GRC Manager

G2
Chicago
Workplace: OnsiteFull timeUSD 120,000 - 131,000 annuallyFunction: Legal, Risk & ComplianceExperience: 7-10 yearsSkills: ["Written communication","Verbal communication","Prioritization","Program management","Cross-functional influence"]

Own and run G2’s day-to-day Governance, Risk, and Compliance program, including security policy governance, customer security questionnaires, vendor risk management, DSAR processing, and audit management. Serve as the front-line trust and compliance representative via the Trust Center, maintain enterprise risk registers, and lead SOC 2 Type II and ISO 27001 cycles end-to-end. Partner across Legal, Security, IT, and Sales, using modern GRC tooling to scale a high-volume compliance operation.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
G2
G2
21 hours ago

GRC Manager

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 8 hours agoStatus: Live

Job Summary

Own and run G2’s day-to-day Governance, Risk, and Compliance program, including security policy governance, customer security questionnaires, vendor risk management, DSAR processing, and audit management. Serve as the front-line trust and compliance representative via the Trust Center, maintain enterprise risk registers, and lead SOC 2 Type II and ISO 27001 cycles end-to-end. Partner across Legal, Security, IT, and Sales, using modern GRC tooling to scale a high-volume compliance operation.
Location: Chicago
Workplace: Onsite
Employment Type: Full time
Job Function: Legal, Risk & Compliance

Key Responsibilities

  • •Own and administer the security policy library, leading annual review cycles, managing approvals, and preventing policy lapses.
  • •Lead responses to customer and prospect security questionnaires and maintain the security knowledge library for fast, accurate answers at scale.
  • •Run third-party/vendor risk management, including reviewing AI-assisted assessments, determining risk levels, and driving remediation of high-risk findings.
  • •Manage DSAR intake and fulfillment to ensure requests are documented and resolved within regulatory timelines.
  • •Lead SOC 2 Type II and ISO 27001 audit cycles end-to-end, including evidence collection, control testing, and serving as primary auditor point of contact.

Pay and Benefits

Salary: USD 120,000 - 131,000 annually

Key Requirements

  • •7–10 years of progressive experience in IT Governance, Risk, and Compliance or information security with direct ownership of a compliance program.
  • •Deep working knowledge of SOC 2 Type II, ISO 27001, NIST CSF, and security/privacy frameworks including PCI DSS, GDPR, and CCPA.
  • •Hands-on experience with modern GRC/compliance automation platforms such as Vanta, Drata, or OneTrust to manage controls and evidence at scale.
  • •Experience running high-volume customer security questionnaire programs and knowledge libraries, including 100+ question enterprise reviews.
  • •Track record managing third-party/vendor risk management and DSAR workflows within regulatory timelines, plus serving as primary auditor contact through full audit cycles.
Experience:7-10 yearsSaaSCloud securityPrivacyEnterprise complianceGRC
Skills:Written communicationVerbal communicationPrioritizationProgram managementCross-functional influence
Certifications:CISSPCRISCCISMCISA
Tech Stack:VantaDrataOneTrustSOC 2 Type IIISO 27001NIST CSFPCI DSSGDPRCCPADSARGRC toolingTrust Center

Company Brief

G2
Operates the world’s largest B2B software marketplace that collects and publishes user reviews to help organizations discover, evaluate, and manage software purchases and vendor reputation.
Industry: Online Marketplaces
Company Size: Large (251 to 1,000 employees)
Growth: Scaleup
Valuation: Unicorn (USD 1B+)
Funding: Series D
Headquarters: Chicago, United States
Founded: 2012
Glassdoor
Glassdoor: 3.7
WebsiteLinkedInGlassdoor