Jobiba hiring network

Security Risk Manager Jobs

3,372 active opportunities · Updated for October 2026

Fresh results

15 shown

Explore current security risk manager jobs. Use filters to narrow by work mode, employment type, experience and date posted.

T
Twilio
📍 - Canada• Full-time• Remote• $99.8K – $124.7K/yr
1mo ago

Who we are At Twilio, we’re shaping the future of communications, all from the comfort of our homes. We deliver innovative solutions to hundreds of thousands of businesses and empower millions of developers worldwide to craft personalized customer experiences. Our dedication to remote-first work , and strong culture of connection and global inclusion means that no matter your location, you’re part of a vibrant team with diverse experiences making a global impact each day. As we continue to revolutionize how the world interacts, we’re acquiring new skills and experiences that make work feel truly rewarding. Your career at Twilio is in your hands. . Hiring and how we work We use Artificial Intelligence (AI) to help make our hiring process efficient. That said, every hiring decision is made by real Twilions! Also, while we are a remote-first company, you may be asked to report in person on an ad-hoc basis for team gatherings, functional off-sites or customer meetings. . See yourself at Twilio Join the team as Twilio’s next Security Risk Senior Analyst. About the job The Senior Security Risk Analyst will be a key member of the One Twilio Risk Management program, focused on maturing our Security risk posture by facilitating risk identification and treatment. The team works closely with our Product and Engineering teams to ensure all areas of cyber risk are identified across Twilio and that risk methodologies are operationally effective and in compliance with regulations (e.g. Cybersecurity and/or Telecom / sector-specific regulations) and industry best practice security measures (e.g. NIST RMF, AI RMF, COSO, ISO 31000). This role provides an exciting opportunity for experienced risk professionals who are passionate about risk management and ready to contribute to the continued growth and maturity of risk practices within a dynamic organization like Twilio. Responsibilities In this role, you’ll: Execute and improve upon daily operations

REMOTErestai
View job →
J
Jamf
📍 Us Remote• Full-time• Remote• From $85.1K/yr
1mo ago

At Jamf, we believe in an open, flexible culture based on respect and trust. Our track record and thriving work environment all stem from the freedom we grant ourselves to get the job done right. We take pride in helping tens of thousands of customers around the globe succeed with Apple. The secret to our success lies in our connectivity, while operating with a high degree of flexibility. Work-life balance remains our priority while feeling connected is important to maintain our strong culture, achieve our goals, and thrive as #OneJamf. What you'll do at Jamf: The Security Risk & Compliance Analyst (Analyst) is responsible for ensuring that Jamf ‘s security controls, policies, and procedures are implemented in accordance with applicable laws, regulations, and industry standards. Reporting to the Director of Security Risk & Compliance, the Analyst will support the activities and improvements across the entire scope of Jamf’s Security Risk & Compliance program. You may be required to work periodically at a Jamf office or collaborative work location with other Jamf employees in your area for certain events or moments that matter. What you can expect to do in this role : Conduct risk assessments in accordance with established methodology. Collaborate with team members to evaluate cyber risk and treatment plans, and follow up to ensure appropriate action is taken to mitigate risk. Support maintenance of security policies to ensure compliance with relevant laws, regulations, and industry standards. Collaborate with teams across Jamf to ensure security policies are consistently implemented. Participate in monitoring efforts to ensure compliance with the security-related policies and procedures. Participate in external audits to ensure Jamf’s ongoing maintenance of its security certifications (i.e., ISO 27001, ISO 27701, SOC2 Type 2, StateRAMP). Support the vendor risk management function for evaluating Jamf’s

REMOTEawsrestagile
View job →

Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the role: Replit’s ecosystem is powered by an expanding array of external services and essential AI model partners. As our lead for Security Vendor Risk & Contract Reviews, you will architect and execute a risk management program focused on substantive evaluation rather than just processing checklists. You’ll analyze SOC 2 documentation, security assessments, and system architectures to determine actual risk profiles, collaborating with our Legal team to secure necessary contractual protections. This role reports to the Head of Security GRC and involves high-impact partnerships across Legal, Engineering, and Product teams. What You'll Do Run substantive third-party risk management (TPRM), independently evaluating real risk, not just processing questionnaire responses Review SOC 2 reports, pen test findings, and architecture documentation to form an independent view of vendor risk, extending the same rigor to AI/model providers Partner with Legal on vendor and AI contract terms, including DPAs, subprocessor agreements, and AI-specific provisions Review contracts for non-standard security language when flagged by Legal or deal desk, and recommend redlines Maintain the vendor and AI/model risk register, feeding findings into the company's master risk register Enable sales through maturing the customer trust program Build the capability for continuous monitoring of vendor ecosystem Required Skills & Experience 8+ years in third-party/vendor risk management, security risk, or a related GRC role Demonstrated ability to independently assess vendor risk rather than relying on questionnaire responses alone, fluent in reading SOC 2 reports, ISO certificates, pen test summaries, and architecture documentation Experi

aigorust
View job →
AI
AlphaSense India
📍 India• Full-time• Remote
19 days ago

About AlphaSense: The world’s most sophisticated companies rely on AlphaSense to remove uncertainty from decision-making. With market intelligence and search built on proven AI, AlphaSense delivers insights that matter from content you can trust. Our universe of public and private content includes equity research, company filings, event transcripts, expert calls, news, trade journals, and clients’ own research content. The acquisition of Tegus by AlphaSense in 2024 advances our shared mission to empower professionals to make smarter decisions through AI-driven market intelligence. Together, AlphaSense and Tegus will accelerate growth, innovation, and content expansion, with complementary product and content capabilities that enable users to unearth even more comprehensive insights from thousands of content sets. Our platform is trusted by over 6,000 enterprise customers, including a majority of the S&P 500. Founded in 2011, AlphaSense is headquartered in New York City with more than 2,000 employees across the globe and offices in the U.S., U.K., Finland, India, Singapore, Canada, and Ireland. Come join us! About the Role AlphaSense is maturing its security risk management program and needs a Senior Risk Analyst to be a core builder and operator of that function. You will design, implement, and mature a risk framework that spans information security, AI, and operational risk—building toward a program that is quantitative-leaning, connected to live data sources, and actionable at every altitude from service owner to executive leadership. You will establish risk identification and scoring methodologies, own the enterprise risk register, and produce risk intelligence that drives real decisions. You will also support the TPRM function led by a dedicated TPRM lead, contributing to assessments and risk tracking as needed. You approach this with an AI-native mindset: using AI to monitor threat landscapes, analyze risk data, draft risk narratives, and surface emerg

REMOTEjavascriptpythonjava
View job →
L
1mo ago

At Lyft, our purpose is to serve and connect. We aim to achieve this by cultivating a work environment where all team members belong and have the opportunity to thrive. Lyft connects people to transportation to change the way we live and get around our communities. Our drivers and passengers entrust Lyft with their personal information and travel details to get where they are going and expect us to keep that data safe. Lyft's Privacy and Compliance team ensures that appropriate security controls and data protections are applied to meet our compliance requirements and customer obligations We conduct security risk assessments, consult with organizational stakeholders, monitor and continuously improve Lyft's Information Security program, facilitate third-party security audits, work with engineering teams to implement, automate, and monitor security controls, develop policies, and advise on all matters related to information security assurance. We also conduct risk assessments of our third parties to ensure we understand and can mitigate any associated risk. We are looking for a highly motivated, organized, and detail-oriented individual to join our Privacy and Compliance team. As a senior member of this team, you will support our third party risk management program by conducting risk assessments and recommending mitigations. You will also help our Customer Trust team by completing inbound security and data protection questionnaires from potential partners and customers. Responsibilities: Third Party Risk Assessments Review vendor or partner requests from internal stakeholders, understanding the business purpose Work with external stakeholders to collect relevant security and data protection information from third parties Review the information and accurately assess and document the risk, and propose potential mitigations Security Questionnaires Draft responses to customer security questionnaires (e.g., CAIQ, SIG) and assist in the ma

restmicroservicesai
View job →
R
Roblox
📍 San Mateo• Full-time• From $209.3K/yr
1mo ago

Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators. At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there. A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As a member of the Roblox Security Governance, Risk, and Compliance (GRC) team, you will play a key role in supporting the Security team’s mission. The GRC team is at the heart of Roblox's security organization — empowering every builder to make risk-informed decisions by establishing a portfolio of governing policies and standards, a repeatable and scalable method of assessing and quantifying risk, and a formal oversight process for GRC capabilities across Roblox. Our program takes a balanced, "right-sized" approach to security governance — combining qualitative and quantitative risk management methodologies, including Factor Analysis of Information Risk (FAIR), to assess and prioritize the security risks that matter most to Roblox. GRC partners closely with Engineering, Legal, Finance, and leadership — including providing regular reporting to the Board of Directors and the Audit & Compliance Committee — to ensure that security risk is visible, well-understood, and actioned appropriately. The team is in an exciting phase of growth and innovation. We are using engineering to drive automation across risk management, policy lifecycle management, supply chain risk, AI risk, and controls pr

awsgitai
View job →
L
Leidos
📍 United States• Remote
13 days ago

Leidos is seeking a detail-oriented Cybersecurity Analyst with expertise in Security Accreditation to support the assessment, authorization, and continuous monitoring of information systems. The successful candidate will ensure systems comply with government and industry cybersecurity requirements while supporting the organization's Risk Management Framework (RMF) processes. Primary Responsibilities: Lead and support the security accreditation process for information systems. Develop, maintain, and review security authorization packages. Conduct security control assessments in accordance with RMF and applicable security standards. Collaborate with system owners, engineers, and stakeholders to implement security controls. Perform security risk assessments and recommend mitigation strategies. Monitor systems for compliance with cybersecurity policies and standards. Maintain Plans of Action and Milestones (POA&Ms) and track remediation activities. Support continuous monitoring activities, including vulnerability management and security reporting. Prepare documentation for Assessment & Authorization (A&A) activities. Participate in internal and external cybersecurity audits. Stay current on cybersecurity threats, regulatory requirements, and best practices. Basic Qualifications: Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field (or equivalent experience). 3–7 years of experience in cybersecurity, information assurance, or security compliance. Experience implementing or supporting the NIST Risk Management Framework (RMF). Knowledge of: NIST SP 800-37 NIST SP 800-53 NIST SP 800-171 FISMA FedRAMP (preferred) Experience with vulnerability assessment tools such as Tenabl

REMOTEawsazurelinux
View job →
S
Stripe
📍 United States• Full-time• Remote
1mo ago

Who we are About Stripe Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone’s reach while doing the most important work of your career. About the team In this role, you would join Stripe's Vulnerability Management team, whose mission is to "Surface vulnerabilities at scale across Stripe." Our vision is to create a culture of continuous excellence in managing vulnerabilities. We want to enhance customer trust by giving users context about threats and vulnerabilities affecting Stripe's systems. We aim to be a key partner in Stripe's risk management by providing visibility into vulnerabilities across Stripe's products and services. What you’ll do As a Software Engineer focused on Vulnerability Management at Stripe, you will use your software engineering expertise to find and prioritize vulnerabilities in our systems. Working closely with engineers across the company, you will drive the timely remediation of discovered vulnerabilities, playing a key role in Stripe's overall security and risk strategy. In addition, you will continuously improve Stripe's security defenses by enhancing our vulnerability management processes and selecting effective scanning tools to uncover weaknesses. Your core responsibilities as a Vulnerability Management Software Engineer will involve building data- and agent-backed systems to surface vulnerabilities across Stripe. In addition, you will coordinate fixes to prevent exploits that could impact Stripe or our users and serve as an advisor on security risks. All of this requires collaborating cross-functionally to advocate for practices that strengthen the safety of

REMOTEairust
View job →
O
Okta
📍 San Francisco• Full-time• From $134K/yr
1mo ago

Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence. This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk. The Technology, Data, and Intelligence (TDI) Team Okta is the leading independent identity provider. The Technology, Data, and Intelligence (TDI) organization is the engine that powers Okta's global workforce, providing the technology and systems that enable our employees to do their best work. The Staff Security Engineer Opportunity We are seeking a highly skilled and hands-on Staff Security Engineer with a DevSecOps & Issue Management focus to join the TDI Security team. In this role, you will be embedded directly within our technical environments , working side-by-side with engineering and operations teams to strengthen Okta’s security posture across infrastructure, cloud, and business systems. This is a tactical and strategic role; you will build a centralized Security Posture Analytics and Reporting capability that aggregates findings, remediation status, and risk data across Okta's security tools to improve visibility, accountability, and execution. The focus is on automating issue tracking and ownership assignment, identifying and routing unowned findings, partnering with remediation teams to accelerate closure, and developing remediation solutions where none currently exist. Longer term, leverage AI to simplify security posture management, increase trust in the data, automate analysis and prioritization, and provide actionable insights that help TDI proactively manage security risk at scale. The ideal candidate combines deep technical security e

awsci/cdrest
View job →
PE
Private Employer
📍 Uttar Pradesh, India• Full-time
1mo ago

About the role We are seeking an experienced and detail-oriented Information Security and Cloud Security Auditor to join our team. The ideal candidate will have 3-7 years of expertise in data security and privacy control implementation, internal auditing, third-party risk management, cybersecurity governance, and cloud security (banking sector preferred). This role will be responsible for conducting comprehensive IT and cloud security audits, ensuring compliance with regulatory requirements, and enhancing our information security policies and procedures. Key Responsibilities -Conduct IT and cloud security audits across various domains, including IT General Controls (ITGC), Information Security Controls, Cloud Security, Network Security, Vulnerability Management, and Vendor Risk Assessments. -Assess compliance with relevant laws, regulations, industry standards, and organizational policies across both on-premises and cloud environments. -Develop and enhance information security and cloud security policies and procedures in alignment with industry best practices. -Maintain thorough documentation of audit findings, risk assessments, security measures, working papers, audit program checklists, and evidence for internal and external reporting. -Validate ITGC, cloud security, and application-specific controls and manage audit documentation, risk assessments, evidence gathering, and control testing. -Follow up on audit findings and ensure timely closure of non-compliance and security issues identified during audits. -Manage and oversee third-party risk assessments and audits, ensuring robust security controls are implemented across traditional and cloud-based service providers. -Lead and participate in the development, migration, and implementation of security controls and policies for network and cloud security solutions. -Conduct risk-based security assessments of internal, vendor, and third-party hosted environments, covering both traditional IT infrastructure and cloud

awsazuregcp
View job →
G
Gitlab
📍 United States• Full-time• Remote• From $203.2K/yr
1mo ago

GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster. The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software. * Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab. An overview of this role As the Senior Director, Internal Audit you'll report to the Vice President, Internal Audit, and help strengthen GitLab's Internal Audit function. You'll turn an established audit methodology into consistent, practical ways of working, guide audit quality and execution, and help prepare and implement a risk-based audit plan that addresses GitLab's strategic, business, and compliance objectives. You'll also support the Internal Audit strategy and roadmap, lead the facilitation of our enterprise risk management program, and build trusted relationships with business partners across GitLab. What you’ll d

REMOTEgitrestai
View job →
P
Point72
📍 New York• $175K – $275K/yr
14 days ago

A Career with Point72’s Technology Team As Point72 reimagines the future of investing, our Technology team is constantly evolving our firm’s IT infrastructure and engineering capabilities, positioning us at the forefront of a rapidly evolving technology landscape. We’re a team of experts who experiment and work to discover new ways to harness open-source solutions, modern cloud architectures, and sophisticated Artificial Intelligence (AI) solutions, while embracing enterprise agile methodologies. Our commitment to building and innovating in the AI space provides the framework intended to drive smarter decision making and enhance how we build and operate our platforms and applications. As a member of Point72’s Technology team, we encourage and support your professional development from day one—helping you advance your technical skills, contribute innovative ideas, and satisfy your own intellectual curiosity—all while delivering real business impact for our multi-billion-dollar global business. What you’ll do Develop and maintain the information security policy and standards library, aligning it with business priorities, regulatory expectations, and control objectives Lead independent assessments of the information security program, including regulatory examinations and third-party evaluations Identify technology risks across a complex business environment and drive mitigation aligned with our firm’s standards and control expectations Investigate data privacy inquiries and privacy-related events, assess business impact, and coordinate timely response activities Partner with technology, legal, compliance, and business stakeholders to translate risk findings into practical remediation plans Advise control owners on policy interpretation, risk treatment, and evidence expectations for assessments and examinations Prepare clear reports for management on team activity, emerging risks, remediation progress, and key decisions Maintain accurate risk, policy, priv

artificial intelligenceai
View job →

Location: Athens, Gr Weekly office requirement: Hybrid – 2 days per week Employment type: Permanent Seniority level: Mid At GWI we're always looking for extraordinary people who thrive on making an extraordinary impact. Right now we're looking for an Information Security GRC Specialist to play a key role in our Legal team in London. If that's you, and making a difference gets you out of bed in the morning, keep reading. It could be the start of something, well, extraordinary. Sounds great, what will I be doing? 🤔 As our Information Security GRC Specialist you'll play a pivotal role in shaping the future of security compliance at GWI. Reporting into our General Counsel and working closely with our Information Security, Product, and Technology teams, you'll own our compliance posture across security frameworks, vendor risk, and client-facing security requirements — while building a security-conscious culture across the business. A few things you'll be responsible for: 👉 Own and maintain GWI's ISO 27001 certification and compliance across relevant security frameworks, keeping our posture sharp as the threat landscape evolves. 👉 Develop, implement, and maintain information security policies and procedures aligned with industry best practices. 👉 Lead vendor risk management and client security assessments — including responding to client security questionnaires and onboarding requirements. 👉 Build and maintain GWI's security trust portal, showcasing our credentials to clients and stakeholders using tools such as Drata or Vanta. 👉 Drive security awareness across the business through training programmes and internal communications that promote a strong GRC culture. It's also fun; shaking things up is what working for GWI is all about. You'll need to be flexible, comfortable with continuous change, and working in a high-tempo environment. What do I need to bring with me? 🧳 You'll need to be able to demonstrate the core skills this role requires. You don't have

airusthr
View job →

At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. We believe that security should be monitored and verified continuously, including the security of your supply chain. The Vendor Risk Management (VRM) product was designed to provide software buyers with tools to evaluate the security of their vendors by inventorying vendors, prioritizing risks, automating security reviews and remediating findings. VRM or Third party Risk Management (TPRM) presents a massive opportunity for Vanta - representing a market of $5-$10B in ARR and a CAGR of 10.8% driven by secular tailwinds in the industry that requires more focussed and deeper scrutiny of the company’s supply chain. As a Senior Software Engineer with full stack focus, you’ll be responsible for driving complex projects across our technical stack and mentor our talented engineering team. Your past experience will be leveraged to accelerate the evolution of our Vendor Risk Management product and help software buyers continuously and comprehensively monitor risks across their vendor supply chain. Our business has found incredible product-market fit and has monetized effectively since the day we signed our first customer. We’re growing at a blistering pace, which presents career-defining opportunities for engineers to accelerate their growth and to contribute to a rapidly-scaling company. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. We’d love for you to join us! Visit our Vanta Engineering Blog to learn more about what our team is working on! What you’ll do as a Senior Software Engineer at Vanta: Lead complex, ambiguous projects end-to-end, partnering wit

typescriptrestgraphql
View job →

At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. The Vendor Monitoring Data team focuses on gathering external data and conducting risk analysis as part of Vanta's Vendor Risk Management (VRM) product. Our work provides comprehensive insights that help customers mitigate third-party risks effectively. As a Senior Fullstack Engineer, you'll drive complex projects across our technical stack while mentoring our talented engineering team. This role offers a unique opportunity to delve into a hyper-focused subject area: external attack surface scanning. You'll tackle unique technical challenges and contribute directly to Vanta's impact by helping customers continuously and comprehensively monitor risks across their vendor supply chain. Our business has found incredible product-market fit and has monetized effectively since the day we signed our first customer. We're growing at a blistering pace, which presents career-defining opportunities for engineers to accelerate their growth and contribute to a rapidly-scaling company. Visit our Vanta Engineering Blog to learn more about what our team is working on! What you’ll do as a Senior Fullstack Engineer, Vendor risk management at Vanta: Identify, scope, and lead large technical projects, laying the groundwork for core products to evolve and scale into highly performant, reliable, and customizable systems Make effective tradeoffs that consider business priorities, user experience, and a sustainable technical foundation Engineer sophisticated monitoring and alerting systems to guarantee the reliability, speed, and integrity of our security data pipeline. Collaborate with security researchers to rapidly deploy new scanning techniques and

typescriptrestai
View job →
🔔

Get new security risk manager jobs by email

Daily job updates · Unsubscribe anytime