> Markdown version of [/jobs/ext/2653587-it-governance-risk-and-compliance-grc-manager](https://www.wearedevelopers.com/jobs/ext/2653587-it-governance-risk-and-compliance-grc-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Governance, Risk, and Compliance (GRC) Manager - **Company:** Valvoline Inc. - **Location:** United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Control Objectives for Information and Related Technology (COBIT), Cyber Security, Information Systems, IT Management, Information Systems Security Architecture Professional, IT General Controls (ITGC), Information Technology, Servicenow - **Published:** August 9, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=462a54c2e5763395 ## About the Role o Minimum Required: Bachelor's degree in Information Security, Cybersecurity, Information Technology, Computer Science, Information Systems, Business Administration, Accounting, Finance, Engineering, or a related field. o Preferred: Master's degree in Business Administration (MBA), Information Security, Cybersecurity, Information Systems, or a related discipline. Work Experience: o Minimum of 8 - 10 years of progressively responsible experience in information security governance, risk management, compliance, information security, internal audit, enterprise risk management, or related disciplines. o Minimum of 3 - 5 years of experience leading teams, large cross-functional programs, or enterprise governance initiatives with accountability for strategic planning, execution, and stakeholder management. o Demonstrated experience developing, implementing, and maintaining enterprise governance, risk, and compliance programs within a global organization. o Experience managing information security governance, regulatory compliance, internal and external audits, IT general controls (ITGCs), risk assessments, and third-party risk management activities. o Experience partnering with Legal, Internal Audit, Information Technology, Enterprise Architecture, and business stakeholders to implement governance and compliance initiatives. o Experience supporting customer security questionnaires, contractual security requirements, customer audits, or other customer assurance activities is preferred. o Experience working with governance, risk, and compliance platforms such as ServiceNow GRC, OneTrust, Archer, MetricStream, or similar solutions is preferred. Licenses and Certifications - Professional certifications such as Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), Certified Data Privacy Solutions Engineer (CDPSE), or Certified Information Privacy Professional (CIPP) are preferred. Project Management Professional (PMP) or equivalent program management certification is also desirable. Competencies Desired * Comprehensive knowledge of information security governance, risk management, compliance, and industry frameworks, including NIST Cybersecurity Framework (CSF), ISO 27001, COBIT, and related best practices. * Strong understanding of regulatory, contractual, and customer information security requirements, including privacy, third-party risk, IT general controls (ITGCs), and audit practices. * Demonstrated ability to develop, implement, and continuously improve enterprise governance programs, policies, standards, and procedures. * Exceptional written and verbal communication skills, including the ability to communicate complex information clearly and effectively to executive leadership, auditors, customers, and non-technical stakeholders. * Proven ability to influence cross-functional teams, build consensus, and lead enterprise initiatives without direct authority. * Strong program and project management skills, with the ability to coordinate multiple initiatives, manage competing priorities, and deliver results in a dynamic environment. * Excellent analytical, critical thinking, and risk-based decision-making skills, with the ability to identify dependencies, assess business impact, and develop practical, well-supported recommendations. * Demonstrated initiative, accountability, and ownership, with the ability to independently drive work to completion, proactively communicate risks and issues, and follow through on commitments. * Strong leadership and people development skills, including coaching, mentoring, performance management, and fostering a culture of continuous improvement. * Experience with governance, risk, and compliance technologies, workflow automation, and metrics-driven program management. * Ability to build and maintain effective working relationships with internal stakeholders, customers, auditors, regulators, vendors, and other external partners. * Ability to balance business objectives with sound information security governance and risk management practices while maintaining a customer-focused mindset. ## Description The Manager, IT Governance, Risk, and Compliance (IT GRC) is responsible for leading the organization's information security governance, risk management, compliance, and assurance programs. This role provides leadership for enterprise governance initiatives that strengthen the organization's security posture, ensure compliance with legal, regulatory, and contractual obligations, and support informed risk-based decision making across the enterprise. The Manager is responsible for the organization's Information Security Governance Framework, including governance policies, standards, procedures, compliance oversight, exception management, security awareness, privacy governance, third-party risk management, IT general controls, customer assurance activities, and continuous improvement initiatives. This role also serves as the primary leader for the organization's IT/OT cybersecurity maturity program, driving cross-functional collaboration, executive reporting, and ongoing improvement of the organization's security capabilities. As a strategic partner to Information Technology, Legal, Internal Audit, Enterprise Architecture, Privacy, and business leadership, the Manager ensures that governance processes are practical, measurable, and aligned with organizational objectives. The role leads customer assurance activities, including responses to customer security questionnaires, contractual security requirements, customer attestations, security assessments, and external assurance programs. The Manager also serves as the primary liaison with internal and external auditors, ensuring governance processes and controls effectively support regulatory, contractual, and business requirements. Success in this role requires a leader who can influence across organizational boundaries, communicate effectively with executive leadership, independently drive complex programs to completion, and balance business objectives with sound information security governance and risk management practices. How You Make an Impact (Job Accountabilities) * Governance Leadership and Program Management (30%) - Provide strategic leadership for the IT Governance, Risk, and Compliance (IT GRC) function, ensuring governance activities align with business objectives and the organization's information security strategy. Lead the IT/OT cybersecurity maturity program, including executive reporting, Steering Committee governance, Aramco reporting, and cross-functional coordination to drive continuous improvement across the enterprise. * Compliance, Audit, and Risk Management (20%) - Direct the organization's information security compliance, enterprise IT risk management, privacy governance, and IT general controls programs. Serve as the primary liaison with Internal Audit and external auditors, coordinating audits, managing remediation activities, maintaining the cyber risk register, and ensuring regulatory, contractual, and internal control requirements are effectively addressed. * Customer Assurance and Third-Party Risk (20%) - Lead customer assurance and third-party risk management activities by overseeing customer security questionnaires, contractual security requirements, customer attestations, security assessments, and third-party security reviews. Partner with Legal, Procurement, Sales, Privacy, and business stakeholders to ensure customer and supplier security requirements are evaluated, communicated, and managed through consistent governance processes. * Information Security Governance Framework (20%) - Own the organization's Information Security Governance Framework, including governance policies, standards, procedures, exception management, security awareness governance, compliance monitoring, and governance metrics. Ensure governance documentation remains aligned with regulatory requirements, industry frameworks, and evolving business objectives while driving continuous improvement across the governance program. * Team Leadership and Continuous Improvement (10%) - Lead, develop, and mentor the IT GRC team by establishing clear priorities, promoting professional growth, and fostering a culture of accountability, collaboration, and continuous improvement. Build strong relationships across Information Technology and business functions while driving operational excellence throughout the GRC organization., We are committed to ensuring accessibility throughout our recruitment process. If you require a reasonable accommodation to participate in any stage of the recruitment or selection process, please contact us at:. * Email: Valvolineglobalcareers@valvolineglobal.com This contact information is solely for accommodation requests. For inquiries about application status, please use the appropriate channels listed in your application materials. ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Your Manager Doesn’t Come with a User Manual (But You Can Totally Write One)](https://www.wearedevelopers.com/videos/1495-your-manager-doesn-t-come-with-a-user-manual-but-you-can-totally-write-one) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Engineering/Manager Pendulum: Generating compound interest on your career](https://www.wearedevelopers.com/videos/100348-engineering-manager-pendulum-generating-compound-interest-on-your-career) - [How to govern Vibe Coding for the Enterprise](https://www.wearedevelopers.com/videos/100290-how-to-govern-vibe-coding-for-the-enterprise) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Velocity with Guardrails: How Technical Teams Can Move Fast Without Losing Decision Integrity](https://www.wearedevelopers.com/magazine/747-velocity-with-guardrails-how-technical-teams-can-move-fast-without-losing-decision-integrity) - [How to Write a CV and Interview if You Don't Fully Qualify For The Job](https://www.wearedevelopers.com/magazine/183-how-to-write-a-cv-and-interview-if-you-don-t-fully-qualify-for-the-job) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)