freehire launches on Product Hunt on 26 August.

Follow →

Sr Project Manager, GRC (Governance Risk and Compliance)

Summary

Lead end-to-end GRC remediation projects (SOC 2, ITGC, privacy, AI governance) across cross-functional teams, maintaining project plans in Jira and delivering executive-level dashboards and reporting.

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Sr Project Manager, GRC (Governance Risk and Compliance) based in United States.

This is a high-impact opportunity for an experienced project manager to lead security, compliance, and regulatory remediation initiatives across a growing organization. You will own complex projects from audit findings and control gaps through planning, execution, and final remediation. Working closely with Security, Legal, Compliance, Finance, Engineering, and other teams, you will translate regulatory requirements into practical, actionable work. You will also support recurring risk and compliance programs while maintaining clear visibility into treatment plans and deadlines. A key part of the role is creating executive-level reporting and dashboards that turn complex project and risk data into clear insights. The ideal candidate will bring strong project discipline, technical fluency, and the confidence to operate across both technical teams and executive stakeholders.

Accountabilities

  • Own end-to-end remediation projects related to SOC 2, ITGC, privacy, AI governance, security, and other regulatory requirements, translating findings and obligations into clear plans, milestones, owners, and deliverables.
  • Manage 2–4 concurrent cross-functional projects, maintaining project plans, tracking risks, issues, dependencies, and deadlines while proactively escalating blockers.
  • Translate security and compliance requirements into actionable technical work that engineering and security teams can execute, maintaining requirements traceability throughout delivery.
  • Apply Agile, waterfall, or hybrid project management methodologies based on project scope, regulatory requirements, and deadlines.
  • Support annual risk assessments and recurring compliance programs by coordinating schedules, stakeholder inputs, deliverables, and deadlines.
  • Track risk treatment plans, ownership, and remediation status, identifying at-risk activities and maintaining accurate project and GRC/IRM data in platforms such as Jira or Optro.
  • Coordinate with external auditors when needed to ensure remediation deliverables meet audit and compliance expectations.
  • Serve as the central point of contact for project and remediation status across Security, Legal, Compliance, Finance, Engineering, and other stakeholders.
  • Build leadership-facing dashboards and reporting that clearly communicate remediation progress, risk treatment status, milestones, and emerging issues.
  • Deliver concise executive updates and risk escalations, facilitate project meetings and working sessions, and ensure decisions and action items are documented and followed through to completion.
  • Improve GRC project management processes, templates, tooling, intake, prioritization, and resource planning to increase consistency and efficiency across the remediation portfolio.
  • Requirements

    • 6+ years of project management experience leading complex, cross-functional initiatives, with 2+ years of experience managing security, compliance, or regulatory remediation projects strongly preferred.
    • Demonstrated ability to translate security and compliance requirements into technical work and manage requirements through delivery.
    • Experience developing executive-level reports, dashboards, summaries, or other visibility tools for project, remediation, or risk management.
    • Familiarity with SOC 2, ITGC, or comparable regulatory and compliance frameworks, including how audit findings and risk treatment plans translate into remediation initiatives.
    • Working technical fluency across cloud infrastructure, APIs, software development lifecycles, and core cybersecurity concepts, with the ability to communicate credibly with engineers and security practitioners.
    • Proven ability to manage multiple concurrent projects with competing priorities, deadlines, and stakeholder expectations.
    • Strong command of Agile, waterfall, or hybrid project management methodologies and tools such as Jira, MS Project, or similar platforms.
    • Excellent verbal and written communication skills, including confidence presenting project status, risks, and recommendations to executive audiences.
    • Strong organizational skills, attention to detail, ownership, problem-solving ability, and the judgment to identify and escalate risks before they impact delivery.
    • Experience writing executive summaries, briefing documents, or other leadership communications is a plus.
    • Familiarity with GRC/IRM platforms such as Optro is advantageous.
    • PMP, CAPM, or equivalent project management certification is a plus.
    • Security certifications such as Security+, CISA, or CISSP are beneficial.
    • Experience in insurance, fintech, or another regulated industry is preferred.
    • Candidates must be authorized to work in the United States without current or future visa sponsorship.
    • Benefits

      • Fully remote work environment.
      • Annual salary estimated at $115,000–$140,000, with compensation determined by experience, skills, certifications, internal equity, and market data.
      • Health insurance with 100% of premiums covered.
      • Dental and vision insurance with 100% of premiums covered.
      • Basic life insurance with 100% of premiums covered.
      • Flexible Spending Account (FSA) or Health Savings Account (HSA) options, depending on plan eligibility.
      • 401(k) plan with up to a 4% company match and immediate vesting.
      • Flexible PTO, with up to 4 weeks available during the first 12 months and typically up to 5 weeks per calendar year thereafter.
      • 12 company-paid holidays annually.
      • Annual continuing education stipend.
      • Opportunity to work on high-impact GRC, security, compliance, and regulatory initiatives across a collaborative, cross-functional environment.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available