> Markdown version of [/jobs/ext/1154431-grc-incident-manager](https://www.wearedevelopers.com/jobs/ext/1154431-grc-incident-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # GRC & Incident Manager - **Company:** Lendistry, LLC. - **Location:** Los Angeles, CA, United States - **Experience:** Experienced - **Salary:** $118,300.0 - $136,300.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Document Management Systems, Information Technology - **Published:** July 2, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=0723b13dbed8b22e ## About the Role * 3-5 years of experience in incident response, GRC, or risk management, preferably in a regulated environment such as fintech or financial services. * Direct experience serving as Incident Commander or in a comparable incident leadership role, including running IAPs and post-incident reviews. * Familiarity with SOC 2 and GLBA Safeguards Rule compliance programs; working knowledge of ISO/IEC 27001. * Experience building and tracking KPIs/metrics for incident response and compliance programs. * Strong written documentation skills; comfortable producing audit-ready records under time pressure. * Professional certifications such as ICS-100/200 preferred. * Bachelor's degree in Computer Science, Information Security, or related field, or equivalent experience/certifications., This is a stationary position that requires frequent sitting (approximately 95%), repetitive wrist motions, grasping, speaking, listening, close vision, and the ability to adjust focus. It also may require occasional standing, lifting, carrying of 20lbs or less, walking, kneeling, bending/stooping, twisting, pulling/pushing, and reaching above the shoulder. Employees in this position must be physically able to efficiently perform the essential functions of the position. ## Description The GRC Incident Manager leads the organization's security and operational incident response function while supporting the GRC program that keeps the company audit-ready. This role owns incident command from detection through resolution, directs cross-functional response across Security, Engineering, IT, Legal, Compliance, Communications, Facilities, HR, and Executive Leadership, and translates each incident into measurable improvement through KPIs, after-action documentation, and updated controls. The role also supports ongoing compliance obligations (SOC 2, GLBA Safeguards Rule, ISO/IEC 27001) so that incident response and compliance posture reinforce each other rather than operating as separate functions., * Serve as Incident Commander for security and operational incidents, holding full command and control over response activities. * Build, execute, and maintain Incident Action Plans (IAPs) that give each response a clear structure, owner, and timeline. * Make time-sensitive decisions under pressure, weighing safety, regulatory exposure, and business continuity. * Lead post-incident reviews and drive corrective actions through to closure. * Run tabletop exercises and simulations to pressure-test playbooks and team readiness. Physical Security Operations * Manage physical security incidents, including unauthorized access, safety threats, and facility disruptions. * Coordinate with Facilities, HR, Legal, and local authorities as needed during physical security events. * Ensure physical security controls align with cybersecurity, business continuity, and compliance programs. Cross-Functional Collaboration * Act as the central point of coordination between technical responders and non-technical stakeholders during an incident. * Direct and coordinate Security Operations, Engineering, IT, Legal, Compliance, Communications, and Executive Leadership throughout the incident lifecycle. * Engage external parties - law enforcement, emergency services, regulators, and vendors - when an incident requires it. * Partner with Security, Engineering, and Compliance to keep response playbooks and escalation paths current. Compliance Management * Support the SOC 2 compliance program (Type I and Type II) - assisting with control ownership, evidence collection, auditor coordination, and remediation tracking. * Support alignment with ISO/IEC 27001, including risk assessments, Statement of Applicability support, and control mapping. * Support GLBA Safeguards Rule obligations, including related vendor oversight and risk documentation. * Conduct periodic risk assessments and control-effectiveness reviews across people, process, and technology. * Support regulator, auditor, and customer due-diligence requests. KPIs & Metrics * Define and track incident response metrics (e.g., time to detect, time to contain, time to resolve, recurrence rate) to measure program maturity. * Develop compliance KPIs (control exceptions, remediation aging, audit findings closure rate) for leadership reporting. * Use trend data from incidents and audits to prioritize control investment and process changes. * Report metrics and program status to Executive Leadership on a recurring cadence. Documentation * Maintain incident response plans, IAP templates, and after-action reports. * Maintain GRC documentation - policies, standards, procedures, and the risk register - under a continuous-compliance model. * Document control evidence, audit responses, and remediation records to support SOC 2, ISO 27001, and GLBA audits. * Keep playbooks, escalation matrices, and contact trees current and accessible. ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [Same Tower, New Confusion: The Tower of Babel 2.0](https://www.wearedevelopers.com/videos/100101-same-tower-new-confusion-the-tower-of-babel-2-0) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [It's not easy being green](https://www.wearedevelopers.com/videos/558-it-s-not-easy-being-green) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Biggest German Tech Companies](https://www.wearedevelopers.com/magazine/424-the-biggest-german-tech-companies) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)