Manager, Security Governance & Risk

Emburse

Dallas (TX)

On-site

USD 140,000 - 210,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive pay
Flexible work
Inclusive culture
Career growth opportunities

Job summary

Emburse is seeking a Manager, Security Governance & Risk to lead the GRC function, mentor a team of professionals, and own platform strategy, controls architecture, data quality, and reporting.

You will own enterprise information security risk management end to end, oversee third‑party risk, and build AI governance and policy programs, partnering with Engineering and Product to mature risk across the business.

Qualifications

  • Bachelor’s degree required; 7+ years in information security, risk, or compliance.
  • 2+ years directly managing people or demonstrated equivalent leadership.
  • Proven experience leading a security GRC function with audits and reporting.
  • Ownership of an enterprise information security risk program and risk register.
  • Experience building security metrics and reporting for executives and Board.
  • Knowledge of audit frameworks (PCI DSS, ISO 27001, SOC 2, NIST) and privacy regs.
  • Experience with AI governance or governance of emerging technologies preferred.

Responsibilities

  • Lead, coach, and develop a team of GRC professionals, setting objectives and career paths.
  • Own Emburse's GRC platform, including strategy, controls, integrations, data quality, and automation.
  • Oversee audits, evidence coordination, and remediation planning with management oversight.
  • Own the enterprise information security risk management program end to end.
  • Mature risk reporting and risk communication beyond static heat maps.
  • Lead Third-Party Risk Management including vendor risk tiering and due diligence standards.
  • Build and own the security metrics and reporting framework with automated data collection.
  • Establish and lead AI governance covering product AI and internal employee/vendor use.
  • Track AI regulatory landscapes and translate obligations into controls and processes.
  • Maintain security policy lifecycle aligned with NIST, ISO, PCI DSS, SOC 2; ensure accessibility.
  • Oversee privacy program operations for GDPR, CPRA/CCPA, PIPEDA, and related regimes.
  • Partner with Engineering and Product on remediation of security risks surfaced by assessments.
  • Sponsor continuous controls monitoring to reduce manual effort and shorten audit cycles.

Skills

GRC leadership
Security metrics
Risk management
Audit coordination
AI governance
Third-Party Risk
Regulatory frameworks
Stakeholder communication

Education

Bachelor’s Degree

Tools

Drata
Vanta

Job description

Who We Are

At Emburse, you’ll not just imagine the future – you’ll build it. As a leader in expense intelligence, we are creating a future where technology drives business value and inspires extraordinary results. Our AI‑powered platform helps organizations modernize financial operations, increase visibility, and optimize spend across the enterprise.

Who We Are

At Emburse, you’ll not just imagine the future – you’ll build it. As a leader in expense intelligence, we are creating a future where technology drives business value and inspires extraordinary results. Our AI‑powered platform helps organizations modernize financial operations, increase visibility, and optimize spend across the enterprise.

The Manager, Security Governance & Risk leads Emburse’s security governance, risk, and compliance function, with primary focus on enterprise security risk management, security metrics and reporting, and AI governance across both Emburse’s AI‑enabled products and internal AI use. This is a people‑leadership role: the Manager leads a team of GRC professionals who independently manage day‑to‑day audit execution while the Manager owns the GRC operating model and platform strategy, governance, configuration standards, data quality, automation, and reporting. This structure allows the Manager to focus on maturing how Emburse identifies, measures, and communicates security risk while maintaining accountability for the quality and effectiveness of the broader GRC program. The ideal candidate pairs credible GRC depth with genuine analytical rigor: someone who can turn control and risk data into decision‑ready reporting for executives and the Board, establish governance for a fast‑moving AI landscape, and grow the people on their team while doing it.

What you will do :
  • Lead, coach, and develop a team of GRC professionals by setting objectives, managing performance, and building career paths that deepen expertise across audit, privacy, and risk.
  • Own Emburse's GRC platform, including platform strategy, control architecture, integrations, data quality, automation, reporting, and continuous‑control‑monitoring maturity; delegate day‑to‑day platform administration and evidence operations to the team as appropriate.
  • Provide management oversight and quality assurance for security and compliance audits while delegating day‑to‑day audit planning, evidence coordination, auditor interaction, and execution; intervene directly on material findings, scope disputes, control deficiencies, or issues requiring management judgment.
  • Own the enterprise information security risk management program end to end, covering risk identification, assessment methodology, risk register maintenance, treatment planning, and tracking remediation to closure.
  • Continuously mature the risk program by improving the consistency, defensibility, and trend analysis behind how risk is scored and communicated, moving the organization beyond static point‑in‑time heat maps.
  • Own the Third‑Party Risk Management program end to end, including vendor risk tiering, assessment methodology, due diligence standards, contractual security requirements, ongoing monitoring, and reassessment cadence, with ICs executing day‑to‑day vendor reviews and assessments against the standards and thresholds this role sets.
  • Build and own the security metrics and reporting framework, defining key risk and performance indicators, establishing authoritative data sources, and automating collection so reporting is repeatable rather than reassembled by hand each cycle.
  • Establish and lead Emburse's AI governance program, covering both AI capabilities within Emburse products and internal employee and vendor use of AI tools.
  • Track the evolving AI regulatory and framework landscape (e.g., EU AI Act, NIST AI RMF, ISO/IEC 42001, emerging state legislation) and translate obligations into concrete control and process requirements.
  • Own the security policy and standards lifecycle, ensuring alignment with industry frameworks (NIST, ISO 27001, PCI DSS, SOC 2) and keeping policies current, accessible, and enforceable.
  • Provide oversight of privacy program operations delivered by the team, ensuring obligations under GDPR, PIPEDA, CCPA/CPRA, and comparable regimes are met.
  • Partner with Engineering and Product on remediation of application and infrastructure security risk surfaced through risk assessments, penetration tests, and audit findings.
  • Sponsor continuous controls monitoring and automation initiatives that reduce manual evidence collection burden on the team and shorten audit cycles.
Education And Experience
Education
  • Required: Bachelor’s Degree; minimum 7+ years of information security, risk, or compliance experience, including 2+ years directly managing people or demonstrated equivalent team leadership (owning workstreams, mentoring, and developing others).
Experience
  • Proven experience leading a security GRC function or team, with direct responsibility for the performance, development, and prioritization of team members.
  • Demonstrated ownership of an enterprise information security risk management program, including assessment methodology, risk register, and treatment tracking.
  • Strong track record building security metrics and reporting for executive, Board, or Audit Committee audiences, shaping what gets measured and why rather than only producing dashboards.
  • Working knowledge of security audit frameworks (PCI DSS, ISO 27001, ISO 27701, SOC 1, SOC 2, NIST, Tx‑RAMP) sufficient to direct, quality‑review, and defend audits executed by the team.
  • Familiarity with privacy frameworks and regulations (GDPR, CPRA/CCPA, PIPEDA) and how they translate into operational controls.
  • Experience with AI governance, AI risk assessment, or governance of other emerging technologies; familiarity with the EU AI Act, NIST AI RMF, or ISO/IEC 42001 strongly preferred.
  • Hands‑on experience with GRC and compliance automation platforms (Drata, Vanta, or comparable), with enough depth to set direction and hold the team accountable for how the platform is configured and used.
  • Experience owning a third‑party risk management program, including assessment methodology and vendor risk tiering, and managing commercial relationships with external audit firms, testing providers, and tooling vendors.
  • Demonstrable experience interacting with auditors and strategic partners in cloud‑based environments similar to Emburse, relating to assurance frameworks such as SOX, PCI DSS, ISO 27001, SOC 2 Trust Principles, Business Continuity and Disaster Recovery, and Third‑Party Risk Management.
  • Ability to remain organized and to elicit cooperation from a wide variety of sources, including team members, other internal departments, and external parties.
  • Ability to effectively prioritize and execute tasks in a high‑pressure environment and react to project adjustments and alterations promptly and efficiently.
  • Ability to exercise good judgment and discretion in confidential matters.
Certifications
  • Preferred: CISSP, CRISC, CISA, CIPP/E, CIPM, AIGP, PMP
What we are looking for :
Required Skills
  • Strong analytical skills, with comfort pulling, structuring, and interpreting control and risk data, and building reporting that withstands scrutiny from auditors, executives, and customers.
  • Ability to explain risk in business terms and write clearly for executive audiences without oversimplifying the underlying technical reality.
  • Genuine people‑leadership instincts: delegates real ownership, coaches rather than corrects, gives direct feedback, and creates room for the team to grow.
  • Comfortable operating with ambiguity in a domain where standards are still forming, and able to make defensible decisions before consensus exists.
  • Ability to influence without authority across Engineering, Product, Legal, Finance, and Sales.
  • Sound judgment about where to apply rigor and where to accept risk, rather than defaulting to maximum control.
  • Experience working on large cross‑functional teams, representing GRC on initiatives such as change management, identity and access management, policy management, and data retention.
  • Ability to develop creative and adaptive solutions to unique and complex inquiries.
  • Comfortable with a rapid‑paced working environment and meeting deadlines.
  • Team‑focused, positive attitude, and good sense of humor.
Why Emburse?
  • A Company with Momentum – We serve 12M+ users across 120 countries, helping businesses modernize their finance operations.
  • A Team That Innovates – Work alongside some of the brightest minds in finance, tech, and AI to solve real‑world challenges.
  • A Culture That Empowers – Competitive pay, flexible work, and an inclusive, collaborative environment that supports your success.
  • A Career That Matters – Your work here drives efficiency, innovation, and smarter financial decision‑making for businesses everywhere.
Shape your future & find what’s next at Emburse.

Emburse provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability or genetics. In addition to federal law requirements, Emburse complies with applicable state and local laws governing nondiscrimination in employment in every location where the company has facilities. This policy applies to all terms and conditions of employment.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses or identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager, Security Governance & Risk
Manager, Security Governance & Risk

Emburse • Boston (MA)

On-site
USD 180,000 - 230,000
Competitive pay
Flexible work
Inclusive environment
Manager, Security Governance & Risk
Manager, Security Governance & Risk

Emburse • Fort Worth (TX), Town of Texas (WI)

On-site
USD 140,000 - 210,000
Competitive compensation
Flexible work options
EEO employer
Manager, Security Governance & Risk
Manager, Security Governance & Risk

Emburse, Inc. • Boston (MA), Northern (KY)

Hybrid
USD 180,000 - 290,000
Customer Trust Lead
Customer Trust Lead

Emburse • Dallas (TX)

On-site
USD 78,000 - 95,000
Competitive pay
Flexible work
Inclusive environment
Customer Trust Lead
Customer Trust Lead

Emburse • Boston (MA)

On-site
USD 78,000 - 95,000
Competitive pay
Flexible work
Inclusive and collaborative environment
Senior Software Engineer - C#
Senior Software Engineer - C#

Emburse • Dallas (TX)

Remote
USD 100,000 - 130,000
Competitive salary
Flexible work environment
Inclusive company culture
Associate Commercial Counsel
Associate Commercial Counsel

Emburse • Town of Texas (WI), Fort Worth (TX)

On-site
USD 100,000 - 120,000
Competitive pay
Flexible work
Inclusive environment
Senior Human Resources Business Partner
Senior Human Resources Business Partner

Socket.dev • Addison (TX)

Hybrid
USD 120,000 - 170,000
Manager, Corporate Financial Planning and Analysis (Fintech/SaaS)
Manager, Corporate Financial Planning and Analysis (Fintech/SaaS)

Emburse, Inc. • Boston (MA)

Hybrid
USD 140,000 - 190,000
Competitive pay
Hybrid work model
Inclusive culture
+1
Manager, Financial Planning and Analysis (Fintech/SaaS)
Manager, Financial Planning and Analysis (Fintech/SaaS)

Emburse, Inc. • Boston (MA)

Hybrid
USD 130,000 - 180,000
Competitive pay
Flexible work
Inclusive, collaborative environment