GRC Manager - Associate

SMBC

Charlotte (NC)

On-site

USD 80,000 - 100,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

SMBC is seeking a Product Specialist for the GRC platform (SAI360) based in Charlotte, NC. This role involves designing, configuring, and improving governance, risk, and compliance capabilities while collaborating with business and technology stakeholders.

The Product Specialist will support the GRC processes and ensure alignment with regulatory obligations. The role allows for a hybrid work model, providing flexibility in work location.

Qualifications

  • 2+ years of experience configuring or maintaining enterprise GRC platforms.
  • Hands-on experience with web technologies for platform configuration.
  • Experience with data visualization tools for reporting.

Responsibilities

  • Lead configuration design workshops with stakeholders.
  • Translate business requirements into functional specifications.
  • Design dashboards using Power BI for management reporting.

Skills

GRC platform configuration
Web technologies (JavaScript, JSON, HTML, XML, SQL)
Data visualization (Power BI, Tableau)
Change management (JIRA, ServiceNow)
Stakeholder engagement

Tools

SAI360
Power BI
Vue.js

Job description

Role Description

This role serves as SMBC Americas Division Information Security’s Product Specialist for the organizational GRC platform (SAI360), responsible for the design, configuration, and continuous improvement of integrated governance, risk, and compliance capabilities.

The SAI360 platform supports core GRC functions including risk management, controls management, assessments, issue management, and regulatory compliance. This role will partner with business, risk, and technology stakeholders to translate regulatory and operational requirements into scalable system configurations and workflows. It also contributes to the standardization of control frameworks, risk taxonomies, and regulatory mappings to support consistent reporting and regulatory alignment across regions.

The Product Specialist is responsible for ensuring Information Security modules are effectively configured, integrated with upstream and downstream systems, and support efficient, audit‑ready processes.

Role Objectives

The Product Specialist delivers configuration, design, and support services for SAI360 users across Information Security and broader control functions. Key responsibilities include:

  • Lead and facilitate configuration design workshops with business, risk, and technology stakeholders
  • Translate business, regulatory, and control requirements into functional design specifications
  • Collaborate with the GRC Technology team to identify, configure, and enhance Information Security’s modules within SAI360 to improve functionality and user experience of GRC processes
  • Ensure the configurations and workflows within Information Security’s modules align with SMBC control standards, regulatory obligations, audit expectations and optimize end‑to‑end GRC workflows (risk assessments, control testing, issue management, regulatory mapping)
  • Support platform governance, including documentation, standards, and controls over system changes (e.g., JIRA) in collaboration with the GRC Technology team.

Reporting:

  • Design and configure dashboards and reports using SAI360‑integrated PowerBI capabilities to support risk, compliance, and management reporting
  • Ensure data integrity, completeness, and auditability within Information Security’s modules

Testing and Deployment:

  • Support user acceptance testing (UAT) and defect resolution
  • Coordinate releases and enhancements in alignment with GRC Technology’s change management processes
  • Ensure proper documentation and traceability of changes to support audit and regulatory review

Stakeholder Engagement and Training:

  • Serve as the primary point of contact for Information Security stakeholders interacting with SAI360 across business and control functions
  • Support Information Security module owners with the development and provision of training and guidance to end users, control owners, and administrators
Qualifications and Skills
  • 2+ years of experience configuring or maintaining enterprise GRC platforms (e.g., SAI360, ServiceNow, Archer)
  • Hands‑on experience working with web technologies used in GRC platforms with the ability to configure, troubleshoot, and implement changes directly within the platform (JavaScript, JSON, HTML, XML, and SQL; experience with Vue.js a plus)
  • Experience with data visualization tools (e.g., Power BI, Tableau) for risk and compliance reporting
  • Working experience with a change ticketing system (e.g., JIRA, ServiceNow)
  • Understanding of information/cyber security governance, risk management, and compliance (GRC) processes
  • Strong stakeholder engagement and communication skills across technical and non‑technical audiences
  • Strong attention to detail with focus on data integrity and audit readiness
Preferred Qualifications
  • Experience supporting information security / cybersecurity GRC, risk management, internal audit, or regulatory compliance
  • Experience working in financial services or a highly regulated environment
  • Exposure to control libraries, risk taxonomies, and regulatory mapping
  • Experience with workflow automation and integration (e.g., APIs, Power Platform)
  • Familiarity with regulatory expectations for information security in financial services (e.g., NYDFS Part 500, SEC, FFIEC Handbooks)
  • Working knowledge of cybersecurity control frameworks (e.g., NIST CSF, NIST 800‑53, CRI Profile, ISO 27001)
Additional Requirements

SMBC’s employees participate in a Hybrid workforce model that provides employees with an opportunity to work from home, as well as, from an SMBC office. SMBC requires that employees live within a reasonable commuting distance of their office location. Prospective candidates will learn more about their specific hybrid work schedule during their interview process. Hybrid work may not be permitted for certain roles, including, for example, certain FINRA‑registered roles for which in‑office attendance for the entire workweek is required.

SMBC provides reasonable accommodations during candidacy for applicants with disabilities consistent with applicable federal, state, and local law. If you need a reasonable accommodation during the application process, please let us know at accommodations@smbcgroup.com.

EOE, including Disability/veterans

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Platform Specialist (SAI360) — Hybrid
GRC Platform Specialist (SAI360) — Hybrid

SMBC • Charlotte (NC)

Hybrid
USD 80,000 - 100,000
Senior Governance, Risk, & Compliance Analyst
Senior Governance, Risk, & Compliance Analyst

Jobgether • United States

On-site
USD 58,000 - 222,000
Medical, dental, vision insurance
Flexible work environment
Paid time off
+1
GRC Specialist (Governance, Risk & Compliance)
GRC Specialist (Governance, Risk & Compliance)

360CyberX • United States

On-site
USD 70,000 - 90,000
Manager, Information Security GRC
Manager, Information Security GRC

Sutton Bank • Columbus (OH)

On-site
USD 110,000 - 170,000
Tech Lead
Tech Lead

SMBC Group • Charlotte (NC), Northern (KY)

Hybrid
USD 130,000 - 190,000
Hybrid work model
Principal Security GRC Analyst
Principal Security GRC Analyst

Jobgether • United States

On-site
USD 150,000 - 210,000
High autonomy
Multi-framework exposure
Cloud environment experience
GRC Consultant
GRC Consultant

NetCov • United States

On-site
USD 80,000 - 100,000
Cyber Security Analyst - Associate
Cyber Security Analyst - Associate

SMBC Group • Charlotte (NC)

Hybrid
USD 70,000 - 110,000
Hybrid work model
Security GRC Analyst
Security GRC Analyst

Socket.dev • United States

Remote
USD 90,000 - 120,000
Health insurance
401(k) with company match
Paid time off
Information Security Administrator, GRC - Boston
Information Security Administrator, GRC - Boston

Mintz • Boston (MA)

On-site
USD 85,000 - 100,000
Bonus eligible
Comprehensive benefits package