See all roles

Manager of Governance, Risk and Compliance (GRC)

Work from home Full-time role Hiring

SpyCloud is seeking a hands-on and operationally focused Manager of Governance, Risk and Compliance (GRC) to lead and mature critical compliance, governance, and risk management initiatives across the organization. This role will own day-to-day execution of SpyCloud's compliance and security governance programs while helping scale operational processes that support the company's security posture and customer trust objectives. The ideal candidate brings strong experience operating security compliance programs within cloud-native and SaaS environments and has deep familiarity with frameworks such as SOC 2, ISO 27001, NIST, and CMMC 2.0. This individual will work cross-functionally with Privacy, Security Engineering, DevOps, Legal, Product Engineering, and business stakeholders to drive compliance readiness, risk mitigation, policy governance, third-party risk management, and audit coordination. This role is highly collaborative and execution-oriented, requiring both strategic judgment and operational ownership. The Manager of GRC will also directly manage at least one team member while helping evolve SpyCloud's overall security governance maturity. What You'll Do:

  • Governance & Compliance Operations
  • Own and manage SpyCloud's day-to-day GRC and compliance operations across multiple frameworks, including SOC 2, ISO 27001, NIST, and CMMC 2.0.
  • Lead internal and external audit coordination activities, evidence collection, remediation tracking, and control validation efforts.
  • Maintain and improve security policies, standards, procedures, and governance documentation.
  • Drive ongoing compliance readiness activities and operationalize scalable compliance processes across the business.
  • Partner closely with Legal, Security Engineering, DevOps, and Engineering teams to ensure alignment on security and regulatory requirements.
  • Risk Management
  • Conduct enterprise risk assessments and facilitate ongoing risk identification, tracking, remediation, and reporting processes.
  • Develop and maintain risk registers and support leadership reporting on security and compliance risks.
  • Lead third-party/vendor risk management activities, including security reviews and vendor assessments.
  • Support customer trust initiatives, including security questionnaires, compliance inquiries, and due diligence requests.
  • Cloud Security & Security Governance
  • Partner with DevOps and Security Engineering teams to strengthen cloud security governance across AWS and cloud-native environments.
  • Ensure security controls are aligned with compliance frameworks and operational best practices.
  • Support implementation and monitoring of governance controls related to cloud infrastructure, identity management, logging, vulnerability management, and secure development practices.
  • Contribute to ongoing security awareness and compliance education initiatives across the organization.
  • Leadership & Cross-Functional Collaboration
  • Manage and mentor direct report(s), supporting professional growth and operational excellence within the GRC function.
  • Collaborate with technical and non-technical stakeholders to drive accountability and operational maturity.
  • Help prioritize remediation efforts and compliance initiatives based on business risk and organizational goals.
  • Support the Senior Director of Governance, Risk and Information Security in scaling SpyCloud's overall security governance program.

Requirements:

  • Experience
  • 6+ years of experience in Governance, Risk, and Compliance (GRC), Information Security, Security Compliance, or related fields.
  • Demonstrated hands-on experience managing operational compliance programs within SaaS, cloud, or cybersecurity environments.
  • Proven experience supporting and maintaining compliance frameworks such as:
  • SOC 2
  • ISO 27001
  • NIST
  • CMMC 2.0
  • Experience leading audits, managing evidence collection, and coordinating remediation activities.
  • Experience with third-party/vendor risk management and enterprise risk assessment processes.
  • Experience working cross-functionally with Legal, Engineering, DevOps, Security, and executive stakeholders.
  • Education
  • Bachelor's degree in Cybersecurity, Information Security, Computer Science, Business, or related field, or equivalent practical experience.
  • Skills
  • Strong understanding of security governance, compliance operations, and risk management practices.
  • Familiarity with cloud security concepts and governance within AWS or similar cloud environments.
  • Strong organizational and project management skills with the ability to manage multiple priorities simultaneously.
  • Excellent written and verbal communication skills.
  • Ability to translate compliance requirements into practical operational processes.
  • Strong analytical, documentation, and problem-solving skills.

Nice to Have:

  • Prior people management or mentorship experience preferred.
  • Certifications
  • One or more of the following certifications strongly preferred:
  • CISSP
  • CISA
  • CRISC
  • CISM
  • ISO 27001 Lead Auditor or Lead Implementer
  • Experience within cybersecurity SaaS organizations.
  • Experience supporting customer-facing security and trust initiatives.
  • Familiarity with security tooling, cloud-native environments, and DevSecOps practices.
  • Experience with AI governance, security governance automation, or modern GRC tooling.
  • Experience working in fast-paced, high-growth technology environments.

SpyCloud is not sponsoring visas at this time. For applicants residing in California, please click here to read SpyCloud's CCPA Notice. For applicants residing in the UK, please click here to read SpyCloud's Employee Privacy Notice. U.S.-Based Benefits + Perks (for Full Time Employees): At SpyCloud, we are committed to working alongside individuals who are equally passionate about preventing cybercrime, regardless of their department or role. Guided by our core values in all business decisions, we prioritize unity in our mission and ensure all SpyCloud employees have the support and benefits they need to stay focused on our goals. In addition to our engaging workspace in South Austin, flexible and remote-friendly work options, and competitive salary package, we offer our employees a comprehensive benefits package that includes:

  • 401(k) with Employer Contribution
  • Health, Vision, and Dental Insurance
  • Health Savings Account (HSA) available with Employer Contribution
  • Employer Paid Life, Short-term, and Long-term Disability Insurance
  • Generous PTO Plan and 16 paid holidays per year

U.K.-Based Benefits + Perks (for Full Time Employees):

  • Retirement Savings Plan with Employer Contribution
  • Employer Provided Private Health Insurance and Healthcare Cashplan
  • Employer Paid Life Insurance and Income Replacement
  • Generous Holiday Plan and 14 paid holidays per year

Learn more and apply: SpyCloud Careers Apply tot his job Apply To this Job

You might like

NextCISO Junior GRC Analyst (Remote)

Work from home Full-time role

REMOTE - Information Security GRC Analyst III - R12694

Work from home Full-time role

GRC Analyst; AuditBoard

Work from home Full-time role

GRC and Privacy Analyst

Work from home Full-time role

GOVERNANCE, RISK, AND COMPLIANCE ANALYST (GRC)

Work from home Full-time role

GRC Analyst (AuditBoard REQUIRED) (468968)

Work from home Full-time role

Project Manager/ w GRC (REMOTE)

Work from home Full-time role

GRC Support- Hybrid | Houston, TX

Work from home Full-time role

Head, Global Intelligence Team, US

Work from home Full-time role

Night Shift SOC Analyst - Level 1

Work from home Full-time role

Director, Healthcare Services (RN) (Remote in Massachusetts)

Work from home Full-time role

Experienced Data Entry Operator – Remote Opportunity with arenaflex

Work from home Full-time role

Experienced Remote Customer Support Representative – Travel Industry Expertise

Work from home Full-time role

Remote Customer Care Specialist - Travel Experience Concierge & Client Support Expert (Full-Time)

Work from home Full-time role

Experienced Full Stack Product Manager – Customer Service Innovation at arenaflex

Work from home Full-time role

Experienced Customer Care Representative – Delivering Exceptional Arenaflex Customer Experiences

Work from home Full-time role

Experienced Retail Customer Service Representative – Delivering Exceptional Customer Experiences at arenaflex

Work from home Full-time role

Experienced Data Entry Clerk Remote Work From Home - Part-Time Focus Group Panelist

Work from home Full-time role

Investor Relations Executive

Work from home Full-time role

Experienced Patient Care Coordinator – After Hours Call Center (Remote)

Work from home Full-time role