GRC Manager (Third-Party IT Risk)

Pinnacle Group, Inc.

Dallas (TX)

On-site

USD 140,000 - 180,000

Full time

30 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Medical Insurance
Dental Insurance
Vision Insurance
401K Contributions
Paid Time Off

Job summary

Pinnacle Group is seeking a GRC Manager – Technology Risk & Governance to own and mature governance, risk, and compliance programs. You will lead third-party risk management, oversee ISO 27001 and SOC 2 compliance in partnership with IT, and collaborate on AI risk governance across the organization.

The role requires strong experience in technology risk, vendor assessments, and security frameworks, with the ability to influence stakeholders and drive risk initiatives at scale.

Qualifications

  • Bachelor’s degree in a related field.
  • Experience in technology risk, governance, compliance, or a related discipline.
  • Vendor risk assessments for SaaS platforms, cloud providers, MSPs, software vendors, and AI-enabled products.
  • Working knowledge of ISO 27001, SOC standards, NIST, CIS Controls, and related governance practices.
  • Ability to communicate findings clearly to technical and non-technical stakeholders.

Responsibilities

  • Own and manage third-party risk management program across vendor lifecycle.
  • Partner with security, legal, compliance, IT, and business stakeholders to assess and mitigate risks.
  • Review SOC 1/2, ISO 27001, penetration tests, BCP/DR, privacy materials, and evidence.
  • Interface with auditors, vendors, and stakeholders to respond to assessment requests.
  • Support responses to third-party questionnaires with accurate, complete documentation.
  • Maintain organized risk and compliance records per internal policies.
  • Prepare risk summaries, dashboards, and governance materials for leadership.
  • Maintain ISO 27001 certification and SOC 2 readiness with IT teams.
  • Collaborate on AI risk governance standards and procedures.
  • Enhance business continuity plans with cross-functional input.

Skills

Technology risk
Governance
Compliance
Vendor risk assessments
Audit support
Communication skills
AI risk governance

Education

Bachelor’s degree in Business Information Systems, Cybersecurity, Risk Management, Compliance, or a related field

Tools

Drata

Job description

Pinnacle Group is seeking a GRC Manager – Technology Risk & Governance to own, manage, and mature key governance, risk, and compliance programs across the organization. This role will oversee third-party risk management, technology risk, compliance readiness, AI risk governance, business continuity, and audit support. The ideal candidate brings hands‑on experience in technology risk, vendor assessments, security frameworks, and compliance programs, with the ability to lead initiatives, influence stakeholders, and support future growth within the risk function.

Job Description
  • Own and manage the third-party risk management program, including risk-based vendor assessments, onboarding reviews, and periodic evaluations throughout the vendor lifecycle.
  • Partner with Information Security, Legal, Compliance, IT, and business stakeholders to identify, assess, document, and mitigate technology, cybersecurity, privacy, AI, and vendor-related risks.
  • Review SOC 1 and SOC 2 reports, ISO 27001 certifications, penetration testing reports, business continuity plans, disaster recovery documentation, privacy materials, and related compliance evidence.
  • Interface with third-party auditors, vendors, and internal stakeholders to gather documentation, respond to assessment requests, and support audit readiness.
  • Support responses to technology-related third-party questionnaires, ensuring information is accurate, complete, consistent, and professionally documented.
  • Maintain organized assessment records, risk documentation, compliance evidence, and supporting materials in accordance with internal policies and procedures.
  • Prepare risk summaries, dashboards, reports, and governance materials for leadership and committee review.
  • Maintain and support Pinnacle Group’s ISO 27001 certification and SOC 2 compliance in partnership with IT and other key stakeholders.
  • Collaborate with cross-functional teams to create, maintain, and implement AI-related standards, procedures, and risk governance practices.
  • Enhance and maintain Pinnacle Group’s business continuity plan in collaboration with appropriate business and technology stakeholders.
Requirements
  • Bachelor’s degree in Business Information Systems, Cybersecurity, Risk Management, Compliance, or a related field.
  • Experience in technology risk, governance, compliance, information security, audit, third-party risk management, or a related discipline.
  • Strong experience performing vendor risk assessments for SaaS platforms, cloud providers, managed service providers, software vendors, and AI-enabled products.
  • Working knowledge of security and compliance frameworks such as ISO 27001, SOC standards, NIST, CIS Controls, and related governance practices.
  • Experience interfacing with third-party auditors and responding to security, risk, compliance, or vendor assessment questionnaires.
  • Ability to assess technology vendors, identify risk concerns, document findings, and communicate recommendations clearly to technical and non-technical stakeholders.
  • Strong written and verbal communication skills with the ability to collaborate effectively across auditors, vendors, IT, Legal, Compliance, and business teams.
  • Experience using Drata or similar governance, risk, and compliance platforms preferred.
  • Working knowledge of AI-related risks, controls, governance standards, and emerging compliance considerations preferred.
Why Join Pinnacle Group?

At Pinnacle Group, you will have the opportunity to make a meaningful impact by strengthening risk governance, compliance readiness, and operational resilience across the organization. This role offers visibility across key business functions and the ability to influence how technology, vendor, AI, and compliance risks are managed at scale. You will join a collaborative, values-driven environment that supports professional growth, ownership, and continuous improvement.

During the hiring process, we may use artificial intelligence (AI) tools to assist in evaluating information related to your application. These tools may help analyze job‑related qualifications or assist recruiters in reviewing applications and interview responses. AI-generated information is one factor considered in our hiring process. Final employment decisions are made by qualified hiring personnel and are not based solely on AI-generated recommendations.

Compensation and Benefits Disclosure

The specific compensation for this position will be determined by a number of factors, including the scope, complexity and location of the role as well as the cost of labor in the market; the skills, education, training, credentials and experience of the candidate; and other conditions of employment. Our full-time consultants have access to benefits including medical, dental, vision and 401K contributions as well as any other PTO, sick leave, and other benefits mandated by appliable state or localities where you reside or work.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

GRC Manager, Tech Risk & AI Governance
GRC Manager, Tech Risk & AI Governance

Pinnacle Group, Inc. • Dallas (TX)

On-site
USD 140,000 - 180,000
Medical Insurance
Dental Insurance
Vision Insurance
+2
Principal/Senior Technology Risk Analyst
Principal/Senior Technology Risk Analyst

Berkshire Hathaway Specialty Insurance • Boston (MA)

On-site
USD 140,000 - 170,000
Health, Dental, Vision
Disability Insurance
Life Insurance
+8
GRC Specialist II
GRC Specialist II

Scigon Solutions, Inc. • Salt Lake City (UT)

On-site
USD 116,000 - 144,000
Governance Analyst
Governance Analyst

Tri-Force Consulting Services Inc. | IT Recruitment & Staffing Agency • Philadelphia

Hybrid
USD 110,000 - 140,000
Program Manager - GRC
Program Manager - GRC

Astreya • Santa Clara (CA)

On-site
USD 150,000 - 230,000
Principal GRC Business Engineer
Principal GRC Business Engineer

Palo Alto Networks, Inc. • Santa Clara (CA)

On-site
USD 168,000 - 271,000
GRC Manager
GRC Manager

G2 Crowd, Inc. • Chicago (IL)

On-site
USD 120,000 - 131,000
Flexible work
Parental leave
Unlimited PTO
Senior Analyst, GRC
Senior Analyst, GRC

Procore Technologies • Austin (TX)

On-site
USD 112,000 - 154,000
Equity compensation
Bonus incentive
Manager - IT Governance, Risk and Compliance
Manager - IT Governance, Risk and Compliance

Plexus Corp. • Neenah (WI)

On-site
USD 112,600 - 169,000
Sr Manager - IT Governance, Risk and Compliance
Sr Manager - IT Governance, Risk and Compliance

Plexus Corp • Neenah (WI)

On-site
USD 130,000 - 194,000
Medical insurance
Dental insurance
Vision insurance
+3