Jobiba hiring network

Lead Program Manager Security Grc Manager Manager Manager Jobs

15 active opportunities · Updated for September 2026

Market range: $145.2K – $213K/yr

Fresh results

15 shown

Explore current lead program manager security grc manager manager manager jobs. Use filters to narrow by work mode, employment type, experience and date posted.

O
OpenAI
📍 San FranciscoFull-time$145.2K – $213K/yr · Jobiba est.
1mo ago

About the Team OpenAI’s Governance, Risk, and Compliance team helps ensure security and privacy are grounded in how our products and systems actually operate. Assurance Operations partners with Security, Engineering, Infrastructure, Product, Privacy, and Legal to make controls provable, risk decisions explicit, and audit readiness a result of well-designed systems. About the Role We are hiring a technical, product-minded GRC builder who can own consequential audits while improving the control and evidence systems behind them. You will build a reusable common control framework, use Codex to automate assurance work, validate changing system scope, and turn repeated audit friction into measurable improvements. We are looking for someone who questions inherited assumptions, solves novel problems creatively, works closely with engineers, and makes the next audit easier by improving the underlying system. You’ll be responsible for: Lead external, internal, customer, and certification audit work from scoping through evidence review, fieldwork, remediation, and closeout. Build a common control framework linking risk, control intent, implementation, owner, system, environment, evidence, and applicable frameworks. Validate actual scope and ownership instead of assuming last year's controls, product boundaries, or evidence remain accurate. Use Codex to build and test evidence checks, control mappings, request triage, owner workflows, monitoring, and remediation reporting. Partner with engineers on cloud architecture, identity, logging, data flows, software changes, vulnerabilities, and control effectiveness. Design maintainable, permission-aware tools that preserve source provenance, human review, and evidence integrity. Reduce repeated requests and operational burden for control owners through measurable workflow improvements. Define roadmaps, decision rights, milestones, success metrics, and clear cross-functional escalations. We’re looking for someone with: Direct ownership

sqlawsrest
View job →
F
Figma
📍 Ca New YorkFull-timeFrom $169K/yr
28 days ago

Figma is growing our team of passionate creatives and builders on a mission to make design accessible to all. Figma’s platform helps teams bring ideas to life—whether you're brainstorming, creating a prototype, translating designs into code, or iterating with AI. From idea to product, Figma empowers teams to streamline workflows, move faster, and work together in real time from anywhere in the world. If you're excited to shape the future of design and collaboration, join us! Figma's Information Security team is growing and looking for a Strategic Program Manager to drive strategic initiatives and engagement across the organization. This is a fast-moving role that will help build and mature security practices and partnerships across the organization, working closely with GRC, Security Operations, Security Engineering, Internal Audit, Legal, People, Product, Sales, and business teams as a trusted security partner. You will work closely with security leadership to design programs, manage portfolios, and drive results that scale with our growing business. If you thrive on taking initiative, finding clarity in ambiguity, and driving impactful programs and relationships, we'd love to hear from you! This is a full time role that can be held from one of our US hubs or remotely in the United States. What you'll do at Figma: Lead strategic security programs from planning through execution, coordinating priorities, dependencies, risks, and accountability across security and business teams Partner with teams across Figma to identify and address security risks, align stakeholders, and translate security priorities into practical guidance and action plans Define and track security program metrics, OKRs, risk registers, and reporting that give leadership visibility into program health, priorities, and risk posture Identify and coordinate the remediation of security gaps by partnering with control owners, security specialists, and business stakeholders to drive issues to reso

B
Baseten
📍 San FranciscoFull-time
29 days ago

ABOUT BASETEN Baseten powers mission-critical inference for the world's most dynamic AI companies, like Cursor, Notion, OpenEvidence, Abridge, Clay, Gamma and Writer. By uniting applied AI research, flexible infrastructure, and seamless developer tooling, we enable companies operating at the frontier of AI to bring cutting-edge models into production. We're growing quickly and recently raised our $1.5B Series F , led by Altimeter Capital, Conviction Partners, and Spark Capital. Join us and help build the platform engineers turn to to ship AI products. THE ROLE We are seeking an experienced and detail-oriented GRC (Governance, Risk, and Compliance) Manager to build, support, and continuously enhance Baseten’s security governance, compliance, and privacy programs. As one of the early members of our security organization, you will play a key role in ensuring our platform meets and exceeds the highest standards for privacy, trust, and regulatory compliance. In this role, you’ll work cross-functionally with engineering, operations, legal, and leadership teams to develop policies, manage audits, and implement controls aligned with frameworks such as SOC 2, ISO 27001, ISO 27701, and FedRAMP. You’ll be instrumental in building scalable processes to manage risk, support customer assurance, and uphold Baseten’s commitment to security and compliance as we grow. RESPONSIBILITIES Governance & Policy Development: Design, implement, and maintain security governance frameworks, policies, and procedures that align with Baseten’s risk posture and industry best practices. Risk Management: Build and manage the company-wide risk assessment program, identifying, tracking, and mitigating key security and compliance risks. Compliance Operations: Lead efforts to achieve and maintain compliance with SOC 2, ISO 27001/27701, HIPAA, FedRAMP and other applicable standards and regulations. Audit & Certification Management: Coordinate external audits and certification processes, ensuring e

awsgcpmachine learning
View job →
F
Figma
📍 Ca New YorkFull-timeFrom $185K/yr
1mo ago

Figma is growing our team of passionate creatives and builders on a mission to make design accessible to all. Figma’s platform helps teams bring ideas to life—whether you're brainstorming, creating a prototype, translating designs into code, or iterating with AI. From idea to product, Figma empowers teams to streamline workflows, move faster, and work together in real time from anywhere in the world. If you're excited to shape the future of design and collaboration, join us! Figma's Security team is growing, and we're looking for a Security Operations Manager to lead the strategy and execution of our security operations program. In this role, you'll build and scale the systems, processes, and tooling that help protect Figma and our community. You'll partner closely with Security Engineering, Platform Security, IT, GRC, and Legal to strengthen our detection and response capabilities, improve operational resilience, and help shape the future of our DART and SOC functions. This is a full time role that can be held from one of our US hubs or remotely in the United States. What you'll do at Figma: Own Figma's security monitoring and incident response program, from detection engineering through post-incident review and continuous improvement Build and automate security operations workflows, including alert triage, enrichment, investigation, and response actions using SOAR and custom tooling Develop and maintain incident response run books, escalation procedures, and communication plans for security events of varying severity Lead incident response preparedness initiatives, including tabletop exercises, red team engagements, and response capability assessments Improve the effectiveness of our SIEM and SOAR platforms by reducing noise, increasing signal fidelity, and closing detection coverage gaps Build and operationalize threat intelligence capabilities to identify adversary behaviors, prioritize investments, and strengthen detection and response programs Partner wi

V
Vanta
📍 TorontoFull-time
29 days ago

At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. As an Engineering Manager leading our Reporting team, you will lead a newly structured team focused on a critical product area within GRC Program Orchestration. This role represents an exciting opportunity to shape the future of how Vanta customers understand, visualize, and operationalize their compliance and security programs. This team is focused on evolving Vanta’s reporting platform beyond dashboards into a scalable, AI-powered reporting experience. The team owns core initiatives across enterprise reporting, historical analytics, AI-assisted insights, and certified data infrastructure powering in-product experiences. This role sits at the intersection of data products, enterprise scalability, and product innovation. As reporting becomes increasingly foundational to enterprise growth, customer retention, and Vanta’s long-term AI strategy, this role will play a key role in shaping engineering execution, cross-functional alignment, and the long-term technical direction of one of Vanta’s critical product investments. Visit our Vanta Engineering Blog to learn more about what our team is working on! What you’ll do as an Engineering Manager at Vanta: Build and scale a high-performing team: lead, coach, and grow the team while hiring strategically, identifying operational gaps, and raising the engineering bar Drive execution across strategic initiatives: Deliver against a multi-quarter roadmap spanning reporting infrastructure, enterprise reporting capabilities, AI-powered insights, and scalable data foundations Shape technical and product strategy: Partner closely with Product and cross-functional engineering teams to define the

restairust
View job →
V
Vanta
📍 United StatesFull-time
29 days ago

At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. As an Engineering Manager leading our Reporting team, you will lead a newly structured team focused on a critical product area within GRC Program Orchestration. This role represents an exciting opportunity to shape the future of how Vanta customers understand, visualize, and operationalize their compliance and security programs. This team is focused on evolving Vanta’s reporting platform beyond dashboards into a scalable, AI-powered reporting experience. The team owns core initiatives across enterprise reporting, historical analytics, AI-assisted insights, and certified data infrastructure powering in-product experiences. This role sits at the intersection of data products, enterprise scalability, and product innovation. As reporting becomes increasingly foundational to enterprise growth, customer retention, and Vanta’s long-term AI strategy, this role will play a key role in shaping engineering execution, cross-functional alignment, and the long-term technical direction of one of Vanta’s critical product investments. Visit our Vanta Engineering Blog to learn more about what our team is working on! What you’ll do as an Engineering Manager at Vanta: Build and scale a high-performing team: lead, coach, and grow the team while hiring strategically, identifying operational gaps, and raising the engineering bar Drive execution across strategic initiatives: Deliver against a multi-quarter roadmap spanning reporting infrastructure, enterprise reporting capabilities, AI-powered insights, and scalable data foundations Shape technical and product strategy: Partner closely with Product and cross-functional engineering teams to define the

restairust
View job →
V
Vanta
📍 United StatesFull-time
29 days ago

At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. As Vanta's Customer Success Manager, Strategic, you will serve as a trusted advisor to Vanta's largest and most complex customers—organizations with 10,000+ employees navigating sophisticated security and compliance landscapes. Unlike traditional CSM roles managing 20-30 accounts, you'll own a focused book of 5-10 strategic accounts, driving deep customer relationships, multi-quarter projects, and high-impact business outcomes. The Strategic CS team plays a defining role in proving Vanta can serve the enterprise at scale. You'll partner closely with Strategic Account Executives and Account Managers to execute land and expand strategies, manage complex implementations, and guide executive stakeholders through their GRC program maturity journeys. Your work will directly influence Vanta's upmarket growth, product roadmap, and strategic positioning in the market. What you’ll do as a Customer Success Manager, Strategic at Vanta: Serve as the primary trusted advisor for 5-10 of Vanta's most strategic customers, each with 10,000+ employees and highly complex organizational structures Lead enterprise-scale implementations, configurations, and optimizations of Vanta's Trust Management Platform across multi-business-unit, multi-geography organizations Build and maintain deep, multi-threaded executive relationships with CISOs, CIOs, Chief Compliance Officers, and other C-level stakeholders Partner closely with Strategic Account Executives and Account Managers to identify expansion opportunities, develop account growth strategies, and execute on land and expand motions Manage complex, multi-quarter projects that require coordination across

restaigo
View job →
V
29 days ago

At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. As the Sr. Manager, Commercial Customer Success, East Region you will lead a team of commercial Customer Success Managers to deliver successful onboarding, healthy adoption, advocacy and retention for our commercial customers in Vanta’s rapidly expanding customer base. You will develop a high performing team of CSMs who are customer value focused and results driven. You will be responsible for influencing the design of our upmarket CS strategy, developing a repeatable methodology to guide our customers in using Vanta as the foundation of their modern GRC program. Partnering closely with Sales, Product and Account Management leaders to represent your team and customers will be key to success in this role. You will be at the forefront of delivering Vanta’s GRC value and a key leader in executing our upmarket strategy. What you’ll do as a Sr. Manager, Commercial Customer Success at Vanta: Hire, mentor and develop a team of expert CSMs and a culture of customer centricity, high performance and accountability Influence strategy and design of the customer success methodology including implementation, adoption, customer value and risk management Define strategies and coach your team to achieve KPIs including revenue retention and customer health Through coaching your team, drive adoption of effec

restaigo
View job →
D
Discord
📍 San Francisco Bay AreaFull-timeFrom $180K/yr
1mo ago

Discord has a highly engaged community of millions of daily active users who use the platform for many different reasons, but there’s one thing that nearly everyone does: play video games. Discord plays a uniquely important role in the future of gaming, and we are focused on making it easier and more fun for people to hang out before, during, and after playing games. Discord's Internal Audit team exists to demonstrate effective risk management, process optimization, and adherence to relevant regulations — through a mix of independent assurance and advisory work that helps teams strengthen our overall control environment. This Technology Risk Audit Manager role owns the technical side of that mission — IT SOX/ITGC, system controls, and domains centered around consumer trust — that protect hundreds of millions of our users worldwide. You'll have the opportunity to help build our internal audit function from the ground up: shaping the frameworks and processes with an AI-native approach from day one, rather than bolting AI on after the fact. Your first few months will focus on learning Discord's financial-reporting systems landscape, understanding the company's GRC program structure, and evaluating AI-powered testing solutions — setting the foundation for a function that's built to scale as Discord grows toward enterprise readiness. This person will report to the Vice President of Internal Audit. What You'll Be Doing Lead IT SOX/ITGC strategy and continuous improvement across financial-reporting-relevant systems Extend risk and controls assessment and assurance into consumer trust domains such as privacy, security, and trust & safety Partner with the Engineering organization to ensure proper access controls, segregation of duties, change management, and CI/CD integrity are in place Guide control design through system implementations, migrations, and platform changes Manage teams and projects related to IT controls and technical audits, including external contractors

ci/cdrestai
View job →
D
Datadog
📍 New YorkFull-timeFrom $192K/yr
1mo ago

As the Engineering Manager for Commercial Audit, you will lead a high-performing team responsible for scaling Datadog’s security and compliance posture through automation, tooling, and engineering excellence. Our GRC (Governance, Risk, and Compliance) function is a critical partner to the broader Security and Engineering organizations, ensuring that Datadog not only meets rigorous global regulatory standards but does so in a way that is efficient, scalable, and integrated into our cloud-native infrastructure. You will manage a team of engineers and analysts who are transitioning to a GRC engineering direction to treat compliance as a software problem, leveraging AI, custom tooling, CI/CD pipelines, and cloud-native services to turn complex regulatory requirements into actionable, automated controls. You will lead the strategy, roadmap, and execution of Datadog’s Commercial Audit initiatives. This is a high-impact leadership role where you will grow a team of engineers and analysts responsible for directly maintaining our compliance programs and related audits (e.g., SOC2, PCI, HIPAA, ISO) while looking to improve efficiency and effectiveness through platforms and tooling. You will act as a bridge between technical engineering, legal, and compliance, enabling the organization to move fast while maintaining a secure and compliant environment. You will champion a culture of "compliance-as-code," identifying opportunities to automate evidence collection, streamline control testing, and reduce manual toil for both your team and our partner engineering teams. At Datadog, we place value in our office culture - the relationships and collaboration it builds, and the creativity it brings to the table. We operate as a hybrid workplace to ensure our Datadogs can create a work-life harmony that best fits them. What You’ll Do: Lead the strategy, roadmap, and execution of Datadog’s commercial security compliance efforts, shifting from manual audit processes to automated, scalable

pythonawsazure
View job →
V
Vanta
📍 United StatesFull-timeRemote
12 days ago

At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. This is not a back-office compliance role and it is not a generic sales-engineering role. You will operate as a named member of deal teams under our pod model: paired with Strategic and Enterprise Account Executives, embedded in their weekly cadences, engaged from first discovery through POC, onsite, close, and expansion. You will be the practitioner in the room that a buyer's CISO or GRC lead trusts — and the internal expert our AEs, SEs, and marketing team build around. What you’ll do as a Subject Matter Expert at Vanta: Serve as the dedicated GRC SME for a book of Strategic/Enterprise Account Executives: join discovery and qualification calls at the earliest deal stages, scope compliance programs against Vanta's platform, and support demos, POCs, workshops, and customer onsites across Compliance, Third-Party Risk Management, Risk Management, and Trust/Questionnaire Automation. Advise prospects on program architecture: multi-framework strategy, shared controls, business-unit and workspace scoping, custom frameworks, and audit sequencing. Answer field questions through our SME channels at customer-forwardable quality — including reviewing and validating AI-agent-generated answers before they reach customers. Our team runs AI-first: you'll use agents daily, act as the quality gate on their output, and (ideally) build tooling of your own. Design and deliver enablement: live sessions for GTM teams, bootcamp scenarios and mock-customer roleplay, async curriculum modules, and review of GRC marketing and SEO content. Own monthly alignment cadences with sales front-line managers; feed structured product feedback to our Product and PM

REMOTErestaigo
View job →
V
Vanta
📍 United StatesFull-timeRemote
12 days ago

At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. This is not a back-office compliance role and it is not a generic sales-engineering role. You will operate as a named member of deal teams under our pod model: paired with Strategic and Enterprise Account Executives, embedded in their weekly cadences, engaged from first discovery through POC, onsite, close, and expansion. You will be the practitioner in the room that a buyer's CISO or GRC lead trusts — and the internal expert our AEs, SEs, and marketing team build around. What you’ll do as a Subject Matter Expert, GTM at Vanta: Serve as the dedicated GRC SME for a book of Strategic/Enterprise Account Executives: join discovery and qualification calls at the earliest deal stages, scope compliance programs against Vanta's platform, and support demos, POCs, workshops, and customer onsites across Compliance, Third-Party Risk Management, Risk Management, and Trust/Questionnaire Automation. Advise prospects on program architecture: multi-framework strategy, shared controls, business-unit and workspace scoping, custom frameworks, and audit sequencing. Answer field questions through our SME channels at customer-forwardable quality — including reviewing and validating AI-agent-generated answers before they reach customers. Our team runs AI-first: you'll use agents daily, act as the quality gate on their output, and (ideally) build tooling of your own. Design and deliver enablement: live sessions for GTM teams, bootcamp scenarios and mock-customer roleplay, async curriculum modules, and review of GRC marketing and SEO content. Own monthly alignment cadences with sales front-line managers; feed structured product feedback to our Product a

REMOTErestaigo
View job →
R
Replit
📍 Foster CityFull-time
29 days ago

Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the role: Replit is building the security GRC function that will scale with an AI-native product. As the Risk & Compliance lead, you'll own our certification and audit program end to end: SOC 2, ISO 27001, and eventually ISO 42001 (AI management systems), while also owning the company's master security risk register and continuous compliance monitoring. You'll report to the Head of Security GRC, who retains overall accountability for the risk program, and work closely with Engineering to make sure controls hold up in practice, not just on paper. What You'll Do Own the end-to-end certification roadmap (SOC 2 Type II, ISO 27001, and future frameworks like ISO 42001) including scoping, gap assessments, remediation, and audit execution Manage relationships with external auditors and drive the annual audit calendar so certifications renew without last-minute scrambles Own and maintain the company's master security risk register including risk identification, scoring methodology, treatment plans, and residual risk reporting Build and maintain continuous compliance monitoring so control status reflects real-time state rather than point-in-time snapshots Own the core audit artifacts that back every certification including ISMS documentation, Statements of Applicability, risk assessments, and potentially FedRAMP System Security Plans (SSPs) Run regular audits and readiness assessments, and track remediation of findings and control gaps to closure Support GDPR and broader privacy compliance alongside the Legal/Privacy team, without owning the legal interpretation of requirements Partner with the GRC Engineer to define what evidence collection and control monitoring should be automated versus manually reviewed Track and

S
Smartsheet
📍 -REMOTE, USA-Full-timeRemoteFrom $1.7M/yr
1mo ago

For over 20 years, Smartsheet has empowered teams to manage work seamlessly and scale solutions smarter. Now, in our most ambitious chapter yet, we are uniting human teams with AI agents. By orchestrating the work agents do best, automating manual tasks and uncovering insights at scale, we create the space for people to focus on what truly matters: judgment, creativity, and big thinking. That is magic at work, and it’s what we show up for every day. FedRAMP and GovRAMP (formerly StateRAMP) are transforming how Smartsheet serves government and regulated customers. We need a FedRAMP and GovRAMP subject matter expert to lead these programs—someone with real hands-on experience obtaining and maintaining ATO authorizations, navigating 3PAO assessments, and managing continuous monitoring requirements. In this role, you'll own Smartsheet's FedRAMP and GovRAMP certifications, manage relationships with our 3PAOs, drive annual assessment preparation, manage POA&M processes, and ensure we maintain authorizations at the highest level. You'll understand the nuances of federal compliance, speak fluently with government agencies and authorized assessors, and translate complex regulatory requirements into clear roadmaps for engineering and operations teams. You'll be the voice of federal compliance at Smartsheet and the trusted advisor to government customers on our security posture. You Will: Own FedRAMP and GovRAMP (formerly StateRAMP) certifications and roadmaps: Lead the overall strategy for obtaining and maintaining federal authorizations, including package management, compliance timelines, and authority coordination. Manage 3PAO relationships and assessments: Work with accredited third-party assessment organizations to conduct initial assessments and annual re-assessments. Coordinate scoping, evidence preparation, testing coordination, and results validation. Lead continuous monitoring (ConMon) execution: Oversee the delivery of monthly, annual, and event-driven Fed

REMOTEawsazuregcp
View job →
F
Figma
📍 San Francisco, CA • New York, NY • United StatesFull-time
1mo ago

Figma is growing our team of passionate creatives and builders on a mission to make design accessible to all. Figma’s platform helps teams bring ideas to life—whether you're brainstorming, creating a prototype, translating designs into code, or iterating with AI. From idea to product, Figma empowers teams to streamline workflows, move faster, and work together in real time from anywhere in the world. If you're excited to shape the future of design and collaboration, join us! Figma's GRC team helps build and maintain trust with our users, regulators, business partners, and the organizations that rely on Figma every day. We partner across the company to strengthen security, manage risk, maintain compliance, and scale the programs that support our continued growth. We're growing our team and looking for security, risk, and compliance professionals across several disciplines. Whether your expertise is in compliance, risk management, governance, GRC tooling, or customer trust, you'll have the opportunity to build programs, improve processes, and help shape how Figma scales security and trust. Roles we hire for on this team: Compliance Management Lead compliance and certification programs across security and regulatory frameworks Manage audit cycles, partner with external assessors, and drive audit readiness initiatives Improve controls, processes, and evidence management practices across the organization <s

🔔

Get new lead program manager security grc manager manager manager jobs by email

Daily job updates · Unsubscribe anytime