Manager of Governance, Risk and Compliance; GRC
Job in
Austin, Travis County, Texas, 78716, USA
Listed on 2026-05-23
Listing for:
SpyCloud
Full Time
position Listed on 2026-05-23
Job specializations:
-
IT/Tech
Cybersecurity, Information Security, Data Security, IT Consultant
Job Description & How to Apply Below
Manager of Governance, Risk and Compliance (GRC)
Austin, Texas | Remote
Spy Cloud is on a mission to make the internet a safer place by disrupting the criminal underground. We protect more than 4 billion accounts worldwide. We are looking for a hands‑on, operationally focused Manager of Governance, Risk & Compliance (GRC) to lead and mature our compliance, governance and risk management initiatives across the organization.
What You'll Do- Own and manage Spy Cloud’s day‑to‑day GRC and compliance operations across multiple frameworks, including SOC 2, ISO 27001, NIST, and CMMC 2.0.
- Lead internal and external audit coordination activities, evidence collection, remediation tracking, and control validation efforts.
- Maintain and improve security policies, standards, procedures, and governance documentation.
- Drive ongoing compliance readiness activities and operationalize scalable compliance processes across the business.
- Partner closely with Legal, Security Engineering, Dev Ops, and Engineering teams to ensure alignment on security and regulatory requirements.
- Conduct enterprise risk assessments and facilitate ongoing risk identification, tracking, remediation, and reporting processes.
- Develop and maintain risk registers and support leadership reporting on security and compliance risks.
- Lead third‑party/vendor risk management activities, including security reviews and vendor assessments.
- Support customer trust initiatives, including security questionnaires, compliance inquiries, and due diligence requests.
- Partner with Dev Ops and Security Engineering teams to strengthen cloud security governance across AWS and cloud‑native environments.
- Ensure security controls are aligned with compliance frameworks and operational best practices.
- Support implementation and monitoring of governance controls related to cloud infrastructure, identity management, logging, vulnerability management, and secure development practices.
- Contribute to ongoing security awareness and compliance education initiatives across the organization.
- Manage and mentor direct report(s), supporting professional growth and operational excellence within the GRC function.
- Collaborate with technical and non‑technical stakeholders to drive accountability and operational maturity.
- Help prioritize remediation efforts and compliance initiatives based on business risk and organizational goals.
- Support the Senior Director of Governance, Risk and Information Security in scaling Spy Cloud’s overall security governance program.
- 6 + years of experience in Governance, Risk and Compliance (GRC), Information Security, Security Compliance or related fields.
- Hands‑on experience managing operational compliance programs within SaaS, cloud, or cybersecurity environments.
- Experience supporting and maintaining compliance frameworks such as SOC 2, ISO 27001, NIST, CMMC 2.0.
- Experience leading audits, collecting evidence, and coordinating remediation activities.
- Experience with third‑party/vendor risk management and enterprise risk assessment processes.
- Experience working cross‑functionally with Legal, Engineering, Dev Ops, Security, and executive stakeholders.
- Bachelor’s degree in Cybersecurity, Information Security, Computer Science, Business or a related field, or equivalent practical experience.
- Strong understanding of security governance, compliance operations, and risk management practices.
- Familiarity with cloud security concepts and governance within AWS or similar cloud environments.
- Strong organizational and project management skills with the ability to manage multiple priorities simultaneously.
- Excellent written and verbal communication skills.
- Ability to translate compliance requirements into practical operational processes.
- Strong analytical, documentation, and problem‑solving skills.
- Prior people‑management or mentorship experience.
- Certifications such as CISSP, CISA, CRISC, CISM, ISO 27001 Lead Auditor or Lead Implementer.
- Experience with in cybersecurity SaaS organizations and supporting customer‑facing security and trust initiatives.
- Familiarity with security tooling, cloud‑native environments, and Dev Sec Ops practices.
- Experience with AI…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×