2d ago
Governance Risk Compliance Manager
Vienna, VA, USA
โจ $130k-$180k / yearest.
full-timemidcybersecurity
๐ Tech Stack
๐ผ About This Role
You'll build and run our compliance program end-to-end, owning the GRC calendar, Vanta instance, policy library, and audit evidence. You'll unblock enterprise deals by turning around security questionnaires quickly. This role combines operational compliance with a sales-forward mindset to earn customer trust.
๐ฏ What You'll Do
- Own SOC 2 audit end-to-end, including transition to rolling 12-month window
- Maintain and continuously improve policy library and GRC calendar
- Manage inbound security questionnaire queue for enterprise sales
- Maintain risk register and lead regular risk review cadences
๐ Requirements
- 3โ5 years of GRC experience in a SaaS or technical environment
- Hands-on experience with multiple SOC 2 audits owning evidence
- Experience with AWS and GCP infrastructure and IaC
- Strong written communication for customer-facing policy writing
โจ Nice to Have
- Relevant certifications: CISA, CISSP, CISM, CCSK, or similar
- Familiarity with ISO 27001, GDPR, or FedRAMP frameworks
- Experience owning or heavily using a GRC tool (Vanta preferred)
๐ Benefits & Perks
- ๐๏ธ Unlimited PTO
- ๐ฅ Health insurance
- ๐ก Remote-friendly (though role is on-site)
- ๐ฒ Equity
- ๐ 401k matching
๐จ Hiring Process
Estimated timeline: 2-4 weeks ยท AI estimate
- 1Recruiter Callยท 30 min
- 2Technical Interviewยท 1 hour
- 3Final Interviewยท 1 hour
0 0 0