> Markdown version of [/jobs/ext/3051883-grc-manager](https://www.wearedevelopers.com/jobs/ext/3051883-grc-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # GRC Manager - **Company:** G2 LLC - **Location:** Chicago, IL, United States - **Experience:** Expert - **Salary:** $120,000.0 - $131,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software as a Service, Cloud Computing Security, Cyber Security, IT Management, PCI Data Security Standards - **Published:** September 24, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=f4cd6fdfb6e09792 ## About the Role * 7-10 years of progressive experience in IT Governance, Risk, and Compliance or information security, including direct ownership of a compliance program. * Deep working knowledge of SOC 2 Type II, ISO 27001, NIST CSF, and common SaaS/cloud security and privacy frameworks (e.g., PCI DSS, GDPR, CCPA). * Hands-on experience with a modern GRC/compliance automation platform (e.g., Vanta, Drata, OneTrust, or similar) used to manage controls, evidence, and risk at scale. * Proven experience managing high-volume customer security questionnaires and knowledge-library programs, including large enterprise reviews. * Experience running a third-party/vendor risk management program, including risk scoring and remediation tracking. * Experience managing DSAR or other privacy request workflows in line with regulatory timelines. * Track record serving as primary point of contact for external auditors through full audit cycles, with strong control-testing and remediation experience. * Excellent written and verbal communication skills, including experience presenting risk and compliance status to executive stakeholders and customers. * Strong prioritization and program-management skills, with the ability to manage a high-volume, multi-workstream caseload independently as a senior individual contributor. * Demonstrated ability to influence and align cross-functional partners (Legal, Engineering, IT, Sales) without formal authority over their teams., * CISSP, CRISC, CISM, or CISA certification. * Experience leading an organization through initial ISO 27001 certification or a comparable new-framework rollout. * Familiarity with procurement-to-GRC integrations and automating vendor intake into a risk workflow. * Working knowledge of global privacy regulations (GDPR, CCPA, LGPD) and experience partnering with Legal on data protection matters. * Experience managing a GRC program budget and vendor/contract relationships (audit firms, tooling, advisory partners). * Track record operating as a senior individual contributor who drives outcomes through influence and cross-functional partnership rather than direct authority. Our Commitment to Inclusivity and Diversity ## Description Summary of Responsibilities: The Governance, Risk, and Compliance (GRC) Manager owns G2's day-to-day security compliance and risk program, and is the senior operator responsible for keeping our customer trust commitments, audit obligations, and risk posture on track. This role runs a high-volume operation: customer security questionnaires, vendor risk reviews, policy governance, DSAR processing, audit management, and risk register maintenance. This manager is expected to bring the judgment to prioritize competing demands, the process discipline to scale a growing workload, and the maturity to represent G2 directly to customers, auditors, and executive stakeholders. This is a senior individual-contributor role. Success depends on the ability to work as a trusted partner across the business: Legal, Security Engineering, IT, Sales, and executive leadership all rely on this person to move their goals forward, whether that's closing a deal that's stuck on a security questionnaire, unblocking an audit finding, or getting a policy approved. The ideal candidate has run a GRC program at this scale before: comfortable working inside modern compliance tooling (e.g., Vanta), fluent in SOC 2 Type II and ISO 27001, and experienced translating technical risk into business language for both customers and leadership. Detailed Responsibilities: In this role, you will be responsible for the following: * Own and administer G2's security policy library (35+ documents), leading the annual review cycle, managing approvals, and ensuring no policy lapses past its renewal date. * Lead response to customer and prospect security questionnaires - from short-form intake to 100+ question enterprise reviews - and maintain the security knowledge library that powers fast, accurate answers at scale. * Own G2's public Trust Center and serve as the company's front-line representative to customers and partners on security and compliance matters. * Run the third-party/vendor risk management program, reviewing AI-assisted vendor risk assessments, making final risk-level determinations, and driving remediation of high-risk findings. * Manage data subject access request (DSAR) intake and fulfillment, ensuring requests are documented and resolved within regulatory timelines. * Support security addendum and contract redlines, partnering with Legal and counterparties through multiple negotiation rounds to close terms. * Maintain and mature enterprise risk registers across business functions, driving treatment plans, control linkage, and quarterly reassessment to closure. * Lead SOC 2 Type II and ISO 27001 audit cycles end-to-end - evidence collection, control testing, and serving as primary point of contact for auditors. * Manage the GRC tooling and vendor ecosystem (compliance platforms, audit firms, privacy tooling), including contract renewals and budget oversight. * Build and deliver executive-level dashboards and reporting on program health, audit status, and risk posture to leadership. * Advise internal teams on the effectiveness of corrective action plans following audit findings, control gaps, or compliance incidents. * Partner cross-functionally with Legal, Security Engineering, IT, Sales, and other business functions as the connective tissue between their goals and G2's compliance and risk requirements. * Identify where process or automation would relieve bottlenecks, and build the business case for that investment. ## Related Videos - [Your Manager Doesn’t Come with a User Manual (But You Can Totally Write One)](https://www.wearedevelopers.com/videos/1495-your-manager-doesn-t-come-with-a-user-manual-but-you-can-totally-write-one) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Beyond the Hype: Building Trustworthy and Reliable LLM Applications with Guardrails](https://www.wearedevelopers.com/videos/1594-beyond-the-hype-building-trustworthy-and-reliable-llm-applications-with-guardrails) - [How to govern Vibe Coding for the Enterprise](https://www.wearedevelopers.com/videos/100290-how-to-govern-vibe-coding-for-the-enterprise) - [Engineering/Manager Pendulum: Generating compound interest on your career](https://www.wearedevelopers.com/videos/100348-engineering-manager-pendulum-generating-compound-interest-on-your-career) - [Great DevEx and Regulatory Compliance - Possible?](https://www.wearedevelopers.com/videos/1426-great-devex-and-regulatory-compliance-possible) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Résumé-Driven Development: How IT trends affect the job market for software developers](https://www.wearedevelopers.com/magazine/59-resume-driven-development-how-it-trends-affect-the-job-market-for-software-developers)