers, each with 10,000+ employees and highly complex organizational structures Lead enterprise-scale implementations, configurations, and optimizations of Vanta's Trust Management Platform across multi-business-unit, multi-geography organizations Build and maintain deep, multi-threaded executive relationships with CISOs, CIOs, Chief Compliance Officers, and other C-level stakeholders Partner closely with Strategic Account Executives and Account Managers to identify expansion opportunities, develop account growth strategies, and execute on land and expand motions Manage complex, multi-quarter projects that require coordination across
At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. As the Sr. Manager, Commercial Customer Success, East Region you will lead a team of commercial Customer Success Managers to deliver successful onboarding, healthy adoption, advocacy and retention for our commercial customers in Vanta’s rapidly expanding customer base. You will develop a high performing team of CSMs who are customer value focused and results driven. You will be responsible for influencing the design of our upmarket CS strategy, developing a repeatable methodology to guide our customers in using Vanta as the foundation of their modern GRC program. Partnering closely with Sales, Product and Account Management leaders to represent your team and customers will be key to success in this role. You will be at the forefront of delivering Vanta’s GRC value and a key leader in executing our upmarket strategy. What you’ll do as a Sr. Manager, Commercial Customer Success at Vanta: Hire, mentor and develop a team of expert CSMs and a culture of customer centricity, high performance and accountability Influence strategy and design of the customer success methodology including implementation, adoption, customer value and risk management Define strategies and coach your team to achieve KPIs including revenue retention and customer health Through coaching your team, drive adoption of effec
At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. This is not a back-office compliance role and it is not a generic sales-engineering role. You will operate as a named member of deal teams under our pod model: paired with Strategic and Enterprise Account Executives, embedded in their weekly cadences, engaged from first discovery through POC, onsite, close, and expansion. You will be the practitioner in the room that a buyer's CISO or GRC lead trusts — and the internal expert our AEs, SEs, and marketing team build around. What you’ll do as a Subject Matter Expert at Vanta: Serve as the dedicated GRC SME for a book of Strategic/Enterprise Account Executives: join discovery and qualification calls at the earliest deal stages, scope compliance programs against Vanta's platform, and support demos, POCs, workshops, and customer onsites across Compliance, Third-Party Risk Management, Risk Management, and Trust/Questionnaire Automation. Advise prospects on program architecture: multi-framework strategy, shared controls, business-unit and workspace scoping, custom frameworks, and audit sequencing. Answer field questions through our SME channels at customer-forwardable quality — including reviewing and validating AI-agent-generated answers before they reach customers. Our team runs AI-first: you'll use agents daily, act as the quality gate on their output, and (ideally) build tooling of your own. Design and deliver enablement: live sessions for GTM teams, bootcamp scenarios and mock-customer roleplay, async curriculum modules, and review of GRC marketing and SEO content. Own monthly alignment cadences with sales front-line managers; feed structured product feedback to our Product and PM
At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. This is not a back-office compliance role and it is not a generic sales-engineering role. You will operate as a named member of deal teams under our pod model: paired with Strategic and Enterprise Account Executives, embedded in their weekly cadences, engaged from first discovery through POC, onsite, close, and expansion. You will be the practitioner in the room that a buyer's CISO or GRC lead trusts — and the internal expert our AEs, SEs, and marketing team build around. What you’ll do as a Subject Matter Expert, GTM at Vanta: Serve as the dedicated GRC SME for a book of Strategic/Enterprise Account Executives: join discovery and qualification calls at the earliest deal stages, scope compliance programs against Vanta's platform, and support demos, POCs, workshops, and customer onsites across Compliance, Third-Party Risk Management, Risk Management, and Trust/Questionnaire Automation. Advise prospects on program architecture: multi-framework strategy, shared controls, business-unit and workspace scoping, custom frameworks, and audit sequencing. Answer field questions through our SME channels at customer-forwardable quality — including reviewing and validating AI-agent-generated answers before they reach customers. Our team runs AI-first: you'll use agents daily, act as the quality gate on their output, and (ideally) build tooling of your own. Design and deliver enablement: live sessions for GTM teams, bootcamp scenarios and mock-customer roleplay, async curriculum modules, and review of GRC marketing and SEO content. Own monthly alignment cadences with sales front-line managers; feed structured product feedback to our Product a
Who Are We HALA is a leading fintech player in the MENAP region that aims to redefine financial services and build the future bank of SMEs. HALA aims at empowering SMEs to start, run, and grow their businesses by providing them with cutting-edge financial and technological tools. HALA currently holds multiple entities in UAE, Saudi Arabia and Egypt (including HALA Payments and HALA Logistics) and offers solutions that enable merchants to digitize their payments as well as manage their sales and operations. Founded in 2017, HALA is currently licensed by the Saudi Arabian Central Bank. Responsibilities Governance & Strategy: Develop, implement, and continuously improve the organization's Information Security Governance framework, policies, standards, and procedures. Lead the creation and execution of the Cyber Security Strategy in alignment with the company's overall business goals. Providing regular reports to the Board of Directors and executive management on the state of cybersecurity. Establish and manage a security metrics and Key Performance Indicator (KPI) program to measure the effectiveness of the security program and report on progress. Oversee the information security budget, ensuring resources are allocated effectively to manage risk. Risk Management: Design and manage a comprehensive enterprise-wide Cyber Security Risk Management program. Conduct regular risk assessments, including Business Impact Analysis (BIA), to identify, analyze, and evaluate information security risks. Facilitate risk treatment planning with business and technology owners, ensuring appropriate mitigation, acceptance, or transfer strategies are implemented. Manage the vendor risk management program, assessing the security posture of
ABOUT BASETEN Baseten powers mission-critical inference for the world's most dynamic AI companies, like Cursor, Notion, OpenEvidence, Abridge, Clay, Gamma and Writer. By uniting applied AI research, flexible infrastructure, and seamless developer tooling, we enable companies operating at the frontier of AI to bring cutting-edge models into production. We're growing quickly and recently raised our $1.5B Series F , led by Altimeter Capital, Conviction Partners, and Spark Capital. Join us and help build the platform engineers turn to to ship AI products. THE ROLE We are seeking an experienced and detail-oriented GRC (Governance, Risk, and Compliance) Manager to build, support, and continuously enhance Baseten’s security governance, compliance, and privacy programs. As one of the early members of our security organization, you will play a key role in ensuring our platform meets and exceeds the highest standards for privacy, trust, and regulatory compliance. In this role, you’ll work cross-functionally with engineering, operations, legal, and leadership teams to develop policies, manage audits, and implement controls aligned with frameworks such as SOC 2, ISO 27001, ISO 27701, and FedRAMP. You’ll be instrumental in building scalable processes to manage risk, support customer assurance, and uphold Baseten’s commitment to security and compliance as we grow. RESPONSIBILITIES Governance & Policy Development: Design, implement, and maintain security governance frameworks, policies, and procedures that align with Baseten’s risk posture and industry best practices. Risk Management: Build and manage the company-wide risk assessment program, identifying, tracking, and mitigating key security and compliance risks. Compliance Operations: Lead efforts to achieve and maintain compliance with SOC 2, ISO 27001/27701, HIPAA, FedRAMP and other applicable standards and regulations. Audit & Certification Management: Coordinate external audits and certification processes, ensuring e
Figma is growing our team of passionate creatives and builders on a mission to make design accessible to all. Figma’s platform helps teams bring ideas to life—whether you're brainstorming, creating a prototype, translating designs into code, or iterating with AI. From idea to product, Figma empowers teams to streamline workflows, move faster, and work together in real time from anywhere in the world. If you're excited to shape the future of design and collaboration, join us! Figma's Security team is growing, and we're looking for a Security Operations Manager to lead the strategy and execution of our security operations program. In this role, you'll build and scale the systems, processes, and tooling that help protect Figma and our community. You'll partner closely with Security Engineering, Platform Security, IT, GRC, and Legal to strengthen our detection and response capabilities, improve operational resilience, and help shape the future of our DART and SOC functions. This is a full time role that can be held from one of our US hubs or remotely in the United States. What you'll do at Figma: Own Figma's security monitoring and incident response program, from detection engineering through post-incident review and continuous improvement Build and automate security operations workflows, including alert triage, enrichment, investigation, and response actions using SOAR and custom tooling Develop and maintain incident response run books, escalation procedures, and communication plans for security events of varying severity Lead incident response preparedness initiatives, including tabletop exercises, red team engagements, and response capability assessments Improve the effectiveness of our SIEM and SOAR platforms by reducing noise, increasing signal fidelity, and closing detection coverage gaps Build and operationalize threat intelligence capabilities to identify adversary behaviors, prioritize investments, and strengthen detection and response programs Partner wi
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the role: Replit’s ecosystem is powered by an expanding array of external services and essential AI model partners. As our lead for Security Vendor Risk & Contract Reviews, you will architect and execute a risk management program focused on substantive evaluation rather than just processing checklists. You’ll analyze SOC 2 documentation, security assessments, and system architectures to determine actual risk profiles, collaborating with our Legal team to secure necessary contractual protections. This role reports to the Head of Security GRC and involves high-impact partnerships across Legal, Engineering, and Product teams. What You'll Do Run substantive third-party risk management (TPRM), independently evaluating real risk, not just processing questionnaire responses Review SOC 2 reports, pen test findings, and architecture documentation to form an independent view of vendor risk, extending the same rigor to AI/model providers Partner with Legal on vendor and AI contract terms, including DPAs, subprocessor agreements, and AI-specific provisions Review contracts for non-standard security language when flagged by Legal or deal desk, and recommend redlines Maintain the vendor and AI/model risk register, feeding findings into the company's master risk register Enable sales through maturing the customer trust program Build the capability for continuous monitoring of vendor ecosystem Required Skills & Experience 8+ years in third-party/vendor risk management, security risk, or a related GRC role Demonstrated ability to independently assess vendor risk rather than relying on questionnaire responses alone, fluent in reading SOC 2 reports, ISO certificates, pen test summaries, and architecture documentation Experi
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the role: Replit is building the security GRC function that will scale with an AI-native product. As the Risk & Compliance lead, you'll own our certification and audit program end to end: SOC 2, ISO 27001, and eventually ISO 42001 (AI management systems), while also owning the company's master security risk register and continuous compliance monitoring. You'll report to the Head of Security GRC, who retains overall accountability for the risk program, and work closely with Engineering to make sure controls hold up in practice, not just on paper. What You'll Do Own the end-to-end certification roadmap (SOC 2 Type II, ISO 27001, and future frameworks like ISO 42001) including scoping, gap assessments, remediation, and audit execution Manage relationships with external auditors and drive the annual audit calendar so certifications renew without last-minute scrambles Own and maintain the company's master security risk register including risk identification, scoring methodology, treatment plans, and residual risk reporting Build and maintain continuous compliance monitoring so control status reflects real-time state rather than point-in-time snapshots Own the core audit artifacts that back every certification including ISMS documentation, Statements of Applicability, risk assessments, and potentially FedRAMP System Security Plans (SSPs) Run regular audits and readiness assessments, and track remediation of findings and control gaps to closure Support GDPR and broader privacy compliance alongside the Legal/Privacy team, without owning the legal interpretation of requirements Partner with the GRC Engineer to define what evidence collection and control monitoring should be automated versus manually reviewed Track and
Get new lead grc program manager jobs by email
Daily job updates · Unsubscribe anytime