Sr Manager, InfoSec Governance Risk and Compliance (GRC)

Ivalua
San Francisco, Pittsburgh
Workplace: HybridFull timeUSD 112,000 - 208,000 annuallyFunction: Legal, Risk & ComplianceExperience: 7+ yearsEducation: bachelorsSkills: ["Communication","Leadership","Problem-solving","Interpersonal skills"]

Experienced InfoSec Governance, Risk and Compliance leader who will own the GRC program globally, manage a high-performing team, drive certifications (FedRAMP, ISO 27001, HIPAA, SOC1/SOC2, PCI DSS, IRAP, etc.), and act as SME on security frameworks while coordinating with cross-functional teams to ensure continuous compliance and strong security posture.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Ivalua
Ivalua
11 months ago

Sr Manager, InfoSec Governance Risk and Compliance (GRC)

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 6 hours agoStatus: Live

Job Summary

Experienced InfoSec Governance, Risk and Compliance leader who will own the GRC program globally, manage a high-performing team, drive certifications (FedRAMP, ISO 27001, HIPAA, SOC1/SOC2, PCI DSS, IRAP, etc.), and act as SME on security frameworks while coordinating with cross-functional teams to ensure continuous compliance and strong security posture.
Location: San Francisco, Pittsburgh
Workplace: Hybrid
Employment Type: Full time
Job Function: Legal, Risk & Compliance

Key Responsibilities

  • •Lead and own the Governance, Risk, and Compliance (GRC) program globally, managing and developing a high-performing team.
  • •Manage and drive compliance efforts and audits for certifications such as FedRAMP, IRAP, ISO 27001, HIPAA, SOC1/SOC2, PCI DSS, and others.
  • •Serve as the subject matter expert (SME) on security frameworks and standards including NIST SP 800-53 Rev 5, NIST 800-171, ITAR, FedRAMP, PCI DSS, SOC2, etc., providing guidance to internal stakeholders.
  • •Efficiently manage and respond to customer security audit and compliance requests in a timely manner.
  • •Maintain continuous compliance and monitoring of security controls to ensure ongoing adherence to standards.

Pay and Benefits

Salary: USD 112,000 - 208,000 annually
Perks:MedicalDentalVisionCommuter Benefits

Key Requirements

  • •7+ years leading GRC programs and managing certifications and audits (FedRAMP, ISO 27001, HIPAA, SOC1/SOC2, PCI DSS, IRAP, etc.)
  • •3+ years experience as a direct leader, managing a team
  • •Strong knowledge of security frameworks such as NIST SP 800-53 Rev 5, NIST 800-171, ITAR, PCI DSS, SOC2, and FedRAMP
  • •Demonstrated ability to manage and influence stakeholders across multiple departments and time zones
  • •Bachelor’s degree in related field preferred or equivalent experience with proven skills
Experience:7+ yearsInformation securityGRCCompliance
Education:Bachelor's
Skills:CommunicationLeadershipProblem-solvingInterpersonal skills
Certifications:FedRAMPISO 27001HIPAASOC1SOC2PCI DSS
Languages:English
Tech Stack:NIST SP 800-53NIST 800-171ITARPCI DSSSOC2FedRAMPISO 27001HIPAASOC1

Company Brief

Ivalua
Provides a cloud-based procure-to-pay and sourcing platform that helps organizations manage procurement, supplier relationships, sourcing events, and spend analytics to drive cost savings, compliance, and supplier collaboration across global enterprises.
Industry: Procurement Platforms
Company Size: Enterprise (1,001+ employees)
Growth: Established Company
Headquarters: Paris, France
Founded: 2000
WebsiteLinkedIn