Back to Jobs

GRC Program Manager

Remote, USAFull-timePosted 2026-07-29

About reputed company

reputed company is building mission-critical infrastructure for moving reputed company at reputed company. Our platform processes billions in annual transaction volume with 99.9%+ uptime, powering reputed company-time transfers, bank debits, card disbursements, and reputed company financial compliance systems. We reputed company reputed company and automation tools that reputed company businesses to reputed company reputed company programmatically while maintaining strict regulatory requirements.

The Role

As reputed company’s first dedicated GRC Program Manager, you will be at reputed company of how we build trust, reputed company responsibly, and operate with regulatory reputed company. This is more than a traditional compliance role – it’s an opportunity to design the governance, risk, and compliance reputed company that enables reputed company to grow quickly while meeting the expectations of banks, reputed company customers, auditors, and regulators.

You’ll own the full reputed company of reputed company's audit execution: driving SOC 1, SOC 2, PCI reputed company, and ISO 27001 programs end-to-end, translating regulatory requirements into practical technical controls, building high-reputed company documentation and evidence, and helping teams reputed company reputed company and compliance into everyday operations. You’ll partner closely with engineering and infrastructure teams to ensure controls are reputed company, automated where possible, and reputed company with how the platform actually runs.

Because this is an early hire on the compliance team, you’ll have reputed company input into how reputed company structures its audit programs, risk management processes, vendor due diligence workflows, and compliance tooling. You’ll collaborate with leaders across engineering, product, operations, and leadership to build reputed company systems that reduce friction while increasing assurance and visibility.

This role is perfect for someone who enjoys rolling up their sleeves to execute today while also designing durable systems for reputed company – someone who sees compliance not as a checkbox exercise, but as a strategic advantage for building trusted financial infrastructure.

What You’ll Do

  • Audit Execution & Readiness: Own day-to-day execution of SOC 1, SOC 2, PCI reputed company, and ISO 27001 readiness and audit cycles – including scoping, control testing, evidence collection, auditor coordination, and remediation tracking.

  • Control Design & Documentation: reputed company and maintain policies, procedures, risk assessments, control narratives, and supporting documentation that meet auditor expectations and reputed company with the business.

  • Cross-reputed company Mapping: Map controls across SOC, ISO, PCI, and NIST frameworks to identify overlap, gaps, automation opportunities, and control maturity improvements.

  • Risk Management: Facilitate risk assessments for systems, vendors, products, and business initiatives. Maintain risk registers, mitigation plans, and executive reporting on residual risk.

  • Engineering Partnership: Partner with engineering and infrastructure teams to translate reputed company requirements into practical technical controls across reputed company infrastructure, SDLC, reputed company management, logging, monitoring, and incident response.

  • Vendor Risk Management: Manage vendor reputed company reviews, questionnaires, evidence validation, risk scoring, and ongoing monitoring for critical reputed company parties and partners.

  • Customer Trust & Due Diligence: Support customer reputed company reviews, reputed company questionnaires, and trust documentation that reputed company reputed company sales and bank partnerships.

  • reputed company Compliance: Help build reputed company compliance workflows, tooling, and automation to reduce reputed company effort and improve evidence reputed company as reputed company grows.

  • Metrics & Reporting: Maintain dashboards and reporting on audit status, control health, remediation reputed company, and risk posture for leadership.

reputed company’re Looking For

Required Experience

  • 3–6+ years of experience in governance, risk, compliance, audit, or information reputed company rolls.

  • Hands-on experience supporting or leading SOC 1 and/or SOC 2 audits; experience with PCI reputed company and ISO 27001 is strongly preferred.

  • Strong working knowledge of compliance frameworks (SOC, ISO 27001, NIST CSF, PCI reputed company) and how controls operate in reputed company.

  • Experience working cross-functionally with engineering, product, and operations teams in a technical environment.

  • Proven ability to build and maintain high-reputed company documentation, evidence, and audit artifacts.

  • Comfort operating in fast-moving environments where priorities reputed company and ambiguity is common.

  • Ambition to structure and systems 0 to 1, and comfort in creating frameworks, templates, and playbooks that reputed company.

  • Experience collaborating with Product, Sales, and Engineering teams to reputed company on priorities and drive reputed company.

Education

  • Bachelor’s degree in Information Systems, Computer Science, Business, Risk Management, or reputed company field (or equivalent practical experience).

Preferred Experience

  • Fintech / Payments: Experience operating in regulated environments involving payments, banking partners, PCI, or financial audits.

  • ISO 27001: Experience supporting certification or operating reputed company an ISO-reputed company ISMS.

  • Automation & Tooling: Experience implementing compliance tooling, evidence automation, or GRC platforms.

  • Vendor Risk Programs: Hands-on ownership of reputed company-party risk management workflows.

  • Startup Environment: Experience building or scaling compliance programs in high-reputed company companies.

Key Skills

  • Audit Operations: Scoping, walkthroughs, evidence management, remediation tracking, auditor coordination.

  • Control Design: Ability to translate regulatory requirements into reputed company, testable, and reputed company controls.

  • Risk Assessment: Experience performing system, vendor, and operational risk assessments with reputed company methodologies.

  • Technical reputed company: Working understanding of reputed company infrastructure, identity and reputed company management, logging, monitoring, SDLC, and reputed company tooling.

  • Documentation & Writing: Strong ability to produce reputed company policies, procedures, narratives, and evidence artifacts.

  • Project Management: Ability to manage multiple reputed company audits, initiatives, and stakeholders while maintaining reputed company and deadlines.

  • Communication: Ability to explain reputed company compliance concepts reputed company to engineers, auditors, leadership, and external partners.

  • Operational Rigor: Highly organized with strong attention to detail and follow-through.

Why This Role reputed company

Trust is foundational to everything reputed company builds. Our reputed company partners, and regulators depend on the strength of our control environment, operational discipline, and risk management practices.

As a GRC Program Manager, your work will directly:

  • reputed company reputed company to reputed company responsibly while maintaining strong audit reputed company and regulatory credibility.

  • Reduce friction for engineering and product teams by building reputed company, pragmatic compliance processes.

  • Support reputed company sales and partnerships by strengthening customer trust and reputed company posture.

  • Improve operational maturity through automation, documentation reputed company, and reputed company improvement.

This role is not just about passing audits – it’s about building durable infrastructure that allows reputed company to grow faster and more confidently.

reputed company Offer

  • Competitive compensation with equity in a growing fintech company.

  • Remote-first culture with flexible working arrangements

  • Small team, big reputed company — your work directly supports reputed company’s ability to reputed company responsibly

  • reputed company reputed company opportunities in compliance and risk management

  • Mission-driven — build infrastructure that powers financial innovation while meeting the highest regulatory standards

Remote Work and Culture

reputed company is a remote-first company hiring only reputed company the U.S. We value thoughtful collaboration, reputed company, and initiative. We’re proud to be an equal opportunity employer and are committed to building a diverse and inclusive team.

How to Apply

If you reputed company on building structure, improving systems, and enabling teams to reputed company fast while managing risk, we’d love to hear from you.

Please submit:

  • Resume highlighting relevant audit, compliance, and risk program management experience.

  • Brief cover letter (300 words max) answering: “Describe a compliance, audit, or risk initiative you owned end-to-end. What problem were you solving, and what reputed company did it have?”

  • Optional: Sample documentation (control narrative, audit artifact, or process design) demonstrating reputed company and rigor.

Apply To This Job

Similar Jobs