GRC & Compliance Manager — Audit Readiness

Accela, Inc.

United States

Remote

USD 150,000 - 170,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Accela, Inc. is seeking a Manager, Governance, Risk, and Compliance to own security governance, risk, compliance, audit, and customer trust programs across SOC 2, ISO 27001, GovRAMP, PCI DSS, HIPAA, NIST CSF, NIST 800-53, CCPA/GDPR, and related requirements.

You will partner with Security, Legal, IT, Engineering, Product, Finance, People, and customer-facing teams to ensure regulatory and customer trust obligations are met, lead audit readiness, and drive continuous improvement of the GRC

Qualifications

  • 6+ years of experience in security governance, risk management, compliance, audit, or related cybersecurity roles.
  • Experience managing or supporting audits and compliance programs for SOC 2, ISO 27001, GovRAMP, PCI DSS, HIPAA, NIST 800-53, or similar frameworks.
  • Strong understanding of security controls, policy management, risk assessment, control testing, evidence collection, and audit readiness practices.
  • Experience working with auditors, customers, internal stakeholders, and executive leadership.
  • Experience managing third-party risk or vendor security review programs.
  • Ability to translate complex compliance obligations into practical business and technical requirements.
  • Strong project management skills with the ability to manage multiple audits, risks, remediation efforts, and stakeholder workstreams simultaneously.
  • Excellent written and verbal communication skills.

Responsibilities

  • Lead the governance, risk, and compliance function across security policies, standards, risk management, audits, third‑party risk, and control operations.
  • Develop, maintain, and operationalize global security policies, standards, procedures, control documentation, and exception processes.
  • Own audit readiness and ongoing compliance programs across frameworks such as SOC 2, ISO 27001, GovRAMP, PCI DSS, HIPAA, NIST CSF, NIST 800-53, CCPA/GDPR, and other customer or regulatory requirements.
  • Lead GovRAMP and PCI DSS readiness, including control mapping, evidence collection, remediation tracking, stakeholder coordination, audit preparation, and audit support.
  • Coordinate audit evidence collection, control testing, remediation tracking, auditor communication, and management responses.
  • Maintain the security risk register, including identification, assessment, ownership, remediation, acceptance, exception tracking, and executive reporting of security risks.
  • Partner with control owners across Security, IT, Engineering, Legal, HR, Finance, Product, and Operations to ensure control effectiveness and accountability.
  • Manage third-party and supply chain risk management, including vendor security reviews, due diligence, risk assessments, contract security input, and remediation tracking.
  • Support customer security reviews, questionnaires, trust center content, security documentation, and customer-facing compliance responses.
  • Develop metrics and dashboards for audit status, control health, risk posture, vendor risk, policy exceptions, compliance readiness, and remediation progress.
  • Support incident response and privacy incident processes by ensuring regulatory, contractual, audit, and customer notification obligations are understood and tracked.
  • Partner with the CISO to communicate security posture, compliance progress, key risks, control gaps, and trade-offs to executives, customers, auditors, and regulators.
  • Drive continuous improvement of the GRC operating model, including automation, evidence reuse, control rationalization, risk prioritization, and policy lifecycle management.

Skills

Security governance
Risk management
Compliance
Audit readiness
Third-party risk
Policy management
Project management
Communication

Tools

GRC platforms
Trust centers
Vendor risk platforms
Control automation tools

Job description

Accela, Inc. is seeking a Manager, Governance, Risk, and Compliance to own security governance, risk, compliance, audit, and customer trust programs across SOC 2, ISO 27001, GovRAMP, PCI DSS, HIPAA, NIST CSF, NIST 800-53, CCPA/GDPR, and related requirements.

You will partner with Security, Legal, IT, Engineering, Product, Finance, People, and customer-facing teams to ensure regulatory and customer trust obligations are met, lead audit readiness, and drive continuous improvement of the GRC

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Engineering Manager: Lead Secure Cloud Compliance
GRC Engineering Manager: Lead Secure Cloud Compliance

Workstreet • Northern (KY)

Hybrid
USD 150,000 - 190,000
Career Development
Role-Related Training
Competitive Compensation
+2
GRC & Security Compliance Lead
GRC & Security Compliance Lead

Neura Market • San Francisco (CA)

On-site
USD 140,000 - 190,000
Equity
Medical, dental, and vision coverage
Flexible PTO
+4
Senior GRC Program Lead - SOC 2, GDPR & Security
Senior GRC Program Lead - SOC 2, GDPR & Security

Tandem Inc. • Draper (UT)

Hybrid
USD 110,000 - 170,000
On-site gym
Flexible PTO
Redo perks: monthly ecommerce credit
+2
Senior GRC & Compliance Strategist
Senior GRC & Compliance Strategist

B Capital • San Francisco (CA)

On-site
USD 140,000 - 200,000
Senior GRC Lead — Build Compliance that Drives Confidence
Senior GRC Lead — Build Compliance that Drives Confidence

ClearData Networks, Inc. in • Raleigh (NC)

On-site
USD 130,000 - 170,000
Opportunity to learn
Vacation + personal days
Employee stock ownership
+2
Security GRC Engineer: Risk, Audit & Compliance
Security GRC Engineer: Risk, Audit & Compliance

Whatnot • Seattle (WA)

On-site
USD 175,000 - 230,000
Health Insurance options including US
Work From Home support
Home office setup allowance
+5
GRC Lead for AI Security: SOC 2 & ISO 27001
GRC Lead for AI Security: SOC 2 & ISO 27001

Replit • Foster City (CA)

On-site
USD 180,000 - 240,000
401(k) program
Health insurance
Dental insurance
+10
Security Compliance, Audit & Architecture Lead
Security Compliance, Audit & Architecture Lead

Accenture • City of Albany (NY)

On-site
USD 87,000 - 294,000
Health insurance
401(k) plan
Bonus opportunities
Governance, Risk and Compliance (GRC) Lead - 249079
Governance, Risk and Compliance (GRC) Lead - 249079

Medix Technology • Northfield Township (IL)

On-site
USD 90,000 - 130,000
GRC Risk & Compliance Manager | Equity & Impact
GRC Risk & Compliance Manager | Equity & Impact

WHOOP • Boston (MA)

On-site
USD 155,000 - 195,000