GRC Manager

G2Chicago, IL
$120,000 - $131,000

About The Position

The Governance, Risk, and Compliance (GRC) Manager owns G2's day-to-day security compliance and risk program. This role is responsible for keeping customer trust commitments, audit obligations, and risk posture on track. The position involves managing a high-volume operation including customer security questionnaires, vendor risk reviews, policy governance, DSAR processing, audit management, and risk register maintenance. The manager is expected to prioritize competing demands, scale a growing workload through process discipline, and represent G2 to customers, auditors, and executive stakeholders. This is a senior individual-contributor role that requires partnering across Legal, Security Engineering, IT, Sales, and executive leadership. The ideal candidate has prior experience running a GRC program at this scale, is comfortable with modern compliance tooling (e.g., Vanta), fluent in SOC 2 Type II and ISO 27001, and experienced in translating technical risk into business language.

Requirements

  • 7–10 years of progressive experience in IT Governance, Risk, and Compliance or information security, including direct ownership of a compliance program.
  • Deep working knowledge of SOC 2 Type II, ISO 27001, NIST CSF, and common SaaS/cloud security and privacy frameworks (e.g., PCI DSS, GDPR, CCPA).
  • Hands-on experience with a modern GRC/compliance automation platform (e.g., Vanta, Drata, OneTrust, or similar) used to manage controls, evidence, and risk at scale.
  • Proven experience managing high-volume customer security questionnaires and knowledge-library programs, including large enterprise reviews.
  • Experience running a third-party/vendor risk management program, including risk scoring and remediation tracking.
  • Experience managing DSAR or other privacy request workflows in line with regulatory timelines.
  • Track record serving as primary point of contact for external auditors through full audit cycles, with strong control-testing and remediation experience.
  • Excellent written and verbal communication skills, including experience presenting risk and compliance status to executive stakeholders and customers.
  • Strong prioritization and program-management skills, with the ability to manage a high-volume, multi-workstream caseload independently as a senior individual contributor.
  • Demonstrated ability to influence and align cross-functional partners (Legal, Engineering, IT, Sales) without formal authority over their teams.

Nice To Haves

  • CISSP, CRISC, CISM, or CISA certification.
  • Experience leading an organization through initial ISO 27001 certification or a comparable new-framework rollout.
  • Familiarity with procurement-to-GRC integrations and automating vendor intake into a risk workflow.
  • Working knowledge of global privacy regulations (GDPR, CCPA, LGPD) and experience partnering with Legal on data protection matters.
  • Experience managing a GRC program budget and vendor/contract relationships (audit firms, tooling, advisory partners).
  • Track record operating as a senior individual contributor who drives outcomes through influence and cross-functional partnership rather than direct authority.

Responsibilities

  • Own and administer G2's security policy library (35+ documents), leading the annual review cycle, managing approvals, and ensuring no policy lapses past its renewal date.
  • Lead response to customer and prospect security questionnaires — from short-form intake to 100+ question enterprise reviews — and maintain the security knowledge library that powers fast, accurate answers at scale.
  • Own G2's public Trust Center and serve as the company's front-line representative to customers and partners on security and compliance matters.
  • Run the third-party/vendor risk management program, reviewing AI-assisted vendor risk assessments, making final risk-level determinations, and driving remediation of high-risk findings.
  • Manage data subject access request (DSAR) intake and fulfillment, ensuring requests are documented and resolved within regulatory timelines.
  • Support security addendum and contract redlines, partnering with Legal and counterparties through multiple negotiation rounds to close terms.
  • Maintain and mature enterprise risk registers across business functions, driving treatment plans, control linkage, and quarterly reassessment to closure.
  • Lead SOC 2 Type II and ISO 27001 audit cycles end-to-end — evidence collection, control testing, and serving as primary point of contact for auditors.
  • Manage the GRC tooling and vendor ecosystem (compliance platforms, audit firms, privacy tooling), including contract renewals and budget oversight.
  • Build and deliver executive-level dashboards and reporting on program health, audit status, and risk posture to leadership.
  • Advise internal teams on the effectiveness of corrective action plans following audit findings, control gaps, or compliance incidents.
  • Partner cross-functionally with Legal, Security Engineering, IT, Sales, and other business functions as the connective tissue between their goals and G2's compliance and risk requirements.
  • Identify where process or automation would relieve bottlenecks, and build the business case for that investment.

Benefits

  • Performance
  • Entrepreneurship
  • Authenticity
  • Kindness
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service