SpyCloud logo
SpyCloud

The leader in operationalizing Cybercrime Analytics to prevent ATO, ransomware, and online fraud.

Manager – Governance, Risk and Compliance (GRC)

Location

Texas

Posted

23 days ago

Salary

0

Seniority

Senior

Bachelor Degree6 yrs expEnglishAWSCloudCyber Security

Job Description

Manager – Governance, Risk and Compliance (GRC)

SpyCloud

• Own and manage SpyCloud’s day-to-day GRC and compliance operations across multiple frameworks, including SOC 2, ISO 27001, NIST, and CMMC 2.0. • Lead internal and external audit coordination activities, evidence collection, remediation tracking, and control validation efforts. • Maintain and improve security policies, standards, procedures, and governance documentation. • Drive ongoing compliance readiness activities and operationalize scalable compliance processes across the business. • Partner closely with Legal, Security Engineering, DevOps, and Engineering teams to ensure alignment on security and regulatory requirements. • Conduct enterprise risk assessments and facilitate ongoing risk identification, tracking, remediation, and reporting processes. • Develop and maintain risk registers and support leadership reporting on security and compliance risks. • Lead third-party/vendor risk management activities, including security reviews and vendor assessments. • Support customer trust initiatives, including security questionnaires, compliance inquiries, and due diligence requests. • Partner with DevOps and Security Engineering teams to strengthen cloud security governance across AWS and cloud-native environments. • Ensure security controls are aligned with compliance frameworks and operational best practices. • Support implementation and monitoring of governance controls related to cloud infrastructure, identity management, logging, vulnerability management, and secure development practices. • Contribute to ongoing security awareness and compliance education initiatives across the organization. • Manage and mentor direct report(s), supporting professional growth and operational excellence within the GRC function. • Collaborate with technical and non-technical stakeholders to drive accountability and operational maturity. • Help prioritize remediation efforts and compliance initiatives based on business risk and organizational goals. • Support the Senior Director of Governance, Risk and Information Security in scaling SpyCloud’s overall security governance program.

Job Requirements

  • 6+ years of experience in Governance, Risk, and Compliance (GRC), Information Security, Security Compliance, or related fields.
  • Demonstrated hands-on experience managing operational compliance programs within SaaS, cloud, or cybersecurity environments.
  • Proven experience supporting and maintaining compliance frameworks such as:
  • SOC 2
  • ISO 27001
  • NIST
  • CMMC 2.0
  • Experience leading audits, managing evidence collection, and coordinating remediation activities.
  • Experience with third-party/vendor risk management and enterprise risk assessment processes.
  • Experience working cross-functionally with Legal, Engineering, DevOps, Security, and executive stakeholders.
  • Bachelor's degree in Cybersecurity, Information Security, Computer Science, Business, or related field, or equivalent practical experience.
  • Strong understanding of security governance, compliance operations, and risk management practices.
  • Familiarity with cloud security concepts and governance within AWS or similar cloud environments.
  • Strong organizational and project management skills with the ability to manage multiple priorities simultaneously.
  • Excellent written and verbal communication skills.
  • Ability to translate compliance requirements into practical operational processes.
  • Strong analytical, documentation, and problem-solving skills.

Benefits

  • 401(k) with Employer Contribution
  • Health, Vision, and Dental Insurance
  • Health Savings Account (HSA) available with Employer Contribution
  • Employer Paid Life, Short-term, and Long-term Disability Insurance
  • Generous PTO Plan and 16 paid holidays per year

Related Categories

Related Job Pages

More Compliance Jobs

Vander Weele Group logo

Compliance Oversight Manager

Vander Weele Group

Grants Monitoring, Oversight, and Technical Assistance

Compliance23 days ago
Full TimeRemoteTeam 11-50Since 2003H1B No Sponsor

• Oversee high-priority compliance inspections and reports • Manage a team of 15 to 20 individuals performing inspection deliverables • Transform inspection data into litigation-ready reports • Ensure 100% evidentiary integrity through refined review protocols • Apply a litigation-informed lens to documentation to eliminate reporting vulnerabilities • Standardize interview methodologies to reduce remediation cycles • Synthesize data into high-level risk insight reports with actionable recommendations • Lead the review and validation of inspection reports • Identify inconsistencies across inspection activities and guide corrective action • Coach inspection teams on compliance and evidentiary proof.

United States
$165K - $175K / year
Job Closed
The Leaflet logo

Compliance Monitoring Analyst

The Leaflet

An independent platform for cutting-edge, progressive, legal, and political opinion.

Compliance23 days ago
Full TimeRemoteTeam 11-50H1B No Sponsor

• Conduct regular monitoring activities to ensure business operations comply with applicable laws, regulations, and internal policies • Review and analyze transactions, reports, and other documents to identify potential compliance issues • Assist in the development and implementation of monitoring plans such as daily, weekly, monthly, and/or quarterly checks • Prepare detailed reports of monitoring activities and findings • Communicate findings to the Compliance Assurance Monitoring Manager and other relevant stakeholders • Assist in the preparation of regulatory filings and reports as required • Assist in the review and updating of internal controls, policies, and procedures to ensure they remain current and effective • Provide recommendations for improvements based on monitoring activities and regulatory changes • Participate in the development and delivery of compliance training programs for employees • Promote a culture of compliance and awareness throughout the organization • Support investigations into potential compliance breaches or irregularities • Assist in developing and implementing corrective action plans to address identified issues • Work closely with other departments (e.g. Legal, Finance, Operations) to ensure a coordinated approach to compliance • Liaise with external regulators and auditors as needed • Stay informed about industry trends, regulatory updates, and best practices in compliance monitoring • Contribute to continuous improvement initiatives within the Compliance Assurance team.

New Jersey
Job Closed
Full TimeRemoteTeam 51-200H1B No Sponsor

• Serve as the dedicated IT business partner for the Quality organization; develop a deep understanding of QA processes, priorities, and roadmap to anticipate and address IT needs proactively • Own Veeva Vault Quality (QualityDocs and associated modules) as the IT system owner: manage system configuration, user administration, release management, and enhancement delivery in partnership with QA stakeholders • Translate Quality business requirements into system enhancements, workflow changes, and configuration updates; manage the enhancement backlog and release cycle in coordination with QA and vendors • Advise Quality on system risk, compliant use of technology, and IT implications of process changes; serve as a trusted technical advisor on how systems can best support quality operations • Participate in QA planning meetings and strategic initiatives to ensure IT capabilities and constraints are represented from the outset • Author validation scripts, test protocols, and supporting documentation (IQ/OQ/PQ) for GxP-regulated systems including Veeva Vault, SAS Validated Cloud, Egnyte GxP, and validated MuleSoft integrations; partner with QA for CSV review and approval • Assess system changes for validation impact; manage change control documentation and ensure validated systems are maintained in a compliant state following changes • Conduct and document periodic reviews of validated systems; manage decommissioning procedures in line with regulatory requirements • Own IT inspection readiness across the validated systems portfolio. • Partner with QA to ensure IT systems and electronic records meet 21 CFR Part 11 and other regulatory requirements; lead IT response to inspection findings and drive remediation to closure • Maintain audit-ready evidence packages for GxP systems: audit trail integrity, access control records, system configuration documentation, and change history • Own the IT policy library: author, version, and maintain SOPs and policies covering electronic records, audit trails, access control, change management, data classification, and AI use • Develop and deliver IT compliance training; maintain training records in validated learning management infrastructure • Manage the IT third-party risk management program: vendor tiering, GxP qualification assessments, data handling reviews, and ongoing oversight for technology suppliers and SaaS providers. • Evaluate new technology and AI vendors against Apogee’s governance framework prior to onboarding; coordinate security assessment inputs with the Director of Cybersecurity

United States
$220K - $245K / year
Job Closed
LifeCare Home Health Family logo

Regulatory Operations Specialist

LifeCare Home Health Family

We strive to help you recover safely and independently in the environment you feel most comfortable in...your home.

Compliance23 days ago
Full TimeRemoteTeam 501-1,000H1B No Sponsor

• Support day-to-day PECOS filings, vendor regulatory documentation, and provider credentialing activities. • Prepare and submit PECOS enrollments, revalidations, and updates under supervision. • Collect, organize, and maintain required ownership, managing employee, and practice location documentation. • Track CMS and MAC correspondence and assist with responses. • Collect and maintain required regulatory documentation for vendors and contractors. • Track expirables and ensure timely updates of required certifications and attestations. • Assist with regulatory onboarding and offboarding documentation. • Support credentialing activities, including license verification, certification tracking, and documentation management. • Maintain credentialing files and ensure alignment with enrollment and payer requirements. • Monitor expirables and notify leadership of upcoming renewals. • Maintain regulatory trackers, calendars, and filing logs. • Ensure records are organized, complete, and audit-ready. • Assist with internal audits and data validation reviews. • Coordinate with HR, Compliance, Operations, and Revenue Cycle to gather required information.

Texas