Remote GRC & InfoSec Leader: SOC 1/2, PCI

Neumo

West Jordan (UT)

On-site

USD 120,000 - 180,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Neumo is seeking a Manager, Information Security (GRC) to own and mature its governance, risk, and compliance program. You will drive SOC 1/2 and PCI readiness, build risk management processes, and lead audits with 1–2 direct reports. The role bridges security, legal, engineering, and leadership to translate requirements into practical controls and scalable workflows.

You will modernize risk management, leveraging automation and AI to scale while maintaining strong governance and board reporting.

Qualifications

  • 6+ years of experience in GRC, information security compliance, or IT audit.
  • Hands-on ownership of SOC 1, SOC 2, and PCI DSS programs with audits.
  • Experience building risk registers, acceptance/exception processes, and CCM.
  • Familiarity with data governance concepts: classification, ownership, retention.
  • Knowledge of GRC platforms (Vanta/Drata/ServiceNow GRC/OneTrust/Archer).
  • Certifications such as CISA/CRISC/CISSP/CISM are a plus but not required.

Responsibilities

  • Own and execute Neumo's GRC strategy and roadmap with the CISO.
  • Mentor 1-2 direct reports across compliance, risk, and audit workstreams.
  • Lead SOC 1/2 and PCI DSS readiness, evidence collection and remediation tracking.
  • Develop and maintain risk register and monthly/quarterly risk mitigations.
  • Design automation to reduce manual evidence and enable CCM.
  • Collaborate with Legal, Privacy, and Engineering on regulatory controls.

Skills

GRC
Audit management
Risk assessment
Control automation
Incident management
Jira
Strategic leadership

Education

Bachelor's degree in a related field
Certifications in CISA/CRISC/CISSP/CISM (nice to have)

Tools

Vanta
Drata
ServiceNow GRC
OneTrust
Archer
Jira

Job description

Neumo is seeking a Manager, Information Security (GRC) to own and mature its governance, risk, and compliance program. You will drive SOC 1/2 and PCI readiness, build risk management processes, and lead audits with 1–2 direct reports. The role bridges security, legal, engineering, and leadership to translate requirements into practical controls and scalable workflows.

You will modernize risk management, leveraging automation and AI to scale while maintaining strong governance and board reporting.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Remote Information Security GRC Manager
Remote Information Security GRC Manager

Neumo • Carrollton (VA)

On-site
USD 140,000 - 190,000
Manager, Information Security (GRC) (Remote)
Manager, Information Security (GRC) (Remote)

Neumo • West Jordan (UT)

On-site
USD 120,000 - 180,000
Senior Director, Information Security — SOC 1/2 & PCI Lead
Senior Director, Information Security — SOC 1/2 & PCI Lead

Neumo • Town of Texas (WI)

On-site
USD 180,000 - 260,000
Remote GRC Lead: PCI/SOX, AI-Driven Compliance
Remote GRC Lead: PCI/SOX, AI-Driven Compliance

Subsplash • United States

On-site
USD 95,000 - 105,000
Generous paid time off
Medical, dental, vision coverage
401(k) matching
+2
Senior GRC Program Lead - SOC 2, GDPR & Security
Senior GRC Program Lead - SOC 2, GDPR & Security

Tandem Inc. • Draper (UT)

Hybrid
USD 110,000 - 170,000
On-site gym
Flexible PTO
Redo perks: monthly ecommerce credit
+2
Remote GRC Leader: Governance, Risk & Compliance
Remote GRC Leader: Governance, Risk & Compliance

Sound Physicians • Northern (KY)

Hybrid
USD 130,000 - 160,000
Medical, dental & vision insurance
FSA (healthcare & dependent care)
401(k) with company match
+2
Remote Security GRC Analyst: Risk & Compliance Lead
Remote Security GRC Analyst: Risk & Compliance Lead

NEPSE Trading • United States

On-site
USD 70,000 - 77,000
Health insurance
401(k) plan with company match
Pension plan
+1
Security GRC Engineer — Lead Compliance & Risk
Security GRC Engineer — Lead Compliance & Risk

Whatnot • Los Angeles (CA)

Hybrid
USD 120,000 - 180,000
Health Insurance options
Work From Home Support
Home office setup allowance
+3
Senior GRC Manager — Remote, Risk & Compliance Strategy
Senior GRC Manager — Remote, Risk & Compliance Strategy

Sound Physicians • United States

On-site
USD 130,000 - 160,000
Senior GRC Engineer - Automate Compliance & Security
Senior GRC Engineer - Automate Compliance & Security

Cloud Software Group • San Ramon (CA)

On-site
USD 160,000 - 241,000