Governance, Risk & Compliance (GRC) Manager

Merci Technologies, Inc.

San Jose, Northern (CA, KY)

Hybrid

USD 140,000 - 210,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Merci Technologies is partnering with a client to seek a Governance, Risk & Compliance (GRC) Manager to lead enterprise cybersecurity governance, regulatory compliance, risk management, audit readiness, and security policy initiatives.

This role bridges security operations, executive leadership, auditors, regulators, and business stakeholders to drive a mature, scalable GRC program and ensure ongoing compliance across SOC 2, ISO 27001, NIST, HIPAA, PCI-DSS, and GDPR where applicable.

Qualifications

  • Bachelor’s degree or higher in a related field.
  • 7+ years of experience in information security, compliance, audit, or GRC.
  • Strong understanding of cybersecurity frameworks and regulatory requirements.
  • Experience managing SOC 2, ISO 27001, NIST CSF, or similar programs.
  • Ability to document, report, and communicate effectively.
  • Ability to work with executive leadership and auditors.

Responsibilities

  • Lead the organization's Governance, Risk, and Compliance program.
  • Develop and maintain cybersecurity policies, standards, and procedures.
  • Conduct enterprise security risk assessments and remediation planning.
  • Manage compliance initiatives such as SOC 2, ISO 27001, NIST, HIPAA, PCI-DSS, and GDPR where applicable.
  • Coordinate internal and external audits.
  • Develop and monitor security controls and compliance frameworks.
  • Oversee third-party risk management and vendor security assessments.
  • Create executive-level compliance and risk reporting dashboards.
  • Partner with Legal, IT, Security, HR, and Operations teams.
  • Maintain risk registers and ensure mitigation activities are tracked.
  • Support customer security reviews and due diligence requests.
  • Drive continuous improvement in governance and compliance processes.
  • Educate stakeholders on compliance obligations and cybersecurity risks.

Skills

GRC leadership
Policy development
Risk assessment
Audit readiness
Regulatory compliance
Stakeholder communication

Education

Bachelor's degree in Cybersecurity, Information Systems, Business, Risk Management, or related field

Tools

Archer
AuditBoard
ServiceNow GRC
Drata
Vanta
Secureframe

Job description

Location: Remote (U.S.) / Offshore/Nearshore
Employment Type: Full-Time
Experience: 7+ Years
Industry: Cybersecurity / Risk & Compliance

About the Opportunity

Merci Technologies is partnering with a client seeking an experienced Governance, Risk & Compliance (GRC) Manager to lead enterprise cybersecurity governance, regulatory compliance, risk management, audit readiness, and security policy initiatives.

This role is ideal for a cybersecurity leader who can bridge the gap between security operations, executive leadership, auditors, regulators, and business stakeholders.

Key Responsibilities
  • Lead the organization's Governance, Risk, and Compliance (GRC) program.
  • Develop and maintain cybersecurity policies, standards, and procedures.
  • Conduct enterprise security risk assessments and remediation planning.
  • Manage compliance initiatives including SOC 2, ISO 27001, NIST, HIPAA, PCI-DSS, and GDPR where applicable.
  • Coordinate internal and external audits.
  • Develop and monitor security controls and compliance frameworks.
  • Oversee third-party risk management and vendor security assessments.
  • Create executive-level compliance and risk reporting dashboards.
  • Partner with Legal, IT, Security, HR, and Operations teams.
  • Maintain risk registers and ensure mitigation activities are tracked.
  • Support customer security reviews and due diligence requests.
  • Drive continuous improvement in governance and compliance processes.
  • Educate stakeholders on compliance obligations and cybersecurity risks.
Required Qualifications
  • Bachelor's degree in Cybersecurity, Information Systems, Business, Risk Management, or related field.
  • 7+ years of experience in information security, compliance, audit, or GRC.
  • Strong understanding of cybersecurity frameworks and regulatory requirements.
  • Experience managing SOC 2, ISO 27001, NIST CSF, or similar programs.
  • Experience conducting risk assessments and control evaluations.
  • Knowledge of third-party risk management methodologies.
  • Strong documentation, reporting, and communication skills.
  • Ability to work effectively with executive leadership and auditors.
Preferred Qualifications
  • CISSP, CISM, CISA, CRISC, Security+, or similar certifications.
  • Experience with GRC platforms such as Archer, AuditBoard, ServiceNow GRC, Drata, Vanta, or Secureframe.
  • Experience supporting cloud environments (Azure, AWS, or GCP).
  • Background in cybersecurity governance and security operations.
  • Experience in highly regulated industries.
Why Join This Opportunity?
  • Lead enterprise-wide cybersecurity governance initiatives.
  • Influence security strategy and business risk decisions.
  • Work closely with executive leadership and external auditors.
  • Help shape a mature and scalable cybersecurity compliance program.
  • Support an organization committed to security, governance, and operational excellence.
About Merci Technologies

Merci Technologies partners with organizations across multiple industries to identify and deliver exceptional talent in Cybersecurity, Cloud, Artificial Intelligence, Data & Analytics, Digital Transformation, Risk & Compliance, and Enterprise Technology.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Remote GRC Leader - Cybersecurity Governance & Compliance
Remote GRC Leader - Cybersecurity Governance & Compliance

Merci Technologies, Inc. • San Jose (CA), Northern (KY)

Hybrid
USD 140,000 - 210,000
Manager, Information Security Governance, Risk & Compliance (GRC)
Manager, Information Security Governance, Risk & Compliance (GRC)

Burtch Works • United States

Remote
USD 140,000 - 170,000
Health and wellness benefits
Remote, US-based work
GRC (Governance, Risk, and Compliance) Consultant
GRC (Governance, Risk, and Compliance) Consultant

Zoho • United States

Remote
USD 120,000 - 180,000
Global Security Governance, Risk & Compliance Manager (Remote)
Global Security Governance, Risk & Compliance Manager (Remote)

Barnes Aerospace • United States

Remote
USD 140,000 - 190,000
Governance, Risk, & Compliance (GRC) Analyst
Governance, Risk, & Compliance (GRC) Analyst

Districttechgroup • Washington

On-site
USD 80,000 - 100,000
Fully remote work environment
Competitive salary and performance bonuses
Health, dental, and vision insurance
+2
GRC Consultant
GRC Consultant

Cyberr • United States

On-site
USD 90,000 - 130,000
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta-Denta • St. Louis (MO)

On-site
USD 75,000 - 110,000
Information Technology Governance Manager
Information Technology Governance Manager

Northwest Partners • United States

On-site
USD 90,000 - 130,000
Health Insurance
Vision Insurance
Dental Insurance
+4
GRC Analyst
GRC Analyst

The Emery Company, LLC • Houston (TX)

On-site
USD 85,000 - 110,000
Cybersecurity Governance Analyst
Cybersecurity Governance Analyst

Veriipro • Fort Lauderdale (FL)

On-site
USD 90,000 - 130,000