Manager, Governance, Risk and Compliance

3 weeks ago


Vancouver, Canada HashiCorp Full time

**Manager, Governance, Risk & Compliance**:
**About the Role**:
We're looking for a GRC manager to lead, develop and mature the commercial compliance (SOC 2 Type 2, ISO 27001/17/18) and policy/controls programs at HashiCorp. This role will be heavily focused on scaling, automating, and managing compliance capabilities across HashiCorp. We're looking for a self-motivated individual who thrives in fast-paced environments, can seamlessly drive efforts with multiple stakeholders to accomplish bold things, has demonstrable experience in GRC and is comfortable working across the breadth and depth of a large, multi-cloud security compliance program.

Security at HashiCorp is a remote team. While prior experience working remotely isn't required, we are looking for team members who can perform well given a high level of independence and autonomy.

**In this role, your responsibilities will include**:

- Manage, mentor and scale an existing team of compliance analysts
- Lead the commercial compliance (SOC 2 Type 2, ISO 27001/17/18) and security policy/controls programs at HashiCorp
- Expand the compliance program to new frameworks and attestations (e.g., PCI)
- Drive the development and maturity of the HashiCorp Common Controls Framework
- Maintain and drive maturity and governance of the HashiCorp Security Policy
- Develop and report on metrics, KPIs and KRIs
- Partner with the Compliance Engineering team to automate manual tasks (e.g., access reviews), continuous monitoring of controls, and audit evidence collection
- Own, document and maintain the scope/boundaries of the compliance program
- Oversee the onboarding and internal readiness/gap assessments of new products being added to the attestation programs
- Create and improve internal self-serve compliance material, such as standardized requirements for new products/services mapped to compliance objectives
- Plan and conduct external gap assessments
- Work with teams to prepare them for external audits
- Own and oversee external attestation/certification audits
- Work with teams to create and track remediation plans for gaps/audit findings
- Assist with other GRC activities and functions as needed

**Must-Have Qualifications**:

- 2+ years of experience as a people manager
- 5+ years of experience working in relevant GRC roles
- Previous experience in a cloud environment, preferably AWS and/or Azure
- Considerable hands on experience with PCI compliance, preferably for a service provider and/or merchant
- Experience leading ISO 27001 compliance and external audits, preferably SOC 2 as well
- Comfortable working with both deeply technical and non-technical audiences
- Develop relationships in a highly cross functional environment and drive alignment across internal organizations
- Highly responsive and have a customer first mindset
- Flexibility in daily hours (i.e., willingness to work longer hours during end of quarter, peak periods and audits)
- Ability to prioritize and track multiple projects in parallel

**Desired Qualifications**:

- Experience working in a large, multi-cloud environment
- Previous experience as a Qualified Security Assessor (QSA) or Internal Security Assessor (ISA)
- Deep understanding of common security compliance frameworks, attestations and certifications
- Previous experience at a technology or SaaS company in similar role

**About the Application Process**:
Please note, as communication is a critical aspect of how we work, a cover letter is a great way to provide a sample of how you communicate. In your cover letter, describe why you're interested in working at HashiCorp, and what draws you to this role in particular.

LI-AZ1

LI-REMOTE

**Colorado, California, Washington and New York City Applicants**: To view base salary ranges for this role in your location and to learn more about which roles are eligible for bonus pay or commissions, please visit our Pay Transparency Calculator below. Individual pay within the range will be determined based on job related-factors such as skills, experience, and education or training. Information on our benefits can be found via the link below. Intern ranges can be found below.



  • Vancouver, Canada Lululemon Full time

    Who We Are lululemon is an innovative performance apparel company for yoga, running, training, and other athletic pursuits. Setting the bar in technical fabrics and functional design, we create transformational products and experiences that support people in moving, growing, connecting, and being well. We owe our success to our innovative product, emphasis...


  • Vancouver, Canada YWCA Metro Vancouver Full time

    Job DescriptionThe Director of Risk, Compliance and IT provides leadership for the IT and Health and Safety teams; is responsible for ensuring that the YWCA’s private, confidential and sensitive information is secure and for integrating data and information systems across the growing number of YWCA sites. This position reviews significant leases and other...

  • Risk Control Engineer

    4 weeks ago


    Vancouver, Canada BFL CANADA Risk and Insurance Full time

    We offer more than a job, we offer a career! We support our employees to shape their career by encouraging continuing education and investing in training and development. We put our employees at the center of what we do to allow them to grow personally and professionally, with projects and challenges that are motivating and rewarding. We inspire people to...

  • Business Analyst

    4 weeks ago


    Vancouver, Canada Ignite Technical Resources. Full time

    Business Analyst - Governance and Compliance BHJOB13022_12497 Business Analyst - Governance and Compliance - Contract position in Vancouver (Hybrid): On behalf of our client in **Vancouver,** **Ignite Technical Resources** is looking for a **Business Analyst - Governance and Compliance **with our client ** **for a **contract opportunity**. **Role...


  • Vancouver, British Columbia, Canada BFL CANADA Risk and Insurance Full time

    We offer more than a job, we offer a careerWe support our employees to shape their career by encouraging continuing education and investing in training and development.We put our employees at the centre of what we do to allow them to grow personally and professionally, with projects and challenges that are motivating and rewarding.We inspire people to do...


  • Vancouver, Canada Raymond James Financial, Inc. Full time

    **Manager, Risk Management** - 2401253 - At Raymond James, _**_we _**_develop, _**_we _**_collaborate, _**_we _**_decide, _**_we _**_deliver, and _**_we _**_improve together_. Raymond James Ltd. is Canada’s leading independent investment dealers offering high quality investment products and services to Canadians seeking customized solutions to their...


  • Vancouver, Canada Cyberium Group Full time

    Senior Consultant or Manager, Risk and Compliance ServicesWe are looking for a Senior Consultant or Manager, Risk and Compliance Services to work as an integral part of our service delivery team serving enterprises in financial services, public sector, high technology sector, and other industry sectors. You will be helping our clients to solve complex...


  • Vancouver, Canada Cyberium Group Full time

    Senior Consultant or Manager, Risk and Compliance ServicesWe are looking for a Senior Consultant or Manager, Risk and Compliance Services to work as an integral part of our service delivery team serving enterprises in financial services, public sector, high technology sector, and other industry sectors. You will be helping our clients to solve complex...


  • Vancouver, Canada Cyberium Group Full time

    Senior Consultant or Manager, Risk and Compliance ServicesWe are looking for a Senior Consultant or Manager, Risk and Compliance Services to work as an integral part of our service delivery team serving enterprises in financial services, public sector, high technology sector, and other industry sectors. You will be helping our clients to solve complex...


  • Vancouver, Canada Cyberium Group Full time

    We are looking for an IT Risk Senior Consultant or Manager to work as an integral part of our management and service delivery team serving enterprises in financial services, public sector, high technology sector, and other industry sectors. You will be helping our clients to solve complex business, risk and IT challenges.You will be an integral part of our...


  • Vancouver, Canada Cyberium Group Full time

    We are looking for an IT Risk Senior Consultant or Manager to work as an integral part of our management and service delivery team serving enterprises in financial services, public sector, high technology sector, and other industry sectors. You will be helping our clients to solve complex business, risk and IT challenges.You will be an integral part of our...


  • Vancouver, Canada Cyberium Group Full time

    We are looking for an IT Risk Senior Consultant or Manager to work as an integral part of our management and service delivery team serving enterprises in financial services, public sector, high technology sector, and other industry sectors. You will be helping our clients to solve complex business, risk and IT challenges.You will be an integral part of our...


  • Vancouver, Canada Cyberium Group Full time

    We are looking for an IT Risk Senior Consultant or Manager to work as an integral part of our management and service delivery team serving enterprises in financial services, public sector, high technology sector, and other industry sectors. You will be helping our clients to solve complex business, risk and IT challenges.You will be an integral part of our...

  • Compliance Manager

    4 weeks ago


    Vancouver, Canada DNBC Financial Group Full time

    Responsible for the design, implementation, and maintenance of the compliance program of the group. - Prepare and respond to regulatory enquiries and manage examinations - Research and report on regulatory developments and make suggestions with respect to related compliance policy and procedure enhancements. - Compliance Management Program: develop and...


  • Metro Vancouver Regional District, Canada TransLink Full time

    **Marketing Statement**: A career at TransLink and our family of companies means working with people with a wide range of skills and perspectives, all teaming up towards a common goal: preserving and enhancing the region's world-envied quality of life. Together, we connect the region and enhance its livability by providing a sustainable transit and...


  • Vancouver, Canada John Wood Group Full time

    Wood, a global leader in engineering and project management, is seeking a talented Governance & Assurance Manager to join our Power Solutions, Process & Chemicals Projects Business Group. Salary range - $165,000 - $200,000 Wood offers a competitive Total Rewards Package, which includes a comprehensive Health & Wellness Plan, Health Care Spending Account,...


  • Greater Vancouver, Canada Cyberium Group Full time

    We are a Cybersecurity Risk Consulting services organization experiencing rapid growth. We offer a unique environment that promotes collaboration and continuous learning, and values work-life balance and fun We bring creative consulting and technology solutions to help solve our clients' complex problems We provide services, using an agile approach, to...


  • Greater Vancouver, Canada Cyberium Group Full time

    We are a Cybersecurity Risk Consulting services organization experiencing rapid growth.We offer a unique environment that promotes collaboration and continuous learning, and values work-life balance and funWe bring creative consulting and technology solutions to help solve our clients' complex problemsWe provide services, using an agile approach, to...


  • Greater Vancouver, Canada Cyberium Group Full time

    We are a Cybersecurity Risk Consulting services organization experiencing rapid growth.We offer a unique environment that promotes collaboration and continuous learning, and values work-life balance and funWe bring creative consulting and technology solutions to help solve our clients' complex problemsWe provide services, using an agile approach, to...


  • North Vancouver, Canada Accord Financial Corporation Full time

    **Summary**:The Compliance Specialist is accountable for reviewing documentation for new and pre -existing accounts to ensure that they are compliant with the procedural requirements. This includes evaluating low, medium and high-risk accounts. **Essential Duties and Responsibilities**: - Strongly adhere to existing procedures and controls in place and...