F&I Sentinel is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, national origin, gender, sexual orientation, gender identity, age, physical or mental disability, genetic factors, military/veteran status, or other characteristics protected by law.
Governance, Risk & Compliance Manager
Location
United States
Posted
2 days ago
Salary
$70K - $100K / year
Seniority
Lead
No structured requirement data.
Job Description
Governance, Risk & Compliance Manager
F & I Sentinel Llc
Role Description The GRC Manager will operate at the intersection of Legal, IT, Security, and Business Operations, serving as a central point of coordination for governance, risk, and compliance initiatives across the organization. The Governance, Risk & Compliance Manager will work closely with Corporate Counsel to align compliance strategy with regulatory obligations and legal risk considerations. The GRC Manager partners heavily with IT and Information Security teams to translate technical controls and security frameworks into business-aligned processes and documentation. Collaboration with Product and Engineering may be required to ensure that data handling, system controls, and security practices align with compliance requirements. In addition, the position supports client-facing teams including Sales, Account Management, and Customer Success by: - Responding to due diligence requests, security questionnaires, and audit inquiries. - Helping to build trust with lender clients and external stakeholders. The role will also coordinate with Operations and Data functions to support data quality auditing and integrity initiatives. Externally, the GRC Manager will interact with third-party auditors, vendors, and client stakeholders to support audits, vendor risk management, and compliance assurance activities. The GRC Manager will mature and scale the company’s GRC capabilities during a period of growth, offering the opportunity to: - Build structure, drive process improvements, and enhance the company’s compliance posture in a highly regulated environment. - Establish and maintain audit readiness (including SOC 2 Type II). - Strengthen vendor risk management practices. - Improve the efficiency and quality of client-facing due diligence responses. - Translate evolving regulatory and security requirements into actionable, business-aligned controls. This is a highly cross-functional and visible role with the opportunity to influence how compliance, risk, and security practices are operationalized across the organization. The ideal candidate will bring both strategic thinking and hands-on execution, helping F&I Sentinel continue to build credibility with financial institution partners while supporting scalable, sustainable growth. Specifically, the GRC Manager will have responsibility in: - Audit & Certification - Drive SOC 2 Type II audit readiness end-to-end: evidence collection, auditor coordination, and remediation tracking. - Execute internal audit procedures across operations for accuracy, completeness, and compliance. - Document audit findings, develop corrective action plans, and track remediation to closure. - Maintain GRC documentation including control narratives, procedures, and supporting artifacts for continuous audit readiness. - Support BCP, DR, and IR programs, including tabletop exercises and plan testing. - Due Diligence & Security Questionnaire Management - Own and optimize the end-to-end Due Diligence Questionnaire (DDQ) response workflow. - Draft, review, and deliver responses to security questionnaires, Request For Proposals (RFP), and vendor assessments. - Partner with IT, infosec, operations, and leadership to serve as the liaison between technical teams and client-facing engagements. - Exercise sound judgment in determining how to frame sensitive topics and present the company’s security posture accurately. - Develop efficiencies through process improvements, implementation of automation and tools, and standardizing responses. - Vendor Risk Management - Manage and continuously improve the vendor risk program. - Maintain a current inventory of third-party providers with data access or critical dependencies. - Apply and refine risk tiering based on data sensitivity, business impact, and regulatory exposure. - Conduct periodic reviews of critical and high-risk vendors; track remediation of findings and ensure contractual compliance. - Maintain vendor risk documentation that supports audit readiness and DDQ responses. - Risk Management Support - Assist in maintaining the risk register; identify emerging risks and document mitigating controls. - Assist with risk assessments; operationalize mitigation strategies and validate controls. - Data Quality Auditing - Partner with the Data Analyst to define data quality audit criteria and compliance-focused reporting requirements. - Review data quality results for accuracy and completeness; identify and escalate data integrity issues. - Design data checks and guardrails that ensure operational data integrity across products. Qualifications - 3–6+ years of professional working experience. - Hands-on experience with SOC 2 audits, either managing or as a key contributor. - Working knowledge of security frameworks such as NIST CSF, ISO 27001, FTC Safeguards Rule, or similar. - Proven ability to draft and manage security questionnaire responses for enterprise clients. - Strong written communication skills. - Ability to operate independently, manage multiple workstreams, and escalate appropriately. - Comfort working in a fully remote environment with a distributed team. Requirements - Experience in fintech, insurtech, automotive finance, or another regulated industry (preferred). - Familiarity with F&I (Finance & Insurance) products or the automotive dealer ecosystem (preferred). - Exposure to vendor/third-party risk management programs (preferred). - Understanding of basic data privacy requirements (CCPA, state privacy laws) (preferred). - Experience with data quality analysis and reporting tools (preferred). - Bachelor's degree in Information Systems, Business, Accounting, Risk Management, or a related field; relevant certifications such as CISA, CRISC, or GRCP are a plus (preferred). Benefits - Opportunity to build and shape foundational GRC processes and programs. - High visibility role with direct impact on client trust, audit outcomes, and enterprise risk posture. - Exposure to a unique intersection of fintech, automotive finance, and regulatory compliance. - Collaborative, cross-functional environment with access to leadership and influence on strategic decisions. - Hybrid/remote culture offering flexibility and autonomy. - Competitive compensation and benefits, with opportunity for growth as the company scales. Company Description F&I Sentinel is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, national origin, gender, sexual orientation, gender identity, age, physical or mental disability, genetic factors, military/veteran status, or other characteristics protected by law.
Related Guides
Related Categories
Related Job Pages
More Compliance Jobs
Regional Regulatory Affairs & Compliance Specialist, Fintech
OptasiaWe deliver Optasia, the AI Platform enabling financial access for the next billion customers.
• Act as the first line of contact and engagement with relevant regulators to proactively manage and mitigate the potential impact of new regulations. • Drive and/or support the establishment of horizon scanning activities and early warning signals of upcoming changes in relevant regulations. • Support the Head of Regulator Affairs & Compliance and Regulatory Compliance Managers in matters related to Regulatory Affairs & Compliance strategy. • Understand relevant laws and regulations and monitor company compliance. • Support the Regulatory Compliance Managers in performing structured assessments of our regulatory compliance. • Support the implementation of a robust regulatory compliance governance framework, including training activities. • Develop marketing materials and training programs to ensure alignment with regulatory compliance guidelines. • Perform various general administrative duties in response to regulatory compliance queries. • Support the business in responding to queries related to compliance with legal obligations. • Be a business partner to local commercial teams to facilitate the go-to-market process.
Regional Regulatory Affairs & Compliance Specialist, Fintech
OptasiaWe deliver Optasia, the AI Platform enabling financial access for the next billion customers.
• Act as the first line of contact and engagement with relevant regulators to proactively manage and mitigate the potential impact of new regulations, reporting obligations and prudential guidelines, in a given regional portfolio, may have on our operations. • Drive and/or support the establishment of horizon scanning activities and early warning signals of upcoming and potential changes in relevant regulations in the given regional portfolio, and disseminate those internally through the appropriate channels to impacted teams. • Support the Head of Regulator Affairs & Compliance and Regulatory Compliance Managers, as may be required, in matters related to the broader Regulatory Affairs & Compliance strategy and activities in a given regional portfolio. • Understand relevant laws and regulations governing our operations, and continually monitor company compliance with new regulations, reporting obligations and prudential guidelines in a given regional portfolio. • Support the Regulatory Compliance Managers, as required, in performing structured assessments of our regulatory compliance to specific requirements and obligations in a given regional portfolio to assess our regulatory risk exposure, its significance and scope. • Support the implementation of a robust and effective regulatory compliance governance framework within the organization, including training and awareness activities to educate employees on relevant regulations and prudential guidelines and collaborate with other departments and relevant stakeholders to create a culture of regulatory compliance. • Develop marketing materials, training programs and relevant internal presentations to ensure alignment with regulatory compliance prudential guidelines in the given regional portfolio. • Perform various general administrative duties; such as gathering of internal information in response to regulatory compliance queries, and reporting obligations from relevant internal and external stakeholders. • Support the business in effectively and timely responding to queries raised by our partners, financial institutions or other third-parties, related to the compliance with our legal and contractual obligations resulting from new or existing business relationships, such as for instance third-party due diligence requirements, supplier onboarding processes, periodic reporting requirements, or any other as required. • Be a business partner to the local commercial teams to facilitate the go-to-market process in the given regional portfolio, as well as responding to existing customer queries related to existing or new regulatory requirements. • Primary responsibility for this role will be for the East Africa region, therefore the ideal candidate shall demonstrate working knowledge and understanding of the regulatory and oversight bodies, governance and operating principles within Kenya, Uganda, Ethiopia, Somalia, South Sudan and Tanzania. • Act as a regional partner to other internal assurance providers, including Internal Audit, as required, to support the delivery of activities within the scope of the Company’s combined assurance arrangements.
NERC CIP Compliance Lead
Intersect PowerIntersect Power is a clean energy company that brings scalable and innovative, low-carbon solutions to its customers in wholesale energy and retail markets. The company develops so
• Help strengthen the systems, processes, and controls that support secure and reliable energy infrastructure operations • Lead initiatives that improve regulatory readiness, cybersecurity resilience, operational continuity, and long-term infrastructure sustainability across critical operational environments • Drive NERC CIP Compliance Excellence by leading and operationalizing compliance programs across critical infrastructure • Manage compliance initiatives that support audit readiness, evidence management, remediation tracking, and regulatory reporting • Partner with internal stakeholders to maintain alignment with evolving NERC CIP standards and regulatory expectations • Collaborate with OT Security, IT, and Operations teams to improve cybersecurity controls across operational technology environments • Support vulnerability management, patch management, and baseline configuration management processes across regulated systems • Develop and improve scalable governance processes, documentation standards, and operational compliance workflows • Partner closely with technical, operational, and compliance stakeholders to align security objectives with operational priorities • Provide leadership during audits, remediation efforts, and regulatory assessments
Senior Manager, Clinical Compliance
OVME AestheticsWe believe the needs of the medical aesthetics consumer have evolved beyond the industry landscape.
- **Multi-state regulatory monitoring** — track changing aesthetic, medical, and licensing regulations across all OVME operating states; translate changes into operational implications for the business. - **Licensing & renewals** — own the cadence and execution of state licensing, facility licensing, and provider credentialing renewals across the network. Nothing lapses on your watch. - **MD relationships + new location signing** — partner with the Sr. Director and the operations team to secure MD relationships for new studio openings; manage the contracted state-by-state Medical Director roster. ****COMPLIANCE PROGRAMS** - **HIPAA, OSHA, privacy** — own HIPAA, OSHA, and patient privacy compliance programs across the studio network. - **Internal audit cadence** — design and run the internal audit rhythm; surface gaps proactively, not reactively. - **Adverse event documentation & reporting** — own the documentation, regulatory reporting, and trend tracking on adverse events. Clinical response sits with the Sr. Director; you own the paper trail and the reporting obligations. - **Marketing compliance review** — review marketing claims, treatment descriptions, and promotional content for regulatory and clinical accuracy before publication. ****EXTERNAL & LEGAL** - **Outside counsel liaison** — primary point of contact for OVME's outside compliance and regulatory counsel; manage the relationship and the scope of engagements.


