Назад
Company hidden
4 дня назад

GRC Program Manager

90 000 - 160 000$
Формат работы
hybrid
Тип работы
fulltime
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
GRC Program Manager (Governance, Risk, and Compliance): Designing and scaling compliance processes across commercial, international, and US Government environments with an accent on audit coordination, regulatory frameworks, and risk management. Focus on tracking FedRAMP, SOC 2, and ISO 27001 deliverables, resolving cross-team blockers, and building compliance operations for USG-regulated environments.

Location: New York, NY; hybrid work and based within a commutable distance of the local hirify.global office are required.

Salary: $90,000–$160,000 per year, plus potential restricted stock units, sign-on bonus, and other incentives.

Company

hirify.global builds software for data-driven decisions and operations used by commercial, international, and government organizations.

What you will do

  • Design, document, and improve GRC processes and compliance frameworks across commercial, international, and US Government environments.
  • Translate regulatory requirements into actionable workflows and coordinate accountability across the compliance lifecycle.
  • Coordinate FedRAMP, SOC 2, ISO 27001, and other internal and external audit cycles, including evidence collection and remediation tracking.
  • Track audit timelines, control implementation, continuous monitoring obligations, and project risks.
  • Collaborate with engineering, legal, customer-facing teams, auditors, and regulators to deliver compliance programs and product certifications.
  • Support adoption, rollout, and ongoing use of compliance-related product features.

Requirements

  • Demonstrated success managing compliance programs for an enterprise software company, startup, or similar organization.
  • Experience with multiple GRC frameworks, including SOC 2, ISO 27001, IRAP, ENS, FedRAMP, NIST 800-53, DoD CC SRG, FISMA, or CMMC.
  • Experience building and scaling compliance processes, particularly in US Government-regulated environments.
  • Experience with risk registers, risk assessments, and third-party or vendor risk programs.
  • Strong project management, stakeholder communication, judgment, composure, and attention to detail.
  • Willingness and eligibility to obtain a U.S. security clearance is preferred.

Culture & Benefits

  • Hybrid work options are available for many teams, generally allowing work from home one or two days per week.
  • Medical, dental, vision, life, AD&D, and disability insurance options.
  • Paid time off, year-end paid leave, and 10 paid holidays.
  • Parental leave, backup care, fertility and family-building benefits, and a new-child stipend.
  • Commuter benefits and access to a 401(k) plan.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →