Risk & Controls Manager

FloQast•New York City, NY
•Hybrid

About The Position

FloQast is seeking a Risk & Controls Manager to join its InfoSec & Compliance department. This role will act as a risk and controls advisor, ensuring compliance with key frameworks and evaluating business initiatives from a risk and controls perspective. The goal is to ensure FloQast's operations, products, and services align with regulatory, contractual, and internal requirements. The position will manage core risk domains such as privacy, third-party risk management, and policy management, and will contribute to broader risk program initiatives like issue management and process automation. The ideal candidate is a GRC professional capable of working across multiple risk and compliance areas, with the role expected to adapt to departmental growth. The InfoSec & Compliance department, reporting to the General Counsel, oversees security, privacy, AI, and financial reporting compliance. The team consists of in-house subject matter experts who advise, direct, train, and monitor the organization, interacting daily with various departments on diverse business initiatives. This role requires working in the office three days per week, with potential for adjustments based on team and business needs as determined by the department leader. Visa sponsorship is not available.

Requirements

  • Bachelor's degree
  • 6+ years of experience in compliance, risk management, information security, privacy, or a related field, with SaaS industry experience preferred.
  • Strong general compliance expertise, including areas such as privacy, security, and IT general controls.
  • Experience applying and maintaining compliance with frameworks such as SOC and ISO standards.
  • Foundational knowledge of privacy regulations and frameworks such as GDPR, CCPA, and related international privacy laws.
  • Strong communication and interpersonal skills, with the ability to collaborate effectively across teams and functions.
  • Highly organized, detail-oriented, and proactive in identifying and addressing compliance risks.
  • Ability to operate autonomously and drive risk and compliance initiatives with limited oversight.
  • Flexible and adaptable in a high-growth, fast-paced environment.

Nice To Haves

  • Certifications such as CIA, CISA, CISSP, CISM, CIPP/E, CIPM, or similar.
  • Experience with cloud hosting environments such as AWS, Azure, or GCP.
  • Experience with emerging technologies, including AI-driven features and associated risk considerations.
  • Prior experience supporting international compliance initiatives or privacy regulatory readiness across multiple jurisdictions.

Responsibilities

  • Collaborate and drive cross-functional alignment with internal stakeholders to review, maintain, and align documentation, policies, and procedures with audit and regulatory expectations.
  • Conduct and document compliance impact assessments covering risk, privacy, and AI considerations to support organizational decision-making.
  • Provide strategic, risk-informed guidance in response to compliance-related inquiries from internal teams.
  • Support FloQast's security and compliance programs by ensuring adherence to applicable SOC and ISO standards.
  • Own execution of FloQast's established privacy program, including maintaining privacy documentation, supporting data subject requests, and ensuring ongoing compliance with applicable privacy laws.
  • Manage FloQast's sub-processor program, including maintaining notification workflows, coordinating updates to the sub-processor list, and responding to client inquiries related to sub-processor changes.
  • Support privacy-related product and vendor reviews, escalating regulatory considerations as needed.
  • Own third-party risk management processes and associated due diligence activities, including coordinating vendor reviews and supporting procurement needs.
  • Own policy management processes across the organization, including facilitating annual reviews, coordinating updates with policy owners, maintaining version history, and routing finalized policies for approval.
  • Support the identification, tracking, and remediation of compliance and policy-related issues, partnering with relevant stakeholders to drive resolution.
  • Identify opportunities for process improvement, including automation and AI, within the risk management and compliance function, and actively develop and implement AI-driven workflows to enhance program efficiency and scalability.
  • Perform any other tasks that may be assigned to help the company meet its goals.

Benefits

  • Medical
  • Dental
  • Vision
  • Family Forming benefits
  • Life & Disability Insurance
  • Unlimited Vacation
  • Employee Stock Program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service