At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. Senior Software Engineer, Trust (TPRM) - Job Description As a Senior Software Engineer on Vanta's Trust TPRM team, you'll build the full-stack product experiences and underlying data infrastructure that help enterprises manage vendor risk at scale — working across teams focused on vendor lifecycle management and vendor monitoring. Vanta's Trust TPRM (Third-Party Risk Management) team is building the products that make vendor risk management seamless for security and procurement teams. From vendor onboarding and lifecycle management to continuous monitoring and procurement integrations, we're creating the platform that helps Vanta customers understand, track, and mitigate third-party risk — a fast-growing, business-critical capability for modern enterprises. As a Senior Software Engineer, you'll contribute as a core member of either the Vendor Lifecycle or Vendor Monitoring Experience team. You'll design and ship full-stack features that directly shape how customers manage vendor relationships, collaborate with product and design partners, and bring real engineering ownership to a product area that's growing quickly within Vanta. What you’ll do as a Senior Software Engineer at Vanta: Design, build, and maintain full-stack features across the TPRM product surface, including vendor onboarding, lifecycle management, and monitoring workflows Contribute to the vendor data model and core platform abstractions that power TPRM products Write clean, well-tested code and actively participate in code reviews; uphold engineering quality standards Engage in architecture discussions and contribute to technical decision-making within your team
Jobiba hiring network
Security Risk Manager Jobs
3,372 active opportunities · Updated for October 2026
Fresh results
15 shown
Explore current security risk manager jobs. Use filters to narrow by work mode, employment type, experience and date posted.
Manage site security operations in harmony with business objectives and Security Strategy Roadmap at major sites Protect enterprise wide infrastructure to ensure business continuity, creating a safe environment for all employees and stakeholders and ensuring enhanced security and personal safety of “designated protectees” Address fraud & misconduct through a well-established framework to prevent, detect, respond, and refine strategies and methodologies. Identify potential threats and calibration of risks from detailed security risk assessments to eliminate, reduce or mitigate risks. Responsible for ensuring security and protection of tangible and intangible assets, at the site Responsible for managing security related automation and infrastructure projects Source: Adani Group | Job ID: 52925
Manage site security operations in harmony with business objectives and Security Strategy Roadmap at major sites Protect enterprise wide infrastructure to ensure business continuity, creating a safe environment for all employees and stakeholders and ensuring enhanced security and personal safety of “designated protectees” Address fraud & misconduct through a well-established framework to prevent, detect, respond, and refine strategies and methodologies. Identify potential threats and calibration of risks from detailed security risk assessments to eliminate, reduce or mitigate risks. Responsible for ensuring security and protection of tangible and intangible assets, at the site Responsible for managing security related automation and infrastructure projects Source: Adani Group | Job ID: 49655
Manage site security operations in harmony with business objectives and Security Strategy Roadmap at major sites. • Protect enterprise-wide infrastructure to ensure business continuity, creating a safe environment for all • Employees and stakeholders and ensuring enhanced security and personal safety of “designated protected” • Address fraud & misconduct through a well-established framework to prevent, detect, respond, and refine strategies and methodologies. • Identify potential threats and calibration of risks from detailed security risk assessments to eliminate, reduce or mitigate risks. • Responsible for ensuring security and protection of tangible and intangible assets, at the site • Responsible for managing security related automation and infrastructure projects Source: Adani Group | Job ID: 49667
Manage site security operations in harmony with business objectives and Security Strategy Roadmap at major sites. • Protect enterprise-wide infrastructure to ensure business continuity, creating a safe environment for all • Employees and stakeholders and ensuring enhanced security and personal safety of “designated protected” • Address fraud & misconduct through a well-established framework to prevent, detect, respond, and refine strategies and methodologies. • Identify potential threats and calibration of risks from detailed security risk assessments to eliminate, reduce or mitigate risks. • Responsible for ensuring security and protection of tangible and intangible assets, at the site • Responsible for managing security related automation and infrastructure projects Source: Adani Group | Job ID: 50710
For over 20 years, Smartsheet has empowered teams to manage work seamlessly and scale solutions smarter. Now, in our most ambitious chapter yet, we are uniting human teams with AI agents. By orchestrating the work agents do best, automating manual tasks and uncovering insights at scale, we create the space for people to focus on what truly matters: judgment, creativity, and big thinking. That is magic at work, and it’s what we show up for every day. Smartsheet's customers in Europe, the Middle East, and Africa expect our Customer Trust team to understand their compliance challenges, speak their language, and respond quickly to security assessments. We're looking for a Sr. Security Engineer I to lead Customer Trust operations across EMEA—responding to security questionnaires, managing vendor risk assessments, and building trusted relationships with enterprise customers in these regions. You will be responsible for questionnaire triage, completion, and queue management for EMEA customers. You'll work closely with EMEA sales teams, understand regional compliance requirements (GDPR, EU data protection, sector-specific frameworks), and ensure Smartsheet maintains a strong reputation for responsiveness and technical credibility in these high-value markets. You will work remotely from the UK and report to our Sr. Director, GRC Engineering, based in the US You Have 5+ years of experience in customer trust, vendor risk management, security assessment, or customer-facing security roles at SaaS or cloud platform companies. Proven experience completing and responding to customer security questionnaires, vendor assessments, and RFIs. Strong understanding of GDPR, EU data protection, and regional compliance requirements: Familiarity with data residency, data processing agreements, DPIAs, and how cloud services operate within EU regulatory frameworks. Knowledge of GRC frameworks: Working knowledge of SOC 2, ISO 27001, and compliance standards commonly referenced in EMEA asse
We are dedicated to ensuring proactive elimination of entire classes of security risk by engineering the core libraries, platforms and frameworks that provide secure guardrails for all Asanas. We are looking for a Senior Software Engineer to join our new Security Development team. This team is focused on building durable, secure-by-default solutions to protect Asana's infrastructure and product. Instead of acting as gatekeepers, we build guardrails that empower engineering teams to move quickly and safely. You will be responsible for engineering preventative controls at scale, focusing on building platforms and frameworks that eradicate systemic risks. This role is based in our San Francisco office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday. Most Asanas have the option to work from home on Wednesdays. Working from home on Fridays depends on the type of work you do and the teams with which you partner. If you're interviewing for this role, your recruiter will share more about the in-office requirements. What you’ll achieve: Design, build, and maintain secure-by-default frameworks, libraries, and platforms to eliminate entire classes of vulnerabilities. Engineer and improve core security services, including our access control frameworks, secrets management infrastructure, and AWS permissions systems. Develop and own the platform for vulnerability remediation, creating tooling that empowers engineering teams to address risks efficiently. Partner with product and infrastructure teams to architect and implement foundational security controls for Asana including cloud networking, and compute infrastructure. Partner with product teams to effectively offer recommendations for how to secure projects at all phases of implementation (design, development, launch, and/or incidents) Influence engineering initiatives through design reviews, communicating security principles, and helping teams make sound security trad
We are dedicated to ensuring proactive elimination of entire classes of security risk by engineering the core libraries, platforms and frameworks that provide secure guardrails for all Asanas. We are looking for a Senior Software Engineer to join our new Security Development team. This team is focused on building durable, secure-by-default solutions to protect Asana's infrastructure and product. Instead of acting as gatekeepers, we build guardrails that empower engineering teams to move quickly and safely. You will be responsible for engineering preventative controls at scale, focusing on building platforms and frameworks that eradicate systemic risks. This role is based in our San Francisco office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday. Most Asanas have the option to work from home on Wednesdays. Working from home on Fridays depends on the type of work you do and the teams with which you partner. If you're interviewing for this role, your recruiter will share more about the in-office requirements. What you’ll achieve: Design, build, and maintain secure-by-default frameworks, libraries, and platforms to eliminate entire classes of vulnerabilities. Engineer and improve core security services, including our access control frameworks, secrets management infrastructure, and AWS permissions systems. Develop and own the platform for vulnerability remediation, creating tooling that empowers engineering teams to address risks efficiently. Partner with product and infrastructure teams to architect and implement foundational security controls for Asana including cloud networking, and compute infrastructure. Partner with product teams to effectively offer recommendations for how to secure projects at all phases of implementation (design, development, launch, and/or incidents) Influence engineering initiatives through design reviews, communicating security principles, and helping teams make sound security trad
The Business Unit Cyber Lead will be responsible for leading and managing the cybersecurity strategy, execution, and risk management efforts within a specific business unit. This role serves as the primary point of contact for all cybersecurity-related matters within the business unit, ensuring that security risks are effectively identified, mitigated, and managed. The Business Unit Cyber Lead will work closely with business leaders, IT teams, and the enterprise cybersecurity function to ensure that cybersecurity initiatives are aligned with business objectives and effectively executed to protect the organization’s digital assets. Source: Adani Group | Job ID: 41567
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the role: Replit is building the security GRC function that will scale with an AI-native product. As the Risk & Compliance lead, you'll own our certification and audit program end to end: SOC 2, ISO 27001, and eventually ISO 42001 (AI management systems), while also owning the company's master security risk register and continuous compliance monitoring. You'll report to the Head of Security GRC, who retains overall accountability for the risk program, and work closely with Engineering to make sure controls hold up in practice, not just on paper. What You'll Do Own the end-to-end certification roadmap (SOC 2 Type II, ISO 27001, and future frameworks like ISO 42001) including scoping, gap assessments, remediation, and audit execution Manage relationships with external auditors and drive the annual audit calendar so certifications renew without last-minute scrambles Own and maintain the company's master security risk register including risk identification, scoring methodology, treatment plans, and residual risk reporting Build and maintain continuous compliance monitoring so control status reflects real-time state rather than point-in-time snapshots Own the core audit artifacts that back every certification including ISMS documentation, Statements of Applicability, risk assessments, and potentially FedRAMP System Security Plans (SSPs) Run regular audits and readiness assessments, and track remediation of findings and control gaps to closure Support GDPR and broader privacy compliance alongside the Legal/Privacy team, without owning the legal interpretation of requirements Partner with the GRC Engineer to define what evidence collection and control monitoring should be automated versus manually reviewed Track and
The Regional Security Head is responsible for managing security operations across multiple sites, aligning security measures with business goals and the Security Strategy Roadmap. This role ensures comprehensive protection of infrastructure, personnel, and assets through proactive threat assessment, risk management, and the deployment of security strategies that ensure business continuity. This role also oversees security-related automation, infrastructure projects, and leads a team to foster a safe and secure environment for employees, stakeholders, and designated protectees. Source: Adani Group | Job ID: 57667
About Pinterest: Millions of people around the world come to our platform to find creative ideas, dream about new possibilities and plan for memories that will last a lifetime. At Pinterest, we’re on a mission to bring everyone the inspiration to create a life they love, and that starts with the people behind the product. Discover a career where you ignite innovation for millions, transform passion into growth opportunities, celebrate each other’s unique experiences and embrace the flexibility to do your best work. Creating a career you love? It’s Possible. At Pinterest, AI isn't just a feature, it's a powerful partner that augments our creativity and amplifies our impact, and we’re looking for candidates who are excited to be a part of that. To get a complete picture of your experience and abilities, we’ll explore your foundational skills and how you collaborate with AI. Through our interview process, what matters most is that you can always explain your approach, showing us not just what you know, but how you think. You can read more about our AI interview philosophy and how we use AI in our recruiting process here . Pinterest’s Security team (Pinfosec) is seeking an IC14 Security Engineer - Security Governance, Risk & Compliance (GRC Senior Analyst) to support and strengthen our security governance and assurance programs. This role is ideal for someone who is detail-oriented, collaborative, and motivated by building scalable security processes that help the business manage risk effectively. Reporting to the Interim Head of Security Governance, Risk & Compliance, this individual contributor will partner closely with Security, Engineering, IT, Legal, Internal Audit, and other cross-functional stakeholders to help maintain and improve Pinterest’s security control environment. The role will contribute to core GRC activities including risk management, policy governance, control testing, audit support, awareness tracking, and internal risk assessmen
The BU CISO is a senior leadership role responsible for overseeing the cybersecurity posture, strategy, and risk management within a specific business unit (BU) of the organization. This role will ensure that cybersecurity initiatives are aligned with the strategic goals of the business unit, while maintaining overall compliance with corporate security standards, policies, and regulatory requirements. The BU CISO will work closely with business unit leaders, IT, legal, and compliance teams to create and implement robust cybersecurity frameworks, address emerging risks, and safeguard the organization’s critical assets. Source: Adani Group | Job ID: 56131
Everpure (NYSE: P) has evolved from storage pioneer to data platform, closing fiscal 2026 with $3.7 billion in revenue, its first billion-dollar quarter, and accelerating growth into FY27. Our strategic agenda spans the companies defining the next era of technology - hyperscalers, AI labs, the AI hardware supply chain, data platform providers, and the broader AI ecosystem. This type of work—work that changes the world—is what the tech industry was founded on. So, if you're ready to seize the endless opportunities and leave your mark, come join us. THE ROLE As a Staff Security Operations Engineer , you will own and continuously mature capabilities across Attack Surface Management, Vulnerability Management, Zero Trust, Secrets and Credential Security, Detection Engineering, and Security Automation . This is a hands-on role requiring strong security engineering expertise combined with the ability to build teams, establish operating processes, measure outcomes, and drive remediation across Engineering, Cloud, Infrastructure, and Product organizations. You will partner closely with GISO leadership and global security teams to translate security strategy into measurable execution and risk reduction. WHAT YOU’LL DO Lead and mature enterprise Attack Surface and Vulnerability Management capabilities across cloud, infrastructure, endpoints, applications, and internet-facing environments. Drive risk-based vulnerability prioritization using asset criticality, exposure, exploitability, known exploitation, threat intelligence, and compensating controls. Establish operating processes, remediation SLAs, KPIs/KRIs, dashboards, and governance to measure and drive security risk reduction. Identify systemic security gaps and develop scalable technical and operational solutions. Provide technical leadership across Zscaler/Zero Trust, secrets and credential security, SIEM/detection engineering, EDR, cloud security, and security automation. Drive automation and integrations using APIs, sc
At Lyft, our purpose is to serve and connect. We aim to achieve this by cultivating a work environment where all team members belong and have the opportunity to thrive. Lyft connects people to transportation to change the way we live and get around our communities. Our drivers and passengers entrust Lyft with their personal information and travel details to get where they are going and expect us to keep that data safe. Lyft's Customer Trust team ensures that appropriate security controls and data protections are applied to meet our compliance requirements and customer contractual commitments. We conduct security risk assessments, consult with organizational stakeholders, monitor and continuously improve Lyft's Information Security program, facilitate third-party security audits, work with engineering teams to implement, automate, and monitor security controls, develop policies, and advise on all matters related to information security assurance. We are looking for a highly motivated, organized, and detail-oriented individual to join our Customer Trust team. As a senior member of this team, you will own a portfolio of concurrent, multi-program compliance efforts and help ensure Lyft meets its enterprise promises and contractual commitments to customers on security and privacy across global markets. You'll manage relationships with external auditors and internal stakeholders, scale our program through efficient processes and automation, and serve as a trusted advisor on technical compliance matters spanning North America, the EU, and the UK. Responsibilities: Program & Audit Ownership Own and lead our ISO 27001 compliance program end-to-end, from certification planning and internal audit through surveillance cycles and Statement of Applicability updates Drive execution across our multi-program compliance portfolio spanning SOC 2, PCI DSS, HIPAA, and NIST CSF, alongside global and international frameworks including UK Cyber Essentials, Spain ENS, and emerging EU re
Get new security risk manager jobs by email
Daily job updates · Unsubscribe anytime