GRC Program Manager, Assurance Engineering & Control Systems
Own audit programs and build reusable, technically grounded control and evidence systems. The role partners across security, engineering, infrastructure, product, privacy, legal, and audit teams to automate assurance work and reduce recurring operational burden.
About the job
Responsibilities
- Lead external, internal, customer, and certification audit work from scoping through evidence review, fieldwork, remediation, and closeout.
- Build a common control framework linking risk, control intent, implementation, owner, system, environment, evidence, and applicable frameworks.
- Validate actual scope and ownership rather than assuming prior controls, product boundaries, or evidence remain accurate.
- Use Codex to build and test evidence checks, control mappings, request triage, owner workflows, monitoring, and remediation reporting.
- Partner with engineers on cloud architecture, identity, logging, data flows, software changes, vulnerabilities, and control effectiveness.
- Design maintainable, permission-aware tools that preserve source provenance, human review, and evidence integrity.
- Reduce repeated requests and operational burden for control owners through measurable workflow improvements.
- Define roadmaps, decision rights, milestones, success metrics, and cross-functional escalations.
Requirements
- Direct ownership of meaningful audit, security, customer-assurance, or regulatory outcomes.
- Practical knowledge of control design, evidence, testing, operating effectiveness, and remediation.
- Technical fluency across cloud systems, identity, logging, APIs, data flows, and system boundaries.
- Ability to use Codex or comparable AI-assisted development tools to build, run, inspect, and test a working solution.
- Experience using code, SQL, APIs, structured data, automation, or data workflows to solve operational problems.
- Ability to design reusable cross-framework controls without removing framework-specific testing and evidence requirements.
- First-principles curiosity, creative problem solving, intellectual humility, and adaptability when facts change.
- Product and program judgment, including defining users, scope, milestones, ownership, adoption, and measurable outcomes.
- Clear, constructive partnership with Security, Engineering, Infrastructure, Product, Privacy, Legal, and audit teams.
Nice-to-haves
- Familiarity with SOC 2, ISO 27001/27017, PCI DSS, NIST, or FedRAMP.
- A specific degree or certification is not required.
Compensation
- Annual salary: $216,000–$252,000.
Skills
GRC, Audit Management, Common Control Frameworks, SOC 2, ISO 27001, Pci Dss, Nist, FedRAMP, Cloud Systems, Identity And Access Management, SQL, APIs, Codex, Automation, Data Workflows
Similar jobs
Technical Program Management jobsLeads an end-to-end product lifecycle assurance program, embedding security, privacy, and compliance controls into product development, launch, and monitoring. The role requires strong technical judgment, cross-functional influence, and experience with CI/CD, Kubernetes architectures, and scalable assurance tooling.
Own cross-functional hardware NPI programs from kickoff through rate production, coordinating engineering, manufacturing, quality, and supply chain. The role requires 5–10 years of technical program management experience, an engineering degree, and strong judgment across schedule, risk, and design-change decisions.
Leads complex search research and engineering programs across retrieval, indexing, model training, and infrastructure. The role requires substantial technical experience, strong program execution, product judgment, and the ability to align cross-functional teams.
Technical Program Manager supporting research IP partnerships by coordinating internal and external teams, enabling frontier AI model deployment, and building scalable processes and tools. The role requires strategic partnerships experience, strong cross-functional communication, and technical fluency with AI or no-code platforms.
Leads cross-functional development and integration of robotic sensor systems from requirements through manufacturing and release. The role requires experience with complex electromechanical hardware programs, sensor technologies, validation, production readiness, and engineering change processes.