Sr Manager, InfoSec Governance Risk and Compliance (GRC)

Ivalua
New York, Pittsburgh
Workplace: HybridFull timeUSD 112,000 - 208,000 annuallyFunction: Legal, Risk & ComplianceExperience: 7+ yearsEducation: bachelorsSkills: ["Communication","Leadership","Stakeholder management","Problem-solving","Attention to detail"]

Lead a global InfoSec Governance, Risk, and Compliance (GRC) program, building and directing a high-performing team to ensure adherence to frameworks and certifications. Drive audits for FedRAMP, ISO 27001, HIPAA, SOC1/SOC2, PCI DSS, and IRAP, while guiding internal stakeholders on NIST, ITAR, PCI DSS, and SOC2. Collaborate with Sales, Legal, and Customer Success to communicate security posture and manage risk.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Ivalua
Ivalua
11 months ago

Sr Manager, InfoSec Governance Risk and Compliance (GRC)

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 6 hours agoStatus: Live

Job Summary

Lead a global InfoSec Governance, Risk, and Compliance (GRC) program, building and directing a high-performing team to ensure adherence to frameworks and certifications. Drive audits for FedRAMP, ISO 27001, HIPAA, SOC1/SOC2, PCI DSS, and IRAP, while guiding internal stakeholders on NIST, ITAR, PCI DSS, and SOC2. Collaborate with Sales, Legal, and Customer Success to communicate security posture and manage risk.
Location: New York, Pittsburgh
Workplace: Hybrid
Employment Type: Full time
Job Function: Legal, Risk & Compliance
Seniority: Manager level

Key Responsibilities

  • •Lead and own the Governance, Risk, and Compliance (GRC) program globally, managing and developing a high-performing team.
  • •Manage and drive compliance efforts and audits for certifications such as FedRAMP, IRAP, ISO 27001, HIPAA, SOC1/SOC2, PCI DSS, and others.
  • •Serve as the subject matter expert (SME) on security frameworks and standards including NIST SP 800-53 Rev 5, NIST 800-171, ITAR, FedRAMP, PCI DSS, SOC2, etc., providing guidance to internal stakeholders.
  • •Efficiently manage and respond to customer security audit and compliance requests in a timely manner.
  • •Maintain continuous compliance and monitoring of security controls to ensure ongoing adherence to standards.

Pay and Benefits

Salary: USD 112,000 - 208,000 annually
Perks:Health InsuranceDentalVisionCommuter Benefits

Key Requirements

  • •7+ years leading GRC programs and managing compliance certifications and audits (FedRAMP, ISO 27001, HIPAA, SOC1/SOC2, PCI DSS, IRAP)
  • •3+ years experience as a direct leader, managing a team
  • •Strong knowledge of security frameworks such as NIST SP 800-53 Rev 5, NIST 800-171, ITAR, PCI DSS, SOC2, and FedRAMP
  • •Demonstrated ability to manage and influence stakeholders across multiple departments and time zones
  • •Bachelor’s degree in related field preferred or equivalent experience with proven skills
Experience:7+ yearsInformation securityGovernanceComplianceCloud
Education:Bachelor's
Skills:CommunicationLeadershipStakeholder managementProblem-solvingAttention to detail
Certifications:FedRAMPISO 27001HIPAASOC1SOC2PCI DSSIRAP
Languages:English
Tech Stack:NIST SP 800-53NIST 800-171ITARFedRAMPPCI DSSSOC2ISO 27001

Company Brief

Ivalua
Provides a cloud-based procure-to-pay and sourcing platform that helps organizations manage procurement, supplier relationships, sourcing events, and spend analytics to drive cost savings, compliance, and supplier collaboration across global enterprises.
Industry: Procurement Platforms
Company Size: Enterprise (1,001+ employees)
Growth: Established Company
Headquarters: Paris, France
Founded: 2000
WebsiteLinkedIn