Remote GRC Manager, Information Security

Neumo

Decorah (IA)

On-site

USD 120,000 - 180,000

Full time

26 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Neumo seeks a Manager, Information Security (GRC) to own and mature the Governance, Risk, and Compliance program, ensuring SOC 1, SOC 2, and PCI certifications. This hands-on leadership role will drive audits, risk assessments, control automation, and incident management with 1–2 direct reports.

The role connects security, legal, engineering, and leadership, translating regulatory requirements into practical controls and communicating risk to executives.

Qualifications

  • 6+ years of experience in GRC, information security compliance, or IT audit, including experience managing or mentoring others.
  • Direct experience owning SOC 1, SOC 2, and PCI DSS compliance programs end-to-end, including audit management.
  • Hands-on experience with GRC platforms (e.g., Vanta, Drata, ServiceNow GRC, OneTrust, Archer, or similar).
  • Experience building risk management programs: risk registers, risk acceptance/exception processes, and recurring risk mitigation cadences.
  • Foundational experience with data governance concepts (classification, ownership, retention).
  • Relevant certifications (e.g., CISA, CRISC, CISSP, CISM) are a plus but not required.

Responsibilities

  • Own and execute Neumo's GRC strategy and roadmap, in partnership with the CISO.
  • Manage, mentor, and grow 1-2 direct reports supporting compliance, risk, and audit activities.
  • Set the foundation for data governance: data classification, ownership, retention, and handling standards.
  • Build and maintain the risk register; lead monthly, quarterly, and annual risk mitigation cycles.
  • Own the risk acceptance and policy exception process, including documentation, approval workflows, and periodic review.
  • Report on compliance posture, audit status, and risk trends to executive stakeholders and the board as needed.
  • Own end-to-end readiness and execution for SOC 1, SOC 2, and PCI DSS audits, including evidence collection, auditor coordination, and remediation tracking.
  • Maintain and continuously improve the internal control framework mapped to SOC 1/2, PCI, and other applicable frameworks (e.g., ISO 27001, NIST CSF).
  • Track control ownership, testing cadence, and control health across the organization using the GRC platform and Jira.
  • Partner with engineering and IT teams to close control gaps and drive remediation of audit findings within SLA.
  • Design and implement control automation to reduce manual evidence collection and continuous control monitoring (CCM).
  • Leverage AI/LLM tooling to accelerate evidence review, policy drafting, control testing, and risk analysis, with appropriate human oversight.
  • Participate in incident management as the GRC/risk representative: assessing regulatory and contractual impact and ensuring proper documentation.
  • Manage third-party/vendor risk assessments and questionnaires (customer security questionnaires, vendor due diligence).
  • Partner with Legal and Privacy on data protection, regulatory, and contractual compliance requirements.

Skills

Jira
GRC
Audit management
Data governance
Incident management
AI tooling
Policy drafting
Communication

Tools

Vanta
Drata
ServiceNow GRC
OneTrust
Archer

Job description

Neumo seeks a Manager, Information Security (GRC) to own and mature the Governance, Risk, and Compliance program, ensuring SOC 1, SOC 2, and PCI certifications. This hands-on leadership role will drive audits, risk assessments, control automation, and incident management with 1–2 direct reports.

The role connects security, legal, engineering, and leadership, translating regulatory requirements into practical controls and communicating risk to executives.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Remote GRC & Information Security Manager
Remote GRC & Information Security Manager

Neumo • Kentucky

On-site
USD 120,000 - 180,000
Remote GRC & Information Security Manager
Remote GRC & Information Security Manager

Neumo • Illinois

On-site
USD 130,000 - 185,000
Remote GRC & InfoSec Manager
Remote GRC & InfoSec Manager

Neumo • Alabama

On-site
USD 110,000 - 160,000
Manager, Information Security (GRC) (Remote)
Manager, Information Security (GRC) (Remote)

Neumo • Alabama

On-site
USD 110,000 - 160,000
Manager, Information Security (GRC) (Remote)
Manager, Information Security (GRC) (Remote)

Neumo • Kentucky

On-site
USD 120,000 - 180,000
Manager, Information Security (GRC) (Remote)
Manager, Information Security (GRC) (Remote)

Neumo • Illinois

On-site
USD 130,000 - 185,000
Manager, Information Security (GRC) (Remote)
Manager, Information Security (GRC) (Remote)

Neumo • Decorah (IA)

On-site
USD 120,000 - 180,000
Remote GRC Leader: Governance, Risk & Compliance
Remote GRC Leader: Governance, Risk & Compliance

Sound Physicians • Northern (KY)

Hybrid
USD 130,000 - 160,000
Medical, dental & vision insurance
FSA (healthcare & dependent care)
401(k) with company match
+2
Remote Security GRC Program Manager
Remote Security GRC Program Manager

United States Digital Space LLC • United States

Remote
USD 130,000 - 190,000
Remote Security GRC Analyst: Risk & Compliance Lead
Remote Security GRC Analyst: Risk & Compliance Lead

NEPSE Trading • United States

On-site
USD 70,000 - 77,000
Health insurance
401(k) plan with company match
Pension plan
+1