Program Manager - GRC

Astreya

Santa Clara (CA)

On-site

USD 150,000 - 230,000

Full time

48 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Astreya is seeking an experienced Program Manager to lead Governance, Risk & Compliance initiatives across its infrastructure landscape, spanning Cybersecurity, Cloud Infrastructure, IAM, and Modern Workplace. You will drive AI-powered risk scoring and compliance monitoring at scale.

You will own end-to-end rollout, coordinate cross-functional teams, support audits, and track remediation. The role demands strong stakeholder management, cloud security knowledge, and ability to deliver measurable

Qualifications

  • Bachelor's or Master's degree in Computer Science, Information Security, Risk Management, or related field.
  • Proven experience in Program/Project Management within GRC, Cybersecurity, or Infrastructure domains.
  • Demonstrated experience coordinating initiatives across multiple technical groups such as Cybersecurity, AppSec, Cloud Infra (AWS/GCP), IAM, and M365/Modern Workplace.
  • Working knowledge of AI/ML concepts and their application to security and compliance use cases (e.g., anomaly detection, predictive risk analytics, generative AI for policy/control analysis).
  • Familiarity with common GRC frameworks and standards (e.g., NIST CSF, ISO 27001, SOC 2, PCI-DSS, CIS Benchmarks).
  • Strong understanding of cloud infrastructure security (AWS, GCP), identity/access management principles, and enterprise collaboration platforms (M365).
  • Excellent stakeholder management, executive communication, and presentation skills.
  • Proven ability to manage multiple concurrent, cross-functional programs in a fast-paced, matrixed environment.
  • PMP, PgMP, CISM, CISA, or CRISC certification is a plus.

Responsibilities

  • Cross-Functional Program Coordination across Cybersecurity, AppSec, AWS/GCP Infra, IAM, and M365 teams to drive alignment on GRC initiatives.
  • Lead the planning, rollout, and adoption of AI-based capabilities across infrastructure and security domains.
  • Maintain and evolve the GRC roadmap for infrastructure, track risk posture and remediation across cloud, IAM, and M365.
  • Define program charters, milestones, RAID logs, and success metrics; report progress to senior leadership.
  • Manage program budgets, resource allocation, and timelines across multiple concurrent work streams.
  • Develop executive dashboards and risk heat-maps; communicate AI/automation concepts in business-friendly terms.

Skills

GRC Program Mgmt
Cybersecurity collaboration
Cloud Infra coordination
IAM & M365 knowledge
AI in security
GRC frameworks
Executive communication
Cross-functional leadership

Education

Bachelor's degree in CS/Security

Tools

ServiceNow GRC
Archer
MetricStream

Job description

We are looking for an experienced Program Manager to drive Governance, Risk & Compliance (GRC) initiatives across our Infrastructure landscape. This role is central to orchestrating cross-functional programs that span Cybersecurity, Application Security, Cloud Infrastructure (AWS/GCP), Identity & Access Management (IAM), and Modern Workplace (M365) teams. A key focus of this role is driving the adoption and rollout of AI-powered capabilities — moving beyond traditional rule-based automation — to strengthen risk management, compliance monitoring, and security operations at scale.

Key Responsibilities

Cross-Functional Program Coordination

  • Serve as the primary program-level point of coordination across multiple stakeholder groups, including Cybersecurity, Application Security, AWS Infrastructure, GCP Infrastructure, IAM, and M365 teams, to drive alignment on GRC initiatives.
  • Build and maintain strong working relationships with engineering, security, and platform leads to ensure program objectives are understood, prioritized, and executed consistently across teams.
  • Facilitate cross-team working sessions, steering committees, and governance forums to resolve dependencies, blockers, and conflicting priorities.

AI-Driven Initiative Rollout

  • Lead the planning, rollout, and adoption of AI-based capabilities (e.g., ML-driven risk scoring, intelligent anomaly detection, AI-assisted compliance monitoring, LLM-based policy/control analysis) across infrastructure and security domains — distinct from traditional rule-based or scripted automation.
  • Partner with data science, security engineering, and platform teams to translate AI/ML capabilities into practical GRC use cases such as automated risk detection, predictive compliance analytics, and intelligent control testing.
  • Track emerging AI capabilities relevant to GRC and infrastructure risk management, and evaluate their applicability for the organization's control environment.
  • Own the end-to-end rollout lifecycle for AI initiatives: use-case definition, pilot design, stakeholder buy-in, phased deployment, and post-rollout measurement of risk/compliance impact.

Governance, Risk & Compliance Ownership

  • Maintain and evolve the GRC roadmap for infrastructure, ensuring initiatives map to applicable regulatory, audit, and internal control requirements.
  • Track risk posture, control gaps, and remediation plans across cloud (AWS/GCP), identity (IAM), endpoint/collaboration (M365), and application security domains.
  • Support internal and external audit engagements by coordinating evidence collection, control walkthroughs, and remediation tracking across stakeholder teams.

Program & Delivery Management

  • Define program charters, milestones, RAID logs, and success metrics for each initiative; report progress to senior leadership and steering committees.
  • Manage program budgets, resource allocation, and timelines across multiple concurrent work streams.
  • Proactively identify risks and dependencies across teams and drive mitigation plans to avoid delivery slippage.

Reporting & Stakeholder Communication

  • Develop executive-level dashboards, status reports, and risk heat-maps summarizing program health and AI-initiative rollout progress.
  • Communicate technical AI/automation concepts in business-friendly terms to non-technical stakeholders and leadership.

Required Skills & Qualifications

  • Bachelor's or Master's degree in Computer Science, Information Security, Risk Management, or related field.
  • Proven experience in Program/Project Management within GRC, Cybersecurity, or Infrastructure domains.
  • Demonstrated experience coordinating initiatives across multiple technical groups such as Cybersecurity, AppSec, Cloud Infra (AWS/GCP), IAM, and M365/Modern Workplace.
  • Working knowledge of AI/ML concepts and their application to security and compliance use cases (e.g., anomaly detection, predictive risk analytics, generative AI for policy/control analysis) — distinguishing these from traditional scripted or rule-based automation.
  • Familiarity with common GRC frameworks and standards (e.g., NIST CSF, ISO 27001, SOC 2, PCI-DSS, CIS Benchmarks).
  • Strong understanding of cloud infrastructure security (AWS, GCP), identity/access management principles, and enterprise collaboration platforms (M365).
  • Excellent stakeholder management, executive communication, and presentation skills.
  • Proven ability to manage multiple concurrent, cross-functional programs in a fast-paced, matrixed environment.
  • PMP, PgMP, CISM, CISA, or CRISC certification is a plus.

Preferred / Nice-to-Have

  • Prior experience piloting or scaling AI-based security/compliance tools (e.g., AI-driven SIEM/SOAR enhancements, AI copilots for GRC platforms, LLM-based control testing).
  • Experience with GRC tooling (e.g., ServiceNow GRC, Archer, MetricStream) and cloud-native security posture management (CSPM) tools.
  • Exposure to Agile/Scrum delivery methodologies for running technical rollout programs.

What Success Looks Like

  • Seamless coordination across Cybersecurity, AppSec, AWS/GCP Infra, IAM, and M365 teams with minimal escalations.
  • Successful, measurable rollout of AI-based GRC capabilities that demonstrably improve risk detection and compliance efficiency over legacy automation approaches.
  • A mature, well-governed program cadence with clear visibility for leadership on risk, compliance, and initiative progress.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Analyst
Information Security Analyst

AMISEQ • San Jose (CA)

On-site
USD 95,000 - 120,000
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

LexisNexis • Raleigh (NC)

On-site
USD 118,000 - 220,000
Senior Technical Governance Program Manager
Senior Technical Governance Program Manager

Jobtailor • California (MO)

On-site
USD 120,000 - 190,000
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

RELX • Raleigh (NC)

On-site
USD 118,000 - 220,000
Annual incentive bonus
GRC Lead
GRC Lead

Jobtailor • Houston (TX)

On-site
USD 120,000 - 180,000
Program Manager, Security Risk Program
Program Manager, Security Risk Program

Meta • Menlo Park (CA)

On-site
USD 190,000 - 260,000
Program Architect - Governance, Risk, and Compliance
Program Architect - Governance, Risk, and Compliance

Onebrief • United States

Hybrid
USD 150,000 - 230,000
Senior Program Manager
Senior Program Manager

Jobtailor • New Jersey

Hybrid
USD 110,000 - 180,000
Artificial Intelligence Engineer- GRC
Artificial Intelligence Engineer- GRC

Glocomms • Westport (CT)

On-site
USD 130,000 - 190,000
Project Manager
Project Manager

truData Solutions • United States

On-site
USD 85,000 - 120,000