Manager, Governance, Risk and Compliance
1 week ago
**Manager, Governance, Risk & Compliance**:
**About the Role**:
We're looking for a GRC manager to lead, develop and mature the commercial compliance (SOC 2 Type 2, ISO 27001/17/18) and policy/controls programs at HashiCorp. This role will be heavily focused on scaling, automating, and managing compliance capabilities across HashiCorp. We're looking for a self-motivated individual who thrives in fast-paced environments, can seamlessly drive efforts with multiple stakeholders to accomplish bold things, has demonstrable experience in GRC and is comfortable working across the breadth and depth of a large, multi-cloud security compliance program.
Security at HashiCorp is a remote team. While prior experience working remotely isn't required, we are looking for team members who can perform well given a high level of independence and autonomy.
**In this role, your responsibilities will include**:
- Develop an org-wide risk management program
- Conduct annual and ad hoc risk assessments
- Perform vendor security assessments
- Work with risk owners to make risk treatment decisions and create remediation plans
- Track risks and remediation plans to keep them on track and within defined timelines
- Manage the security risk acceptance process
- Communicate security risk, assessment results, and remediation plans across HashiCorp
- Maintain HashiCorp's security risk register
- Execute on security risk activities required for our compliance portfolio
- Collect and use internal and external security risk data to improve the risk scoring model and help inform security risk decision making
- Assist with audit readiness preparation and external audits
- Define, collect, and report on metrics for the security risk management program
- Continually improve the security risk management program, policies, and processes
- Help with common GRC activities as needed
**Must-Have Qualifications**:
- 2+ years of experience as a people manager
- 5+ years of experience working in relevant GRC roles
- Previous experience in a cloud environment, preferably AWS and/or Azure
- Considerable hands on experience with PCI compliance, preferably for a service provider and/or merchant
- Experience leading ISO 27001 compliance and external audits, preferably SOC 2 as well
- Comfortable working with both deeply technical and non-technical audiences
- Develop relationships in a highly cross functional environment and drive alignment across internal organizations
- Highly responsive and have a customer first mindset
- Flexibility in daily hours (i.e., willingness to work longer hours during end of quarter, peak periods and audits)
- Ability to prioritize and track multiple projects in parallel
**Desired Qualifications**:
- Experience working in a large, multi-cloud environment
- Previous experience as a Qualified Security Assessor (QSA) or Internal Security Assessor (ISA)
- Deep understanding of common security compliance frameworks, attestations and certifications
- Previous experience at a technology or SaaS company in similar role
**About the Application Process**:
Please note, as communication is a critical aspect of how we work, a cover letter is a great way to provide a sample of how you communicate. In your cover letter, describe why you're interested in working at HashiCorp, and what draws you to this role in particular.
LI-AZ1
LI-REMOTE
**Colorado, California, Washington and New York City Applicants**: To view base salary ranges for this role in your location and to learn more about which roles are eligible for bonus pay or commissions, please visit our Pay Transparency Calculator below. Individual pay within the range will be determined based on job related-factors such as skills, experience, and education or training. Information on our benefits can be found via the link below. Intern ranges can be found below.
-
Governance Risk
1 week ago
Toronto, Canada Interac Full timeGovernance Risk and Compliance, Lead The Governance Risk and Compliance, Lead is a key resource to ensuring Interac Corp. “Security First” principles are embedded in all environments. The successful candidate will have knowledge of principles in security policies and standards and modern practices and a good understanding of security aspects of the...
-
Governance Risk
4 days ago
Toronto, Canada Interac Full timeGovernance Risk and Compliance, Lead The Governance Risk and Compliance, Lead is a key resource to ensuring Interac Corp. “Security First” principles are embedded in all environments. The successful candidate will have knowledge of principles in security policies and standards and modern practices and a good understanding of security aspects of the...
-
IT Governance, Risk
4 weeks ago
Toronto, Canada Enbridge Full timeIT Governance, Risk & Compliance Specialist Join Enbridge’s team as an IT Governance, Risk & Compliance Specialist, dedicated to safeguarding data, ensuring regulatory compliance, and fostering a secure environment for innovation. Posting Details Posting End Date: December 21, 2025 Employee Type: Regular - Full time Union/Non‑union: This is a non‑union...
-
Toronto, Canada KPMG Full timeOverview: At KPMG, you’ll join a team of diverse and dedicated problem solvers, connected by a common cause: turning insight into opportunity for clients and communities around the world. Our **Governance, Risk and Compliance Services (GRCS)** professionals under **Advisory Risk Services** provide a range of assurance and advisory services to enhance the...
-
IT Governance, Risk
4 weeks ago
Toronto, Canada Enbridge Full timePosting End Date: December 21, 2025 Employee Type: Regular-Full time Union/Non: This is a non-union position In today’s digital landscape, security is the cornerstone of trust and resilience in the IT space. Cybersecurity, risk management, and compliance are not just technical requirements—they are essential safeguards that protect sensitive data, ensure...
-
IT Governance, Risk
4 weeks ago
Toronto, Canada Enbridge Full timePosting End Date: December 21, 2025 Employee Type: Regular-Full time Union/Non: This is a non-union position In today’s digital landscape, security is the cornerstone of trust and resilience in the IT space. Cybersecurity, risk management, and compliance are not just technical requirements—they are essential safeguards that protect sensitive data, ensure...
-
Governance Risk
6 days ago
Toronto, Canada Interac Corp. Full timeWho We Are:Every transaction matters. Every Canadian matters. At Interac, we protect both — driving trust, security, and inclusion, so our digital economy thrives. Founded in 1984, Interac connects Canadians through secure digital payments, advanced identity verification and industry-leading fraud protection. Connecting banks, businesses, and...
-
Director, Governance, Risk
3 weeks ago
Toronto, Canada Numeris Full timeOverviewNumeris is Canada’s most trusted and authoritative source for broadcast measurement and consumer behaviour data. As well, the industry leading intelligence provider to broadcasters, advertisers, and agencies. We have been recognized for over 75 years as providing the gold standard in audience intelligence.We have great people who do exceptional...
-
Director, Governance, Risk
2 weeks ago
Toronto, Canada Numeris Full timeDirector, Governance, Risk & Compliance (GRC) Numeris, Canada’s leading audience intelligence provider, is seeking a Director to lead the Governance, Risk & Compliance (GRC) department. The Director will ensure adherence to regulatory standards and internal policies across Numeris and its subsidiaries, driving ethical and lawful operations. Numeris is a...
-
Director, Governance, Risk
3 weeks ago
Toronto, Canada Numeris Full timeDirector, Governance, Risk & Compliance (GRC) Numeris, Canada’s leading audience intelligence provider, is seeking a Director to lead the Governance, Risk & Compliance (GRC) department. The Director will ensure adherence to regulatory standards and internal policies across Numeris and its subsidiaries, driving ethical and lawful operations. Numeris is a...