Source Job

Brazil

  • Lead the GRC strategy, shifting from bureaucratic to strategic enabler focused on real business risk.
  • Manage cyber risk quantification, third-party risk, and continuous compliance programs.
  • Oversee information security governance, AI governance, and IAM governance, reporting to the CISO.

GRC Information Security Risk Management Cloud Security AI Governance

20 jobs similar to Information Security Manager - GRC

Jobs ranked by similarity.

$110,100–$143,100/yr
North America

  • Defines program goals, governance frameworks, and measurable objectives for cyber risk and compliance programs.
  • Manages user attestations, third-party risk, cyber contract negotiation, and coordination of IT audits/assessments.
  • Implements GRC tooling and monitors program effectiveness through KPIs, QA reviews, and control testing.

Velera is a credit union service organization providing fintech solutions to over 4,000 financial institutions. The company fosters a remote-first, inclusive culture with a focus on employee wellbeing and belonging.

India

  • Design and implement a structured risk management program including risk taxonomy and scoring methodology.
  • Build and maintain the enterprise risk register as a living operational tool.
  • Leverage AI tools to monitor threat intelligence and accelerate risk analysis.

AlphaSense provides AI-driven market intelligence and search to help companies make smarter decisions. Founded in 2011, the company has over 2,000 employees globally and is headquartered in New York City.

$127,200–$205,100/yr
Global Unlimited PTO

  • Own and continuously improve Camunda's Information Security Management System (ISMS), driving measurable improvements.
  • Drive security audit cycles for ISO 27001, SOC 2, and future frameworks with minimal supervision.
  • Review information security requirements in customer contracts and lead responses to complex security questionnaires.

We are the enterprise platform for agentic orchestration, enabling organizations to coordinate AI agents, people, and systems across complex business processes. We are a fully remote, global team trusted by over 700 organizations, named a GP Bullhound Next Unicorn and Great Place to Work certified.

US 24w maternity 24w paternity

  • Own the end-to-end GRC strategy and roadmap, driving compliance maturity and reducing audit risk.
  • Design and implement policy-as-code systems, translating compliance frameworks into enforceable code.
  • Lead full audit cycles, manage evidence collection, and architect GRC platform strategy for continuous compliance.

Smartsheet empowers teams to manage work and scale solutions, now uniting human teams with AI agents to automate tasks and uncover insights. With a history of over 20 years, the company fosters a culture of inclusion, creativity, and big thinking, offering professional growth and a supportive environment.

US 4w PTO

  • Own and continuously mature the company risk register, designing AI-assisted workflows for real-time risk posture.
  • Lead external audit management (SOC 2 Type II) and automate evidence collection pipelines in Vanta.
  • Engineer the Trust and Assurance program for scale, including automated vendor risk intake and AI-assisted response generation.

ButterflyMX empowers people to open and manage doors & gates from a smartphone, with products installed in over 20,000 properties worldwide. As a distributed, primarily remote workforce, they seek intelligent, passionate, and collaborative individuals driven by shared commitment to excellence and innovation.

$60,000–$60,000/yr
Argentina Mexico Brazil Chile Uruguay Colombia Ecuador

  • Lead customer security reviews, RFPs, RFIs, and questionnaires to keep deals moving.
  • Own SOC 2 Type II program management and the customer-facing trust portal.
  • Author security policies and manage AI compliance frameworks.

Sparkrock helps social benefit organizations like nonprofits, school boards, and government agencies reach their full potential through technology. They are a best-in-class, 100% remote organization with a focus on culture and growth, serving over 150,000 users.

US

  • Lead the design and governance of control frameworks and risk workflows within the GRC platform, ensuring alignment with compliance requirements like HIPAA, HITRUST, and NIST.
  • Oversee risk assessments, control testing, and vendor evaluations to identify and mitigate security risks.
  • Manage policy lifecycle, audit coordination, and reporting on control effectiveness and risk indicators.

USAP is a healthcare organization focused on providing anesthesia services and patient safety. It is a growing company with a culture of security, compliance, and collaboration.

$133,109–$239,596/yr
Global Unlimited PTO

  • Act as a trusted advisor to business leaders, bridging security risks and business priorities.
  • Lead security assessments, risk reviews, and remediation planning for new products and enterprise changes.
  • Maintain clear visibility of security risk, control health, metrics, and dashboards, escalating when needed.

Experian is a global data and technology company, powering opportunities for people and businesses around the world. With a team of 25,200 people in 32 countries, they foster an inclusive, purpose-driven culture and have been recognized as a World's Best Workplace in 2025.

Europe 5w PTO

  • Own and drive the compliance roadmap across multiple frameworks like ISO 27001, TISAX, and SOC 2.
  • Implement ISO 27001 end-to-end for customers and mentor junior compliance specialists.
  • Act as the senior compliance voice for customers, auditors, and product, partnering with CS and founders.

Secfix automates security compliance in Europe, helping companies achieve ISO 27001, GDPR, TISAX, and SOC 2 quickly and easily. We are a 100% remote team with hubs in Munich, Berlin, and London, backed by top VCs with a high-performing, ownership-driven culture.

Brazil

  • Manage and monitor vulnerability management processes to identify and mitigate risks.
  • Investigate security events and support incident response and containment activities.
  • Contribute to SIEM operations, IAM initiatives, and AWS cloud security enhancements.

Our partner is a fast-growing company focused on innovation, operating in the cybersecurity space. They foster a dynamic, collaborative culture with a focus on remote work and employee well-being.

LATAM

  • Coordinate governance activities for strategic Technology and Cybersecurity programs in LATAM.
  • Support the Vulnerability Management Program and M&A technology integration initiatives.
  • Develop KPIs, dashboards, and executive reports to drive risk-based decision-making.

Experian is a global data and technology company that drives opportunities for people and businesses worldwide. With 25,200 employees in 32 countries, the company is people-centric, inclusive, and recognized as a top workplace.

$115,000–$145,000/yr
Global

  • Serve as a hands-on GRC advisor for customers, guiding them through risk assessments, audit preparation, and control rollouts.
  • Help customers navigate audits like SOC 2, ISO 27001, HIPAA, PCI-DSS, and NIST, translating requirements into practical steps.
  • Spot GRC complexity early and partner with Support and Customer Success to own escalations requiring real GRC expertise.

Compyl is a GRC and automated security compliance platform built by security practitioners. Backed by Venture Guides, Contour Venture Partners, and Armory Square Ventures, it is a high-growth Series A company.

Global 5w PTO

  • Own and automate our GRC program, including SOC 2 audits, risk assessments, and vendor security reviews.
  • Drive internal security across identity, device management, access reviews, and incident response.
  • Build customer-facing trust resources and coordinate product security audits with engineering.

Close builds a communication-first, AI-powered CRM designed to simplify sales for small businesses. The bootstrapped and profitable company has a 120-person, 100% remote team focused on helping customers scale.

$150,000–$170,000/yr
US Unlimited PTO

  • Lead the governance, risk, and compliance function across security policies, standards, risk management, audits, and third-party risk.
  • Own audit readiness and ongoing compliance programs across frameworks such as SOC 2, ISO 27001, GovRAMP, PCI DSS, HIPAA, NIST CSF, and more.
  • Manage third-party and supply chain risk management, including vendor security reviews, due diligence, and remediation tracking.

Accela provides government software solutions to improve efficiency, increase citizen engagement, and enable thriving communities. They have been an industry leader for nearly 20 years and are committed to diversity, equity, and inclusion.

US

  • Lead GRC initiatives to protect the business and strengthen technology risk posture.
  • Translate complex risk data into clear insights and action plans for leadership.
  • Build and improve policies, standards, and procedures for governance and compliance.

Herbalife is a global nutrition company focused on developing and distributing dietary supplements and personal care products. The company employs thousands worldwide and fosters a collaborative, fast-paced environment with a culture of accountability and continuous improvement.

$70,000–$77,000/yr
US

  • Perform enterprise risk assessments using NIST CSF, SOC 2, and CIS frameworks.
  • Develop and execute security awareness programs including training and phishing simulations.
  • Support governance and control management by maintaining policies and control libraries.

Protective helps protect customers against life's uncertainties by providing insurance and peace of mind. The company offers a collaborative environment with a focus on employee wellbeing and work-life balance.

Brazil

  • Perform testing and validation of ITGC and security controls.
  • Assess control effectiveness and support remediation efforts.
  • Support internal and external audits including SOC 2 and ISO 27001.

Marlabs is a global AI and Digital Solutions Consulting firm that delivers intelligent solutions across AI, data, analytics, and product engineering. Since 2000, they have partnered with large organizations worldwide, fostering a culture of innovation and collaboration.

US 5w PTO

  • Take ownership of building and scaling comprehensive security, privacy, and compliance programs that protect customer data.
  • Lead compliance initiatives such as SOC 2 Type 2 audits and evaluate additional frameworks like ISO 27001 and HIPAA.
  • Build scalable automated security processes by replacing manual tasks with scripts, APIs, and AI-powered solutions.

Our partner is a technology company focused on building secure, scalable systems. They operate with a remote, collaborative culture emphasizing ownership, transparency, and continuous improvement, with around 50–300 employees.

US 3w PTO

  • Lead and advance governance, risk management, compliance, and information security programs to support organizational objectives and regulatory requirements.
  • Manage vulnerability management, third-party risk, security governance, policy development, and AI governance initiatives.
  • Partner with leaders to foster a culture of accountability, risk awareness, and continuous improvement.

Ultimate Medical Academy is a non-profit healthcare educational institution with a national presence, headquartered in Tampa, Florida and founded in 1994. The organization offers online and on-campus programs and fosters a culture of integrity, student success, and team member development.

Brazil

  • Support the design, assessment, and improvement of IT controls to strengthen technology governance and compliance.
  • Perform testing and validation of ITGC, security controls, and QMS controls, and assist with audit activities.
  • Collaborate with Engineering, Security, Product, Risk, and Quality teams to drive continuous improvement and risk management.

A global technology organization focused on digital environment and security. They operate with cross-functional teams across engineering, security, risk, and product.