Sr Manager, InfoSec Governance Risk and Compliance (GRC)

Ivalua
Pittsburgh
Workplace: HybridFull timeUSD 112,000 - 208,000 annuallyFunction: Legal, Risk & ComplianceExperience: 7+ yearsEducation: bachelorsSkills: ["Leadership","Communication","Stakeholder management","Problem-solving","Team building"]

Lead and grow the global GRC program, overseeing audits and certifications (FedRAMP, IRAP, ISO 27001, HIPAA, SOC1/SOC2, PCI DSS) and guiding security frameworks, risk management, and compliance across the organization. Build a high-performing team, mentor security professionals, and serve as SME on NIST, ITAR, and FedRAMP, while communicating security posture to customers and stakeholders.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Ivalua
Ivalua
11 months ago

Sr Manager, InfoSec Governance Risk and Compliance (GRC)

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 6 hours agoStatus: Live

Job Summary

Lead and grow the global GRC program, overseeing audits and certifications (FedRAMP, IRAP, ISO 27001, HIPAA, SOC1/SOC2, PCI DSS) and guiding security frameworks, risk management, and compliance across the organization. Build a high-performing team, mentor security professionals, and serve as SME on NIST, ITAR, and FedRAMP, while communicating security posture to customers and stakeholders.
Location: Pittsburgh
Workplace: Hybrid
Employment Type: Full time
Job Function: Legal, Risk & Compliance
Seniority: Manager level

Key Responsibilities

  • •Lead and own the Governance, Risk, and Compliance (GRC) program globally, managing and developing a high-performing team.
  • •Manage and drive compliance efforts and audits for certifications such as FedRAMP, IRAP, ISO 27001, HIPAA, SOC1/SOC2, PCI DSS, and others.
  • •Serve as the subject matter expert (SME) on security frameworks and standards including NIST SP 800-53 Rev 5, NIST 800-171, ITAR, FedRAMP, PCI DSS, SOC2, etc., providing guidance to internal stakeholders.
  • •Efficiently manage and respond to customer security audit and compliance requests in a timely manner.
  • •Maintain continuous compliance and monitoring of security controls to ensure ongoing adherence to standards.

Pay and Benefits

Salary: USD 112,000 - 208,000 annually
Perks:MedicalDentalVisionCommuter Benefits

Key Requirements

  • •7+ years leading GRC programs and managing compliance certifications and audits (FedRAMP, ISO 27001, HIPAA, SOC1/SOC2, PCI DSS, IRAP)
  • •3+ years as a direct leader managing a team with global scope
  • •Strong knowledge of security frameworks (NIST SP 800-53 Rev 5, NIST 800-171, ITAR, PCI DSS, SOC2, FedRAMP)
  • •Demonstrated ability to influence stakeholders across departments and time zones
  • •Excellent project management, analytical, and problem-solving skills with keen attention to detail
Experience:7+ yearsGRCCybersecurityComplianceFedRAMPPCI DSSSOC2HIPAANIST
Education:Bachelor's
Skills:LeadershipCommunicationStakeholder managementProblem-solvingTeam building
Certifications:FedRAMPISO 27001SOC1SOC2HIPAAPCI DSS
Languages:English
Tech Stack:NISTFedRAMPISO 27001SOC1SOC2PCI DSSHIPAAITARNIST SP 800-53NIST 800-171

Company Brief

Ivalua
Provides a cloud-based procure-to-pay and sourcing platform that helps organizations manage procurement, supplier relationships, sourcing events, and spend analytics to drive cost savings, compliance, and supplier collaboration across global enterprises.
Industry: Procurement Platforms
Company Size: Enterprise (1,001+ employees)
Growth: Established Company
Headquarters: Paris, France
Founded: 2000
WebsiteLinkedIn