Skip to main content
Accela

Manager, Governance, Risk & Compliance

RemoteUnited States onlyArchived
Published
Role
Security
Experience
Senior
Employment
Full-time
$150k–$170k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

GRC/security compliance manager with 6+ years in security governance, risk, compliance, audit, third-party risk, or cybersecurity. Must be US-based and experienced with audits/compliance programs such as SOC 2, ISO 27001, GovRAMP, PCI DSS, HIPAA, NIST 800-53, or similar frameworks.

Optional skills

GRC platformstrust centersvendor risk platformspolicy management platformscontrol automation tools

What you'll do

  • Lead the governance, risk, and compliance function across security policies, standards, risk management, audits, third-party risk, and control operations.
  • Develop, maintain, and operationalize global security policies, standards, procedures, control documentation, and exception processes.
  • Own audit readiness and ongoing compliance programs across frameworks such as SOC 2, ISO 27001, GovRAMP, PCI DSS, HIPAA, NIST CSF, NIST 800-53, CCPA/GDPR, and other customer or regulatory requirements.
  • Lead GovRAMP and PCI DSS readiness, including control mapping, evidence collection, remediation tracking, stakeholder coordination, audit preparation, and audit support.
  • Coordinate audit evidence collection, control testing, remediation tracking, auditor communication, and management responses.
  • Maintain the security risk register, including identification, assessment, ownership, remediation, acceptance, exception tracking, and executive reporting of security risks.
  • Partner with control owners across Security, IT, Engineering, Legal, HR, Finance, Product, and Operations to ensure control effectiveness and accountability.
  • Manage third-party and supply chain risk management, including vendor security reviews, due diligence, risk assessments, contract security input, and remediation tracking.
  • Support customer security reviews, questionnaires, trust center content, security documentation, and customer-facing compliance responses.
  • Develop metrics and dashboards for audit status, control health, risk posture, vendor risk, policy exceptions, compliance readiness, and remediation progress.
  • Support incident response and privacy incident processes by ensuring regulatory, contractual, audit, and customer notification obligations are understood and tracked.
  • Partner with the CISO to communicate security posture, compliance progress, key risks, control gaps, and trade-offs to executives, customers, auditors, and regulators.
  • Drive continuous improvement of the GRC operating model, including automation, evidence reuse, control rationalization, risk prioritization, and policy lifecycle management.
  • May support incident response activities related to evidence preservation, notification obligations, contractual obligations, and control impact analysis.

What they require

  • 6+ years of experience in security governance, risk management, compliance, audit, third-party risk, or related cybersecurity roles.
  • Experience managing or supporting audits and compliance programs for SOC 2, ISO 27001, GovRAMP, PCI DSS, HIPAA, NIST 800-53, or similar frameworks.
  • Strong understanding of security controls, policy management, risk assessment, control testing, evidence collection, and audit readiness practices.
  • Experience working with auditors, customers, internal stakeholders, and executive leadership.
  • Experience managing third-party risk or vendor security review programs.
  • Ability to translate complex compliance obligations into practical business and technical requirements.
  • Strong project management skills with the ability to manage multiple audits, risks, remediation efforts, and stakeholder workstreams simultaneously.
  • Excellent written and verbal communication skills.
  • Preferred: Experience in SaaS, cloud, public-sector technology, government technology, or regulated environments.
  • Preferred: Experience with GovRAMP, FedRAMP Moderate or High, PCI DSS, NIST 800-53, or other public-sector and payment security compliance frameworks.
  • Preferred: Experience supporting privacy programs involving CCPA, GDPR, HIPAA, or similar requirements.
  • Preferred: Experience developing executive-level risk and compliance reporting.
  • Preferred: Relevant certifications such as CISSP, CISM, CISA, CRISC, ISO 27001 Lead Implementer, or ISO 27001 Lead Auditor.
  • Very light travel may be expected for team or company offsites and industry conferences.

Benefits

  • Eligible for an annual bonus target.
  • Flexible time off.
  • Comprehensive medical plans.
  • Comprehensive dental plans.
  • Comprehensive vision plans.
  • Family planning benefits.
  • 401(k) retirement savings plan with company match.
  • Health savings account with company contributions.
  • Flexible spending account.
  • Life coverage.
  • Accident coverage.
  • Disability coverage.
  • Business travel insurance.
  • Employee assistance programs.
  • Other well-being benefits.
  • Job accommodations available on request.

Accela designs and delivers government software, providing a cloud-based platform of government software solutions for communities and government agencies.

GovTechMid-size

Details

Apply routeGreenhouse
$150k–$170k/yr