Senior Manager, Information Security GRC
Listed on 2026-07-15
-
IT/Tech
Information Security & Data Protection, Cybersecurity
ABOUT GREYSTAR
Greystar is a leading, fully integrated global real estate platform offering expertise in property management, investment management, development, and construction services in institutional-quality rental housing. Headquartered in Charleston, South Carolina, Greystar manages and operates over $300 billion of real estate in more than 265 markets globally with offices throughout North America, Europe, South America, and the Asia-Pacific region. Greystar is the largest operator of apartments in the United States, managing over one million units/beds globally.
Across its platforms, Greystar has nearly $79 billion of assets under management, including over $35 billion of development assets and over $36.5 billion of regulatory assets under management. Greystar was founded by Bob Faith in 1993 to become a provider of world-class service in the rental residential real estate business. To learn more,
The Senior Manager, Information Security GRC owns the strategy, execution, and continuous improvement of Greystar’s Global Information Security Governance, Risk, and Compliance program. This role builds and leads the GRC function - developing internal team capability and directing third-party partners - and is accountable for the frameworks, processes, and reporting that govern security risk, regulatory compliance, third-party risk, and security awareness across the enterprise.
The Senior Manager sets the GRC program roadmap, advises senior leadership on the organization’s risk posture, and partners across the business to preserve the availability, integrity, and confidentiality of Greystar and customer information in compliance with applicable information security laws, policies, and standards. Reports to the Information Security Officer (or CISO).
- Own the GRC program roadmap and strategy, setting priorities, objectives, and maturity goals aligned with business and security objectives.
- Build and lead the GRC function, growing internal team capability while directing third-party partners to deliver against program objectives.
- Advise the Information Security Officer and senior leadership on enterprise security risk posture, emerging threats, and regulatory exposure.
- Establish and report program metrics, dashboards, and KPIs that communicate GRC program health to senior leadership and the board.
- Own the information security policy framework, including development, approval, enforcement, and periodic review of policies, standards, and procedures for global locations.
- Direct the monitoring of changes in laws, regulations, and industry standards affecting information security (e.g., NIST, ISO 27001, PCI DSS, SOX, GDPR, CCPA), and oversee translation of those changes into actionable business requirements.
- Oversee compliance assessments and maintain the organization’s compliance posture across applicable frameworks and regulations.
- Build and mature AI governance practices, applying emerging frameworks such as ISO 42001 and the NIST AI RMF.
- Lead the enterprise information security risk management program, including risk assessments across business units, applications, infrastructure, and processes; the risk register; and risk treatment planning.
- Drive remediation of identified risks, partnering with control owners and holding the program accountable for closure.
- Own the third‑party risk management program, including pre‑contract security due diligence, recurring vendor risk reviews, the vendor risk inventory, and remediation tracking.
- Oversee responses to client, regulator, and internal audit requests, including security questionnaires (SIG, CAIQ), evidence collection, and findings remediation.
- Direct periodic audits of internal control systems to ensure access levels, segregation of duties, and configuration baselines remain appropriate, and lead the response to audit findings requiring action.
- Oversee periodic user access and privileged access reviews across in‑scope systems and applications, ensuring timely remediation of inappropriate or excessive access.
- Partner with Legal, Privacy, and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).