Jobiba hiring network

Security Risk Manager Jobs

3,372 active opportunities · Updated for October 2026

Fresh results

15 shown

Explore current security risk manager jobs. Use filters to narrow by work mode, employment type, experience and date posted.

O
Okta
📍 San Francisco• Full-time• From $264K/yr
1mo ago

Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence. This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk. Position Overview: We are seeking a visionary Senior Director, Governance, Risk and Compliance (GRC) to lead and scale our world-class GRC Security organization. We don't view Governance, Risk, and Compliance (GRC) as a passive reporting function or an administrative checklist—we build engineering-forward, automated, and AI-driven GRC programs capable of operating in an evolving AI world. Reporting directly to Security Executive leadership, you will operate as a partner to the Senior Executives across Okta’s workforce, taking direct responsibility for cyber risk, data governance, security compliance and product certifications to enable Okta to ship world class, secure products. You will blend deep domain expertise across enterprise cyber risk, audit, and global compliance with a forward-thinking engineering mindset—pioneering continuous control monitoring, compliance-as-code, and robust AI governance for generative and agentic architectures. This is not just a leadership role. This is a builder’s role. Key Responsibilities: Drive AI-first Transformation: Execute a vision to integrate AI and agentic tools into daily GRC operations (automated evidence collection, automated risk scoring, intelligent policy mapping, and continuous audit readiness). Enterprise Risk & Governance: Operationalize Okta’s AI risk and governance framework—addressing training data protection, model risk management, responsible AI principles, and alignment with emerging

awsrestmachine learning
View job →
O
OpenAI
📍 San Francisco• Full-time
1mo ago

About the Team The Corporate Security team ensures the physical safety and security of the organization's assets, operations, and personnel. We are committed to maintaining a secure environment that enables our team to focus on advancing artificial intelligence in a responsible manner. About the Role As a Protective Intelligence & Threat Analyst, you will identify, assess, and communicate physical security threats affecting OpenAI, its personnel, executives, operations, and assets. You will leverage open-source intelligence, social media, investigative tools, and other information sources to assess violent or disruptive threats, geopolitical developments, and emerging risks relevant to the company. The role will support a broad range of Protective Intelligence activities, including persons of interest investigations, behavioral threat assessment, executive and individual risk assessments, event and travel security assessments, and time-sensitive intelligence support to Corporate Security and cross-functional partners. You will turn complex and often incomplete information into clear assessments and actionable recommendations that help inform security and protective decisions. We are seeking candidates with intelligence experience, particularly in protective intelligence, threat investigations, or behavioral threat assessment. Successful candidates will understand the intelligence cycle, OSINT investigative techniques, corporate physical security, risk management, and threat assessment, and will be comfortable operating independently in a fast-moving environment involving sensitive and occasionally high-profile matters. This role could be based in San Francisco, CA, or may be a remote role for the right candidate. We use a hybrid work model of 3 days in the office per week. Relocation offered for those outside of the Bay Area. In this role, you will: Identify and investigate potential physical threats to OpenAI, its executives, employees, facilities, operations,

pythonawsrest
View job →
A
Artefact
📍 Pune• Full-time
19 days ago

Key Responsibilities Enterprise Data Strategy & Client Engagement: Develop and maintain a comprehensive data architecture strategy that aligns with organizational and client business objectives. Serve as a key technical advisor for clients, translating business requirements into innovative data solutions. Build and maintain strong client relationships by providing expert guidance and managing expectations throughout project lifecycles. Data Modeling, Design & Engineering: Design and optimize both logical and physical data models to support enterprise-wide systems. Architect data warehousing solutions, overseeing the integration of data from multiple sources to enable robust business intelligence and analytics. Directly develop, test, and implement ETL processes and data pipelines, ensuring data quality, consistency, and performance. Technology Evaluation & Implementation: Evaluate emerging data technologies and tools to determine their fit within the existing architecture and potential for future scalability. Oversee the integration of new technologies into the enterprise data architecture, balancing innovation with risk management. Team Leadership & Hands-On Management: Lead cross-functional teams, providing mentorship and technical guidance to junior data engineers and architects. Maintain a hands-on approach by actively participating in coding, design sessions, and troubleshooting complex data issues. Ensure project milestones are met through effective resource management and team coordination. Performance, Security & Best Practices: Optimize data storage, retrieval, and processing performance across various systems. Collaborate with security teams to enforce data governance, compliance, and privacy standards. Establish and promote best practices in data management, data engineering, and architecture design. Documentation & Reporting: Develop and maintain comprehensive documentation covering data architecture designs, data flows, integrati

pythonsqlazure
View job →

Employee Applicant Privacy Notice Who we are: Shape a brighter financial future with us. Together with our members, we’re changing the way people think about and interact with personal finance. We’re a next-generation financial services company and national bank using innovative, mobile-first technology to help our millions of members reach their goals. The industry is going through an unprecedented transformation, and we’re at the forefront. We’re proud to come to work every day knowing that what we do has a direct impact on people’s lives, with our core values guiding us every step of the way. Join us to invest in yourself, your career, and the financial world. The Role: Positioned in the first line of defense (1LOD) and reporting to the Head of Business Controls, this experienced executive will act as the Business Controls Lead for SoFi’s Technology and Cybersecurity organizations. This includes comprehensive coverage of Engineering, Information Security, Infrastructure, and Data across the full SoFi Legal structure: SoFi Inc., SoFi Bank, Galileo, Technisys, and SoFi Hong Kong. The Business Controls Lead will act as the direct advisor to the Chief Technology Officer (CTO), Chief Information Security Officer (CISO), and their senior leadership teams. You will lead a team of experienced IT risk & controls team charged with promoting risk awareness and ensure the overall effectiveness of risk and compliance management program implementation and execution across the 1LOD. This role provides support, advisory services, and enables strategic alignment directly to department heads to accelerate and ensure quality execution. You will be responsible for supporting and driving consistent 1LOD adherence to critical programs, such as building and maintaining risk and control self-assessments (RCSAs); identification and evaluation of control effectiveness through control testing; 1LOD risk reporting; and supporting audits and regulatory exams. You will monitor the first l

aifinancesupply chain
View job →
DU
DoorDash USA
📍 San Francisco• Full-time
19 days ago

About the Team DoorDash’s Internal Audit team provides independent assurance that the company’s risk management, governance, and internal control processes are operating effectively. We are a small team that is looking to expand and bring on motivated professionals. We don’t think of ourselves as a typical audit function - we are obsessively focused on risks to the organizations which reflects in the type of projects we support and execute. DoorDash is rapidly growing - we are expanding in multiple geos and launching new products. This exciting growth allows us to drive creative analysis, strategy, and solutions. Our focus areas include financial, operational, regulatory, security, IT, and more. About the Role We are seeking a Senior Director, IT Internal Audit to lead the strategy, execution and evolution of DoorDash’s global IT audit function. In this highly visible role, you will help shape the technology risk management practices across DoorDash - you will oversee a broad portfolio of audits, including IT SOX, cybersecurity, data governance, AI governance, and operational technology. You will report directly to the Chief Audit Executive and serve as a strategic advisor to DoorDash’s technology, security, and engineering leaders. You will bring deep technical audit expertise, exceptional leadership skills, and a passion for innovation to build and lead a world-class IT audit organization that scales with the business. This role demands someone who can balance strategy with execution (and isn’t afraid to roll up their sleeves) — a leader who can anticipate emerging technology risks, foster strong cross-functional partnerships, translate complex technical concepts into meaningful business insights, and be ready to operate at the lowest level of detail. You will partner with teams across Security, Platform Engineering, Data Engineering, Privacy Legal, AI, Product, and Compliance to strengthen our risk posture and drive a data-driven approach

awsgitrest
View job →
S
19 days ago

Senior Compliance Specialist Position Description SingleStore is building a real-time data platform that helps organizations transact, analyze and act on data in a single system. We are committed to operating with strong security, privacy and resilience standards across our products, services and internal operations. We are seeking an experienced and highly motivated Senior Compliance Specialist to help scale our security, privacy and compliance programs. This role will be responsible for maintaining key certifications, driving cross-functional compliance initiatives, overseeing development and management of our privacy program, supporting compliance with the Digital Operational Resilience Act (DORA), and helping mature our Business Continuity Management System (BCMS). The ideal candidate is practical, organized and collaborative, with experience translating regulatory and framework requirements into durable operational processes across technical and business teams. Job Responsibilities Support governance activities across the security, privacy and compliance program, including maintaining Information Security Management System documentation, evidence, policies, procedures and audit trails. Help maintain and improve active certifications and attestations such as ISO/IEC 27001, SOC 2 Type II, HIPAA and PCI DSS, while coordinating with stakeholders across the business to ensure ongoing compliance. Drive readiness efforts for new compliance objectives, certifications and customer-driven assurance requirements. Participate in enterprise risk management activities, including risk methodology, risk assessments, treatment planning and follow-up with risk owners. Oversee the development, implementation and ongoing management of SingleStore’s privacy program in partnership with Legal, Security, IT and business stakeholders. Support compliance with applicable privacy and data protection requirements, including operationalizing controls and processes needed to meet regu

sqlgitai
View job →
R
Replit
📍 Foster City• Full-time
1mo ago

Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the role Replit is the agentic software creation platform that enables anyone to build applications using natural language. As we scale to support millions of developers and enterprise organizations, maintaining a robust, transparent, and technically sound Governance, Risk, and Compliance (GRC) program is critical. We are looking for a GRC Engineer to serve as a key technical contributor for our compliance and risk management ecosystem. You will architect the systems and processes that automate trust, partnering deeply across the organization. We need a pragmatic operator who understands that GRC exists to enable the business—balancing rigorous standards with the velocity of a high-growth startup. What You'll Do Technical Excellence & Architecture Technical Depth: Act as a technical subject matter expert for the GRC team. You will drive quality, technical depth, and operational efficiency in our security controls. Program Architecture: Own the technical vision for Replit’s GRC program, moving the team from manual workflows toward "Compliance-as-Code" and automated evidence collection. Thought Leadership: Champion a culture of security and privacy across the company, educating teams on why controls exist rather than just enforcing them. Cross-Functional Collaboration Engineering & Architecture: Partner with Architects and Engineering Leads to "bake in" compliance requirements early in the design phase. You will translate complex technical implementations into narratives that satisfy frameworks without slowing down development. Legal & Privacy: Work closely with Legal Counsel to interpret and implement requirements for Privacy (GDPR, CCPA) and emerging AI-specific regulations (e.g., EU AI Act). Sales &a

awsgcpai
View job →
O
OpenAI
📍 San Francisco• Full-time
1mo ago

About the Team The IT and Security organization builds the systems, data foundations, and automation that help OpenAI operate securely and reliably at scale. We support critical domains across identity, access, infrastructure security, enterprise systems, and internal productivity. As OpenAI grows, audit readiness and control assurance increasingly depend on reliable data: accurate system inventories, access populations, change records, configuration state, exception signals, and evidence generated directly from source systems. Our goal is to move beyond manual evidence collection and build scalable data products, automated validation, and continuous control monitoring that make security and IT controls measurable, repeatable, and defensible. About the Role We are looking for an IT Controls Data Engineer to build the data infrastructure that powers audit readiness, IT controls, evidence automation, and continuous control monitoring. In this role, you will design and maintain the pipelines, datasets, models, validation logic, dashboards, and evidence exports that make IT controls measurable, repeatable, and defensible. You will work across Security, IT, Infrastructure, Engineering, Finance Risk Management, and auditors to turn complex system behavior into reliable control data products. This is a technical builder role. The ideal candidate is strong in data engineering and analytics engineering, comfortable working with enterprise and security system data, and able to explain data lineage, source-system behavior, and control logic clearly to technical and audit stakeholders. You’ll be responsible for Building reliable data pipelines, models, and datasets for IT controls, including access, identity, configuration, change, ticketing, exception, and evidence data. Creating data quality, lineage, reconciliation, and completeness checks that make control data defensible for SOX and other audit use cases. Designing automated evidence generation workflows that produce compl

pythonsqlaws
View job →
PE
Private Employer
📍 Uttar Pradesh, India• Full-time
1mo ago

About the Role We are seeking an experienced Privacy Lead to establish, manage, and continuously enhance the organization's Privacy Program across business functions, products, technology platforms, and third-party ecosystems. The ideal candidate will possess deep expertise in privacy regulations including India's Digital Personal Data Protection Act (DPDP Act), GDPR, and privacy governance frameworks. The individual will partner closely with Legal, Compliance, Information Security, Product, Engineering, Risk, HR, and Business teams to ensure privacy-by-design principles are embedded into organizational processes and technology solutions. The Privacy Lead will serve as the subject matter expert for privacy governance, regulatory compliance, privacy risk management, data subject rights management, privacy impact assessments, and data protection controls. Key Responsibilities Privacy Governance & Strategy -Develop and execute the enterprise-wide Privacy Program and Privacy Governance Framework. -Define privacy policies, standards, procedures, and controls aligned with regulatory requirements. -Establish Privacy-by-Design and Privacy-by-Default principles across products and services. -Build privacy risk management and privacy control monitoring mechanisms. -Advise executive leadership on emerging privacy risks and regulatory developments. -Act as the organization's privacy subject matter expert for audits, inspections, and regulatory reviews. Regulatory Compliance Lead compliance initiatives for: -Digital Personal Data Protection Act (DPDP Act), India -GDPR (General Data Protection Regulation) -ISO 27701 Privacy Information Management System -RBI data governance and customer data protection requirements -Applicable privacy and data protection obligations relevant to the Banking, FinTech, Payments, and Technology sectors Responsibilities include: -Regulatory gap assessments -Compliance monitoring -Privacy control implementation -Privacy risk assessmen

AG
Adani Group
📍 Mumbai• Full-time
28 days ago

The Lead - Cybersecurity is responsible for safeguarding AdaniConneX's operational data center infrastructure by establishing and managing a robust cybersecurity framework covering IT and Operational Technology (OT) environments. The role will lead cybersecurity governance, cyber risk management, incident response, network and endpoint security, cyber resilience, regulatory compliance, and third-party cybersecurity assurance across multiple operational data centers. The incumbent will drive a proactive security culture, ensure adherence to cybersecurity policies and standards, strengthen cyber resilience, and support business continuity while enabling safe, secure, sustainable, and compliant data center operations. Source: Adani Group | Job ID: 57528

H
12 days ago

Become a part of our caring community The Associate Vice President, Model & AI Governance, is the enterprise leader responsible for establishing and overseeing the organization’s framework for model governance, artificial intelligence (AI) risk management, responsible AI and AI governance. Reporting to the Chief Audit & Risk Officer, this executive provides independent second-line oversight and challenge of the organization’s use of models, advanced analytics, machine learning, generative AI, and emerging AI technologies. The role establishes the governance, risk-management, control, monitoring and escalation framework necessary to ensure AI models are deployed in a manner that is safe, ethical, transparent, explainable, compliant, secure and aligned with the organization’s mission and risk appetite. The Associate Vice President, Model & AI Governance, partners closely with executive leadership, technology, data and analytics, clinical/business leaders, compliance, legal, privacy, cybersecurity, information security, internal audit, enterprise risk management and other control functions to ensure AI-related risks are identified, assessed, governed, monitored, and appropriately reported. This leader will serve as an advisor to executive management on emerging model and AI risks, while maintaining appropriate independence from the teams developing and deploying models and AI solutions. Key Responsibilities Own and continuously enhance the enterprise model governance framework, including model identification, inventory, classification, risk tiering, development, validation, approval, implementation, monitoring, change management, retirement and documentation. Define model risk appetite, risk taxonomy, minimum control standards, governance requirements and escalation thresholds. Provide effective challenge over model

REMOTEmachine learningartificial intelligenceai
View job →

Experienced Engineering Technical Specialist Company: The Boeing Company Boeing Defense, Space & Security (BDS) is seeking Experienced Engineering Technical Specialists (Level 3) to join the team in Berkeley, MO. This position supports Risk Managed Framework compliance across multiple avionics test labs as well as the administration of embedded PCs and host PCs on avionics test benches. The Lab Infrastructure team is responsible for the design, modification, and troubleshooting of all test benches used in the avionics' lab to support systems integration testing on the F-15. Position Responsibilities Build and configure embedded PCs and host PCs on test benches Support RHEL 9 Installation, configuration, patching and maintenance of Linux server environments Support containerization Provide active directory management and file server management Troubleshoot user problems related to hardware, software, or processes Conduct monthly OS patching and anti-virus updates Create user accounts and reset passwords Run backups on workstations and servers Maintain compliance with Risk Managed Framework and NISPOM rules Keep facility signage up to date Maintain lab access list Travel may be required up to 10% of the time; domestically and/or internationally depending on business needs. This position requires an active U.S. Secret Security Clearance (U.S. Citizenship Required). (A U.S. Security Clearance that has been active in the past 24 months is considered active) Basic Qualifications (Required Skills/Experience) <ul

linuxrecruitment
View job →
C
Clearwater
📍 India• Full-time• $30K – $35K/yr
19 days ago

SPECIFIC JOB RESPONSIBILITIES Defensive Operations (SecOps): Design and automate the Security Incident Response (SIR) and Vulnerability Response (VR) lifecycles. Build playbooks in Flow Designer to automate threat containment and remediation. Offensive Operations: Develop custom scoped applications to track penetration testing results, manage red-team engagement lifecycles, and automate the ingestion of reconnaissance data. Compliance & GRC: Configure and customize Integrated Risk Management (IRM) modules to map technical controls to frameworks like SOC2, ISO 27001, HIPAA, and FedRAMP. Integrations & Orchestration: Build robust, secure integrations (REST/SOAP, IntegrationHub , MID Servers) with our XDR, SIEM (Splunk/Sentinel), and cloud-native services (AWS/Azure/GCP). Multi-Tenancy & MSSP Architecture: Architect a scalable, multi-tenant environment that ensures strict data isolation between clients while allowing for unified " ClickOps " and Terraform-driven automation. AI & Innovation: Explore and implement Now Assist (GenAI) and AI-heavy workflows to automate security reporting and incident summarization. Defensive Operations (SecOps): Design and automate the Security Incident Response (SIR) and Vulnerability Response (VR) lifecycles. Build playbooks in Flow Designer to automate threat containment and remediation. Offensive Operations: Develop custom scoped applications to track penetration testing results, manage red-team engagement lifecycles, and automate the ingestion of reconnaissance data. Compliance & GRC: Configure and customize Integrated Risk Management (IRM) modules to map technical controls to frameworks like SOC2, ISO 27001, HIPAA, and FedRAMP. Integrations & Orchestration: Build robust, secure integrations (REST/SOAP, IntegrationHub , MID Servers) with our XDR, SIEM (Splunk/Sentinel), and cloud-native services (AWS/Azure/GCP)

awsazuregcp
View job →
V
Vanta
📍 United States• Full-time• Remote
1mo ago

At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. Vanta's V4G Partnerships function sits at the intersection of our platform, the government agencies and contractors we serve, and the broad network of systems integrators, resellers, service providers, and auditors within the public sector compliance and risk management ecosystem. You'll help build and grow these partnerships to build pipeline, as well as to ensure that customers have access to high-quality, trusted delivery through Vanta. As Director, Vanta for Government (V4G) Partnerships , you will own Vanta's partner function for the public sector — the strategy, the network, and the programs that let it scale — supporting both our government sales motion (Federal and SLED) and our government vendor business. Reporting directly to the Head of Public Sector, you will define the partner archetypes, tiering, and coverage model required to serve government demand, and own V4G partner-sourced pipeline and ARR that rolls into Vanta's overall partner-sourced target. You'll work in close partnership with the VP of Global Channel & Alliances, who owns that overall target and channel operating model, to ensure the public sector motion is built on — and strengthens — that foundation. This is a high-impact, cross-functional role for someone who has built a public sector partner function from the ground up: designing joint GTM programs, negotiating enterprise partnership agreements, and standing up the mechanisms that let a partner network scale beyond the person running it. You'll have meaningful scope: you'll own the V4G partner function — the strategy, the partner network, the program design, and the team — and decide how Vanta

REMOTErestaigo
View job →
V
Vanta
📍 United States• Full-time• Remote
1mo ago

At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. The Third-Party Risk Management team drives product development excellence across Vanta's EPD organization. This area is responsible for building and improving the tools, practices, and systems that enable product squads to move faster and deliver higher-quality experiences. As Director of Design, you will lead a team of product designers, set the design strategy for the area, and ensure Vanta ships world-class user experiences across your squads. As a Director of Product Design at Vanta, you will define a net-new experience vision, strategy, and execution for a highly AI-centric workflow builder. You’ll partner cross functionally to align others around your vision and execution, championing your experience strategy to scale your customer impact. You’ll enable Vanta to serve our most complex enterprise use cases while opening up an entirely new class of automation and extensibility across the product. What you’ll do as a Director of Design at Vanta: Set the vision and design strategy for Vanta’s Risk product area, helping customers understand, prioritize, and act on risk across their organizations. Lead, mentor, and grow a high-performing team of product designers while fostering a culture of craft, experimentation, accountability, and customer obsession. Partner closely with Product, Engineering, Research, Content Design, Design Systems, and Go-to-Market teams to shape strategy and deliver cohesive customer experiences. Translate complex risk management workflows into intuitive, scalable experiences for security, compliance, IT, legal, finance, and business stakeholders. Define experiences that help customers identify, assess,

REMOTEaifinance
View job →
🔔

Get new security risk manager jobs by email

Daily job updates · Unsubscribe anytime