Sr. Manager of Compliance and Risk Management

Parallels Inc• Remote, US,
•$170,000 - $190,000•Remote

About The Position

Parallels is seeking a Senior Manager of Compliance and Risk Management to support the ongoing maturity of our Governance, Risk, and Compliance program. This role is primarily focused on third-party risk management, responding to customer RFPs and security/vendor questionnaires, ensuring organization-wide compliance to common security, privacy, and AI frameworks, and leading, creating and managing the risk register, and policy development. In addition, this position will lead all infrastructure and product security or privacy incidents ensuring full compliance with required regulations. This is a blended role: you’ll own audit readiness and control testing for our certifications while also driving enterprise and third-party risk management and compliance. You’ll work directly with external auditors and assessors, and partner closely with Security, Legal, IT, HR, and Engineering to keep the program audit-ready year-round.

Requirements

  • Bachelor's degree in Information Security, Computer Science, Business, or related field (or equivalent experience)
  • 8+ years of experience in GRC, information security compliance, IT audit, or enterprise/vendor risk management
  • Hands-on experience leading or supporting audits against major frameworks (e.g., ISO 27001, NIST and SOC 2)
  • Demonstrated experience managing external audits end-to-end, including auditor relationships and finding remediation
  • Solid understanding of risk assessment methodologies and control frameworks (e.g., COBIT)
  • Experience with risk register tools, GRC platforms and ticketing systems

Nice To Haves

  • Familiarity with compliance frameworks such as SOC 2, ISO 27001, and DORA.
  • Comfortable working cross-functionally with IT, Legal, and business stakeholders.

Responsibilities

  • Monitor organizational compliance with internal policies and external regulations. Track control performance, identify gaps, and prepare regular compliance status reports for leadership.
  • Monitor regulatory and framework changes (e.g., EU Data Act) and assess their impact on the compliance program.
  • Respond to customer RFPs and security/vendor questionnaires, coordinating with subject matter experts to ensure accurate and timely responses. Maintain a library of standard responses and supporting evidence.
  • Work directly with sales to attend customer calls for large enterprise customers.
  • Maintain the organization’s Trust Center to enable customers and partners to quickly find compliance, security, and privacy information, with the goal of automating responses for repeat questions.
  • Define and manage the third-party risk management program, including vendor security assessments, due diligence reviews, and ongoing monitoring of vendor risk. Track vendor remediation items and maintain vendor risk documentation.
  • Ensure ongoing reviews for existing third parties, including changing usage related to AI and privacy where applicable.
  • Maintain and update the organization’s risk register, ensuring all identified risks are documented, assessed, and monitored. Track risk treatment plans and follow up with risk owners on remediation status.
  • Contribute to executive and board-level reporting on risk and compliance posture, including recurring management business reviews.
  • Oversee the development, review, and implementation of GRC policies and procedures. Define processes and implement automation to ensure that policies stay current with regulatory changes and organizational needs.
  • Lead employee awareness and training of policy requirements.
  • Prepare and maintain audit-readiness materials, control narratives, policies, and standard operating procedures for both internal and external stakeholders.
  • Lead and coordinate audits and assessments across the compliance portfolio (e.g., ISO 27001/42001, SOC 2, NIST, FedRAMP, GovRAMP, CMMC, PCI DSS), owning evidence collection, auditor interviews, and finding remediation end-to-end.
  • Manage external audits end-to-end, including auditor and assessor relationships.
  • Design, test, and monitor internal controls; identify gaps and drive remediation with control owners across the business.
  • Lead all infrastructure and product security or privacy incidents, ensuring full compliance with required regulations and reporting obligations.
  • Define and own the company-wide incident process, ensuring readiness and compliance with required regulatory frameworks.
  • Implement systems to ensure efficient and compliance incident handling.
  • Manage, hire and train GRC analysts, ensuring that they maintain the skills needed to manage the complexity of Parallels environment.

Benefits

  • Fully remote workspace
  • Flexible hours
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service