Sr Manager, InfoSec Governance Risk and Compliance (GRC) San Francisco Bay Area, California, Un[...]

Ivalua

San Francisco (CA)

On-site

USD 112,000 - 208,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Medical benefits
Dental benefits
Vision benefits
Transportation benefits

Job summary

A leading cloud-based procurement solutions provider is seeking a Manager, InfoSec Governance Risk and Compliance (GRC) to lead a global team and own the GRC program. Responsibilities include managing compliance audits, serving as a security subject-matter expert, and collaborating with multiple teams to enhance security posture. Ideal candidates will have significant experience in GRC and managing security frameworks, along with strong communication skills. The position offers competitive compensation in San Francisco.

Qualifications

  • At least 7+ years of proven experience leading GRC programs and managing compliance certifications.
  • At least 3+ years as a direct leader managing a team in a global setting.
  • Strong knowledge of security frameworks including NIST SP 800-53 and FedRAMP.

Responsibilities

  • Lead the Governance, Risk, and Compliance (GRC) program globally.
  • Manage compliance efforts and audits for certifications.
  • Serve as the subject-matter expert on security frameworks.

Skills

GRC program leadership
Management of compliance certifications
Knowledge of security frameworks
Analytical and problem-solving skills
Interpersonal and communication skills
Project management skills

Education

Bachelor's degree in a related field

Job description

Manager, InfoSec Governance Risk and Compliance (GRC)

Manager, InfoSec Governance Risk and Compliance (GRC)

Founded in 2000, Ivalua is a leading global provider of cloud-based procurement solutions.

Company Overview

At Ivalua we are a global community of exceptional professionals who believe that digital transformation revolutionizes supply chain sustainability and resiliency. Our cloud-based spend management platform empowers brands to manage spend, improve ESG performance, lower risk, and boost productivity.

Role

We are looking for an experienced InfoSec Governance Risk and Compliance (GRC) Manager to lead a global team and own the GRC program worldwide. Reporting to InfoSec leadership, you will manage and develop a high‑performing team, drive compliance efforts, and serve as a subject matter expert on security frameworks and standards.

What You Will Do
  • Lead and own the Governance, Risk, and Compliance (GRC) program globally, managing and developing a high‑performing team.
  • Manage and drive compliance efforts and audits for certifications such as FedRAMP, IRAP, ISO 27001, HIPAA, SOC1/SOC2, PCI DSS and others.
  • Serve as the subject‑matter expert on security frameworks and standards including NIST SP 800‑53 Rev 5, NIST 800‑171, ITAR, FedRAMP, PCI DSS, SOC2, etc., providing guidance to internal stakeholders.
  • Efficiently manage and respond to customer security audit and compliance requests in a timely manner.
  • Maintain continuous compliance and monitoring of security controls to ensure ongoing adherence to standards.
  • Collaborate closely with Sales, Marketing, and Customer Success teams to communicate Ivalua’s security posture to prospects and customers.
  • Review and negotiate information security exhibits and contractual terms in partnership with the legal team.
  • Lead the Security Awareness and Training program to promote a culture of security across the organization.
  • Track, manage, and drive remediation efforts for control deficiencies and gaps identified through internal and external audits.
  • Oversee the Third‑Party Risk and Vendor Security Assessment program to mitigate supply chain risks.
  • Develop, maintain, and enforce InfoSec policies, standards, and plans.
Your Profile

If you have the below experience and strengths this role could be for you:

Skills and Experience
  • At least 7+ years of proven experience leading GRC programs and managing compliance certifications and audits (FedRAMP, ISO 27001, HIPAA, SOC1/SOC2, PCI DSS, IRAP, etc.).
  • At least 3+ years experience as a direct leader, managing a team. The position will be part of an established global team with opportunity to grow the team.
  • Strong knowledge of security frameworks such as NIST SP 800‑53, NIST 800‑171, ITAR, PCI DSS, SOC2, and FedRAMP.
  • Demonstrated ability to manage and influence stakeholders across multiple departments and time zones.
  • Excellent project management, analytical, and problem‑solving skills with keen attention to detail.
  • Strong interpersonal and communication skills, capable of building trust and managing conflicts effectively.
  • Self‑motivated with a high degree of initiative and ability to work independently.
  • Ability to handle multiple competing priorities and deadlines efficiently.
  • Bachelor’s degree in related field preferred or equivalent experience with proven skills.
Soft Skills
  • Excellent interpersonal, communication, and organizational skills.
  • Team player with the ability to interface effectively with a broad range of individuals and roles, including IT and vendors.
  • High degree of initiative, dependable, and able to work well with limited supervision.
Equal Employment Opportunity

As set forth in Ivalua’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Compensation

Title: Manager, InfoSec Governance Risk and Compliance (GRC)

Range minimum: USD 112,000

Range maximum: USD 208,000

Additional compensation / rewards: Ivalua also offers exceptional benefits including medical, dental, vision and transportation.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr Manager, InfoSec Governance Risk and Compliance (GRC) Pittsburgh, Pennsylvania, United States
Sr Manager, InfoSec Governance Risk and Compliance (GRC) Pittsburgh, Pennsylvania, United States

Ivalua • Pittsburgh

On-site
USD 112,000 - 208,000
Medical benefits
Dental benefits
Vision benefits
+1
Lead Global GRC & Security Compliance Program
Lead Global GRC & Security Compliance Program

Ivalua • Pittsburgh

On-site
USD 112,000 - 208,000
Medical benefits
Dental benefits
Vision benefits
+1
GRC Manager
GRC Manager

Valence • United States

Hybrid
USD 130,000 - 190,000
WFH stipend
Phone stipend
Workspace support
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Icehouseventures • San Francisco (CA)

On-site
USD 135,000 - 165,000
Comprehensive health coverage
Flexible PTO
Equity package
Strategic Account Manager
Strategic Account Manager

Socket.dev • Pittsburgh

Hybrid
USD 113,000 - 188,000
Hybrid work model
Medical, dental, vision
Retirement plan
+2
Services Advisory Lead
Services Advisory Lead

Socket.dev • New York (NY)

Hybrid
USD 105,000 - 195,000
Hybrid work model
Competitive compensation package
Professional development programs
Strategic Account Manager
Strategic Account Manager

Socket.dev • New York (NY)

On-site
USD 113,000 - 188,000
Hybrid work model (3 days in office)
Annual bonus
Medical, dental, vision, retirement
Services Advisory Lead
Services Advisory Lead

Ivalua • New York (NY)

Hybrid
USD 105,000 - 195,000
Hybrid work model
Competitive benefits
Career development opportunities
Solution Consultant
Solution Consultant

Socket.dev • Redwood City (CA)

Hybrid
USD 105,000 - 175,000
Hybrid working model (3 days in office
Strategic Account Manager New Pittsburgh, PA - US
Strategic Account Manager New Pittsburgh, PA - US

Ivalua • Pittsburgh, Northern (KY)

On-site
USD 113,000 - 188,000
Hybrid work model (3 days in office)
Snacks in office
Weekly lunches in office
+2