Jobiba hiring network

Senior Grc Program Manager Jobs

7,292 active opportunities · Updated for October 2026

Fresh results

15 shown

Explore current senior grc program manager jobs. Use filters to narrow by work mode, employment type, experience and date posted.

P
Postman
📍 San Francisco• Full-time
1mo ago

Who Are We? Postman is the world’s leading API platform, used by more than 45 million+ developers and 500,000 organizations, including 98% of the Fortune 500. Postman is helping developers and professionals across the globe build the API-first world by simplifying each step of the API lifecycle and streamlining collaboration—enabling users to create better APIs, faster. The company is headquartered in San Francisco and has offices in Boston, New York, Austin, Tokyo, London, and Bangalore - where Postman was founded. Postman is privately held, with funding from Battery Ventures, BOND, Coatue, CRV, Insight Partners, and Nexus Venture Partners. Learn more at postman.com or connect with Postman on X via @getpostman. P.S: We highly recommend reading The "API-First World" graphic novel to understand the bigger picture and our vision at Postman. The Opportunity The Security GRC team is responsible for the overall security posture of Postman by ensuring compliance with applicable regulations and contractual obligations and maintaining effective and efficient governance, risk, and compliance programs. In addition, the Security GRC team is directly involved with supporting and enabling Sales and driving security and compliance initiatives to further the growth of Postman. We seek a Senior GRC Engineer who combines deep GRC expertise with strong engineering skills to build and scale automation across governance, risk, and compliance. This is a hands-on technical role focused on designing and operating GRC tooling, integrations, and AI-assisted workflows that reduce manual effort while improving security assurance. The ideal candidate has experience implementing and maturing compliance programs, including SOC 2, ISO 27001, HIPAA, GDPR, CCPA, and FedRAMP, and can translate security and risk requirements into practical engineering solutions. As a senior member of the Security GRC team, you will partner with Security, Engineering, IT, Legal, Sales, and other stakeholders to

javascriptpythonjava
View job →
V
Vanta
📍 United States• Full-time
1mo ago

At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. Our Senior Software Engineers lead and mentor engineers, delivering high-value products for our customers and infrastructure that enables our business to scale. Vanta’s team and technology surface are growing quickly, and it’s essential that we invest in the right abstractions and systems to enable us to scale with our business. As a Senior Software Engineer, you’ll be responsible for setting technical direction to enable our product and infrastructure to scale with our business, driving complex projects across our technical stack, and mentoring our talented engineering team. Your past experience will be leveraged to enable and accelerate Vanta’s growth. Our business has found incredible product-market fit and has monetized effectively since the day we signed our first customer. We’re growing at a blistering pace, which presents career-defining opportunities for engineers to accelerate their growth and to contribute to a rapidly-scaling company. Visit our Vanta Engineering Blog to learn more about what our team is working on! The GRC (Governance, Risk and Compliance) organization is the primary org responsible for developing and maintaining Vanta's core product offerings. These teams are at the heart of Vanta moving upmarket to support enterprise customers and build products that enable our customers’ existing security and compliance programs to integrate seamlessly with Vanta, giving them invaluable insights and recommendations to continue to operate, mature and evolve their programs. What you’ll do as a Senior Software Engineer at Vanta: Lead complex projects with multiple stakeholders and engineers to deliver significant imp

typescriptreactnode.js
View job →
V
1mo ago

At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. Our Senior Software Engineers lead and mentor engineers, delivering high-value products for our customers and infrastructure that enables our business to scale. Vanta’s team and technology surface are growing quickly, and it’s essential that we invest in the right abstractions and systems to enable us to scale with our business. As a Senior Software Engineer, you’ll be responsible for setting technical direction to enable our product and infrastructure to scale with our business, driving complex projects across our technical stack, and mentoring our talented engineering team. Your past experience will be leveraged to enable and accelerate Vanta’s growth. Our business has found incredible product-market fit and has monetized effectively since the day we signed our first customer. We’re growing at a blistering pace, which presents career-defining opportunities for engineers to accelerate their growth and to contribute to a rapidly-scaling company. Visit our Vanta Engineering Blog to learn more about what our team is working on! Please note we are only able to hire in Alberta, Ontario, and British Columbia. The GRC (Governance, Risk and Compliance) organization is the primary org responsible for developing and maintaining Vanta's core product offerings. These teams are at the heart of Vanta moving upmarket to support enterprise customers and build products that enable our customers’ existing security and compliance programs to integrate seamlessly with Vanta, giving them invaluable insights and recommendations to continue to operate, mature and evolve their programs. What you’ll do as a Senior Software Engineer at Vanta: Lead comp

typescriptreactnode.js
View job →
V
1mo ago

At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. Our Senior Software Engineers lead and mentor engineers, delivering high-value products for our customers and infrastructure that enables our business to scale. Vanta’s team and technology surface are growing quickly, and it’s essential that we invest in the right abstractions and systems to enable us to scale with our business. As a Senior Software Engineer, you’ll be responsible for setting technical direction to enable our product and infrastructure to scale with our business, driving complex projects across our technical stack, and mentoring our talented engineering team. Your past experience will be leveraged to enable and accelerate Vanta’s growth. Our business has found incredible product-market fit and has monetized effectively since the day we signed our first customer. We’re growing at a blistering pace, which presents career-defining opportunities for engineers to accelerate their growth and to contribute to a rapidly-scaling company. Visit our Vanta Engineering Blog to learn more about what our team is working on! The GRC (Governance, Risk and Compliance) organization is the primary org responsible for developing and maintaining Vanta's core product offerings. These teams are at the heart of Vanta moving upmarket to support enterprise customers and build products that enable our customers’ existing security and compliance programs to integrate seamlessly with Vanta, giving them invaluable insights and recommendations to continue to operate, mature and evolve their programs. What you’ll do as a Senior Software Engineer at Vanta: Lead complex projects with multiple stakeholders and engineers to deliver significant imp

typescriptreactnode.js
View job →
DC
14 days ago

We're looking for a Head of Enterprise & Field Marketing to lead and scale our global field marketing organization, own account-based marketing for our largest and most strategic accounts, drive alliances and partner marketing in service of enterprise growth and regional strength; and oversee our strategic events strategy and programs. This is a senior leadership role responsible for the strategy, team, and execution to drive high-quality pipeline and conversion for Diligent’s AI-powered GRC platform in all regions, and design programs that turns enterprise pipeline into revenue through a full-funnel approach, including integrated regional campaigns; 1:1/1:few ABM for named global accounts; bespoke strategic events that offer cut-through experiences for prospects and customers; and leveraging co-marketing of alliances and partnerships for net-new pipeline and brand expansion. You would be joining Diligent at an exciting moment in the company’s history, as they unleash their new AI-powered GRC platform to help General Counsels, Chief Compliance Officers, Audit and Risk Leaders. This is the result of nearly three years of intense development of agentic workflows inside the Diligent platform, as well as MCP/plug-in access to Diligent offerings - providing a robust, differentiated experience for clients who need solutions that accelerate and action critical business objectives, not just static reporting. Working closely with Sales and the broader GTM organization, you will lead an established, multi-region field marketing team and be responsible for evolving it from regional execution into a more specialized, account-centric growth engine — tightly aligned with enterprise sales leadership, customer success, global events, and partner teams. You'll own the budget, the roadmap, and the relationship with sales as the primary marketing partner for our highest-value opportunities. You w

awsgitai
View job →

Most security assurance work is reactive: a customer asks, a team scrambles, an answer goes out. This role exists to end that cycle. As a Senior Staff Analyst, you’ll own a named portfolio of our most significant customers from a security perspective, and get ahead of what they need — their regulatory environment, their audit calendar, their risk appetite, their control expectations — well enough to have the evidence ready before the request arrives. You’ll lead customer security audits hands-on, sit across from customer security teams as a peer rather than a form-filler, and build account security plans that make the next assessment predictable instead of painful. This is deliberately a hands-on senior individual contributor role. You’ll spend your time in audits, in customer conversations, and in the detail of controls and evidence — not in a management chain. If you’ve got deep SOC 2 and ISO 27001 knowledge, real technical range across cloud architecture, identity and vulnerability management, and the presence to hold a room with a sceptical CISO, this is a portfolio you can genuinely own. Here’s a breakdown of what you’ll do (not all of it, just the important stuff): Own a portfolio of strategic accounts as their dedicated security point of contact, building durable relationships with their security, risk, compliance and procurement teams. Lead customer security audits and assessments hands-on — scoping, preparing evidence, running the sessions, defending control design and driving findings to closure with internal owners. Build and maintain an account security plan for each account: their frameworks and regulators, audit and reassessment cycles, known concerns, open items and the roadmap commitments they care about. Anticipate requirements before they’re raised, tracking regulatory change, industry expectations and each account’s compliance calendar so documentation and evidence are staged in advance. Act

reactawsgit
View job →
O
14 days ago

Strength in Trust OneTrust’s mission is to enable innovation through the responsible use of data and AI. We believe that ensuring data is trusted shouldn’t slow teams down—it should accelerate what’s possible. This led us to develop the first technology platform for responsible data use in 2016. Today, with AI representing the latest and most impactful expansion of data yet, OneTrust is once again redefining what responsible innovation looks like. OneTrust, the AI‑Ready Governance Platform™, unifies regulatory intelligence, automation, and connected governance workflows so businesses can continue to move at the speed of AI while ensuring good governance to prevent data misuse at scale. Trusted by thousands of organizations worldwide, OneTrust is shaping the future where trusted data becomes a transformative force for business and society. The Challenge We are looking for a dynamic Senior Information Security GRC Analyst to support IT and InfoSec by performing various governance, risk, and compliance activities as part of the OneTrust InfoSec GRC team. Your Mission Customer Security Assurance & Questionnaires Own a high volume of end-to-end completion of customer security questionnaires (CAQs) , RFP security sections, and other assurance artifacts (e.g., SIG, CAIQ, custom questionnaires). Provide accurate, consistent, and defensible responses by leveraging internal evidence repositories (SOC reports, ISO certificates, policies, standards, diagrams, pen test summaries, etc.). Partner with internal stakeholders (Sales, Marketing, Customer Success, Security, Engineering, Privacy, Legal, Compliance, Product) to validate responses and resolve gaps. Customer Engagement & Security Discussions Meet with customers and prospects to explain security controls, risk posture, and compliance commitments . Present security topics with confidence and clarity—tailoring depth for technical and non-technical audiences. Support Sales and Customer Success by addressin

awsgitai
View job →
O
14 days ago

Strength in Trust OneTrust’s mission is to enable innovation through the responsible use of data and AI. We believe that ensuring data is trusted shouldn’t slow teams down—it should accelerate what’s possible. This led us to develop the first technology platform for responsible data use in 2016. Today, with AI representing the latest and most impactful expansion of data yet, OneTrust is once again redefining what responsible innovation looks like. OneTrust, the AI‑Ready Governance Platform™, unifies regulatory intelligence, automation, and connected governance workflows so businesses can continue to move at the speed of AI while ensuring good governance to prevent data misuse at scale. Trusted by thousands of organizations worldwide, OneTrust is shaping the future where trusted data becomes a transformative force for business and society. The Challenge We are looking for a Senior Technical Architect (GRC) to join our Technical Advisory team (part of Customer Success). This is a customer-facing role for someone who combines strong GRC expertise with attention to details, and the ability to build trust with customers. You will work with risk leaders, compliance teams, audit, control owners, procurement, and technology stakeholders to understand business objectives and challenges, assess maturity and platform adoption, and provide clear recommendations to unlock business outcomes. You will act as a trusted advisor and product expert without owning hands-on implementation or configuration. Your Mission Lead outcome-focused discovery, advisory engagements, workshops, and expert sessions with customers. Apply your GRC expertise to understand customer objectives, processes, pain points, constraints, and desired outcomes before recommending a path forward. Guide customers across relevant capabilities such as IT risk management, compliance automation, enterprise policy management, audit and compliance management, third-party risk, and related GRC workflows. Expl

awsgitai
View job →

For over 20 years, Smartsheet has empowered teams to manage work seamlessly and scale solutions smarter. Now, in our most ambitious chapter yet, we are uniting human teams with AI agents. By orchestrating the work agents do best, automating manual tasks and uncovering insights at scale, we create the space for people to focus on what truly matters: judgment, creativity, and big thinking. That is magic at work, and it’s what we show up for every day. Smartsheet's customers in Europe, the Middle East, and Africa expect our Customer Trust team to understand their compliance challenges, speak their language, and respond quickly to security assessments. We're looking for a Sr. Security Engineer I to lead Customer Trust operations across EMEA—responding to security questionnaires, managing vendor risk assessments, and building trusted relationships with enterprise customers in these regions. You will be responsible for questionnaire triage, completion, and queue management for EMEA customers. You'll work closely with EMEA sales teams, understand regional compliance requirements (GDPR, EU data protection, sector-specific frameworks), and ensure Smartsheet maintains a strong reputation for responsiveness and technical credibility in these high-value markets. You will work remotely from the UK and report to our Sr. Director, GRC Engineering, based in the US You Have 5+ years of experience in customer trust, vendor risk management, security assessment, or customer-facing security roles at SaaS or cloud platform companies. Proven experience completing and responding to customer security questionnaires, vendor assessments, and RFIs. Strong understanding of GDPR, EU data protection, and regional compliance requirements: Familiarity with data residency, data processing agreements, DPIAs, and how cloud services operate within EU regulatory frameworks. Knowledge of GRC frameworks: Working knowledge of SOC 2, ISO 27001, and compliance standards commonly referenced in EMEA asse

REMOTEawsaigo
View job →
DC
14 days ago

Role Overview You are a senior product leader who wants to shape how AI transforms IT and cyber risk management at scale. In this role, you will own one of the most strategic product areas in a global GRC SaaS platform, defining how organisations identify, assess, and act on cyber risk — and how CISOs and boards get the clarity they need when it matters most. You will set and drive the product vision, roadmap, and outcomes for IT & Cyber Risk on a multi-solution platform used by enterprises worldwide. You will partner closely with engineering, design, data science, and senior leaders to build AI-native capabilities that automate risk detection, prioritisation, and reporting. Your work will have high executive visibility, real strategic weight, and direct impact on how customers manage governance, risk, and compliance. Here’s a breakdown of what you’ll do (not all of it, just the important stuff) Lead the end-to-end product strategy and roadmap for IT & Cyber Risk, aligning to company objectives and broader platform direction. Design and deliver AI-powered features (LLMs, agents, ML models) that automate risk identification, assessment, and reporting for enterprise security and risk teams. Partner with engineering, data science, and design to define technical approaches, ship high-quality releases across web, mobile, and API, and iterate using product analytics. Develop deep market and customer insight by engaging regularly with CISOs, security leaders, and risk managers, and turn those insights into clear product bets. Define, track, and communicate product KPIs, AI performance metrics, and north star outcomes to senior stakeholders, including business cases for major investments. Work cross-functionally with Sales, Customer Success, Professional Services, and Marketing to ensure successful launches and adoption of new IT & Cyber Risk capabilities. These are the essentials you’ll need to get an interview 7+ years of product management experience, includi

awsgitagile
View job →
C
Clearwater
📍 India• Full-time• $30K – $35K/yr
14 days ago

SPECIFIC JOB RESPONSIBILITIES Defensive Operations (SecOps): Design and automate the Security Incident Response (SIR) and Vulnerability Response (VR) lifecycles. Build playbooks in Flow Designer to automate threat containment and remediation. Offensive Operations: Develop custom scoped applications to track penetration testing results, manage red-team engagement lifecycles, and automate the ingestion of reconnaissance data. Compliance & GRC: Configure and customize Integrated Risk Management (IRM) modules to map technical controls to frameworks like SOC2, ISO 27001, HIPAA, and FedRAMP. Integrations & Orchestration: Build robust, secure integrations (REST/SOAP, IntegrationHub , MID Servers) with our XDR, SIEM (Splunk/Sentinel), and cloud-native services (AWS/Azure/GCP). Multi-Tenancy & MSSP Architecture: Architect a scalable, multi-tenant environment that ensures strict data isolation between clients while allowing for unified " ClickOps " and Terraform-driven automation. AI & Innovation: Explore and implement Now Assist (GenAI) and AI-heavy workflows to automate security reporting and incident summarization. Defensive Operations (SecOps): Design and automate the Security Incident Response (SIR) and Vulnerability Response (VR) lifecycles. Build playbooks in Flow Designer to automate threat containment and remediation. Offensive Operations: Develop custom scoped applications to track penetration testing results, manage red-team engagement lifecycles, and automate the ingestion of reconnaissance data. Compliance & GRC: Configure and customize Integrated Risk Management (IRM) modules to map technical controls to frameworks like SOC2, ISO 27001, HIPAA, and FedRAMP. Integrations & Orchestration: Build robust, secure integrations (REST/SOAP, IntegrationHub , MID Servers) with our XDR, SIEM (Splunk/Sentinel), and cloud-native services (AWS/Azure/GCP)

awsazuregcp
View job →
DC
Diligent Corporation
📍 Vancouver• Full-time• From C$250K/yr
14 days ago

Overview We are seeking a hands-on Director of AI Software Engineering to lead and scale AI engineering efforts supporting multiple business units across Governance, Risk, and Compliance (GRC). This role sits at the intersection of product delivery, platform evolution, and applied AI—driving real-world impact across core workflows. This is not a pure management role. We are looking for a builder who leads from the front, someone who has recently written production code, shipped systems end-to-end, and can operate comfortably in ambiguity while aligning teams and stakeholders. What You’ll Do Lead AI Engineering Across GRC Own delivery of AI-powered capabilities embedded directly into business unit workflows (e.g., risk analysis, compliance automation, reporting, due diligence) Partner with product, data, and platform teams to translate business problems into scalable AI systems Stay Hands-On Contribute to architecture, code reviews, and critical path implementation Prototype and validate new approaches (LLMs, agents, retrieval systems, classification pipelines, etc.) Set engineering standards for performance, reliability, and cost efficiency Build and Scale Teams Lead and mentor a high-performing team of AI/ML and software engineers Drive hiring, coaching, and career development Establish a culture of ownership, speed, and technical excellence Drive Execution Deliver production-grade systems—not experiments Balance speed with rigor (security, privacy, compliance) Operate across multiple concurrent initiatives with clear prioritization Communicate and Influence Act as a bridge between engineering and business stakeholders Clearly articulate trade-offs, risks, and outcomes to senior leadership Align cross-functional teams around shared goals and timelines What We’re Looking For Proven Builder 10+ years in software engineering, with recent hands-on coding experience Demonstrated track record of shipping production systems at scale Experience with modern

pythonjavaaws
View job →
O
10 days ago

Strength in Trust OneTrust’s mission is to enable innovation through the responsible use of data and AI. We believe that ensuring data is trusted shouldn’t slow teams down—it should accelerate what’s possible. This led us to develop the first technology platform for responsible data use in 2016. Today, with AI representing the latest and most impactful expansion of data yet, OneTrust is once again redefining what responsible innovation looks like. OneTrust, the AI‑Ready Governance Platform™, unifies regulatory intelligence, automation, and connected governance workflows so businesses can continue to move at the speed of AI while ensuring good governance to prevent data misuse at scale. Trusted by thousands of organizations worldwide, OneTrust is shaping the future where trusted data becomes a transformative force for business and society. The Challenge Due to rapid growth and increased demand for our Privacy, Security, Data Governance, GRC, Third-Party Risk, Ethics and Compliance, and ESG platform, OneTrust is seeking a Senior UX Designer to join the User Experience Design team within our dynamic Research and Development team. This team continually improves the usability, design, and overall experience of OneTrust offerings, including web applications and other products and services. It is an excellent opportunity to improve the experience of an exceptionally wide range of users around the world. Your Mission The Senior UX Designer will work under the oversight of a Principal UX Designer and assist with all the UX responsibilities below: Design: Create deliverables for the entire design process, including information architecture, interface design, interaction design, and low and high-fidelity prototypes. Standards: Identify, define and promote UX best practices, including templates UX Metrics: Identify, collect, and analyze data to inform user experience decisions, including web metrics, customer sup

airecruitment
View job →
C-
CLEAR - Corporate
📍 New York• Full-time• From $225K/yr
14 days ago

CLEAR is building THE secure identity company of the future. Our mission is to make experiences safer and easier—physically and digitally. With more than 43 million Members and a growing network of partners across the world, CLEAR's secure identity platform is transforming the way people live, work, and travel. Whether it’s at the airport, stadium, or throughout your everyday life, CLEAR unlocks the magic of frictionless experiences. We are seeking a Senior Product Security Engineer to serve as a technical leader and strategic contributor within our Product Security team. This role goes beyond execution — you will drive the evolution of CLEAR’s application security posture by influencing architecture, shaping security engineering processes, and mentoring team members in security and engineering. You’ll lead security initiatives across the organization and help embed security into every stage of our software development lifecycle. What you'll do: Drive security strategy and implementation across all CLEAR products and engineering teams, ensuring consistent protection of customer and business-critical assets. Partner with engineering leadership to align application security initiatives with company-wide technology and product roadmaps, balancing innovation with risk mitigation. Provide technical leadership across CLEAR’s application security initiatives, guiding architecture, design, and development to meet high security standards. Serve as a trusted advisor to cross-functional teams — including Engineering, DevOps, Product, GRC, and IT — enabling secure-by-design practices across the organization. Design and drive implementation of scalable automated security controls and testing frameworks integrated into CLEAR’s CI/CD pipelines. Lead complex threat modeling, architecture reviews, and risk assessments across high-value systems and platforms, driving meaningful security outcomes. Engage with CLEAR's customers to provide insight and support their fraud and ident

javascriptpythonjava
View job →
B
14 days ago

Senior Manager, Japan Security and Compliance GTM WHAT IS BOX? [Recruiting owns] Box is the market leader for Cloud Content Management. Our mission is to power how the world works together. Box is partnering with enterprise organizations to accelerate their digital transformation by creating a single platform for secure content management, collaboration and workflow. We have an amazing opportunity to further establish ourselves as leaders in the space, and we need strong advocates to help us achieve that goal. By joining Box, you will have the unique opportunity to help capture a majority of this developing market and define what content management looks like for the digital enterprise. Today, Box powers over 97,000 businesses, including 70% of the Fortune 500 who trust Box to manage their content in the cloud. WHY BOX NEEDS YOU Box's security, compliance, and privacy posture is a business enabler for customers and a competitive differentiator in the market. We are looking for a Senior Manager, Japan Security and Compliance GTM, to lead Box’s customer trust efforts in Japan. This will include oversight and responsibility for gathering, vetting and scaling security, compliance, privacy and other trust-related information to customers and partners. The right person should be excellent at communicating vertically and horizontally across the company and will be comfortable explaining Box's security, compliance, and privacy posture. WHAT YOU'LL DO Lead Japan’s customer trust efforts, including responding to customer security due-diligence questionnaires and, as needed, leading customer audits. Work with US-based GRC, Security, Legal, Product and other SMEs to find answers to customer questions specific to the Japan market. Assess the need for new customer-facing content; drive the development of new content; and then scale it to account teams, customers and partners, as appropriate. Work closely with both Box Japan’s leadersh

🔔

Get new senior grc program manager jobs by email

Daily job updates · Unsubscribe anytime