TL;DR
Grc Manager: Leading and maturing the global Governance, Risk, and Compliance program with an accent on audit and certification strategy across frameworks such as ISO 27001, SOC 2 Type 2, C5, PCI DSS, ISO 42001, and FedRAMP. Focus on third-party risk management, supplier governance, policy lifecycle management, enterprise risk processes, and security awareness programs.
Location: Remote
Salary: $120,000-$150,000
Company
hirify.global is the leading data security platform purpose-built for the cloud era, on a mission to reinvent how businesses secure data, enable agile collaboration, and boldly pursue new business opportunities.
What you will do
- Own end-to-end lifecycle of external audits and certifications, including ISO 27001, SOC 2 Type 2, C5, PCI DSS, ISO 42001, and FedRAMP.
- Lead pre-engagement vendor security assessments and ongoing reassessments within hirify.global’s Third-Party Risk Management (TPRM) program.
- Lead formal policy exception process, including risk evaluation, compensating controls, and executive approval workflows.
- Facilitate periodic risk assessments across business units to identify and assess operational, technical, regulatory, and strategic risks.
- Oversee annual security awareness training program and develop targeted training modules for high-risk roles.
- Lead, mentor, and develop a team of 3–4 GRC analysts, defining career paths and professional development plans.
Requirements
- 7–10+ years of experience in GRC, security compliance, or audit leadership.
- 3+ years of people management experience.
- Deep expertise in ISO 27001, SOC 2 Type 2, PCI DSS, FedRAMP, C5, and ISO 42001 (or emerging AI governance frameworks).
- Strong understanding of cloud security environments (AWS, GCP, Azure).
- Proven experience building or maturing a third-party risk management program.
- Excellent executive communication and reporting skills.
Nice to have
- CISSP, CISA, CRISC, CISM, ISO 27001 Lead Implementer/Auditor, or similar certifications.
- Experience in SaaS or cloud-native environments.
- Experience preparing organizations for FedRAMP authorization.
- Familiarity with automation tools for GRC evidence collection and control monitoring.
Culture & Benefits
- Ability to work remotely, with office setup reimbursement.
- Competitive salary and unlimited PTO.
- Health, vision, and dental insurance, as well as life, short and long-term disability insurance.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →