Sr Project Manager, GRC (Governance Risk and Compliance)

Coterie
$115,000 - $140,000Remote

About The Position

Coterie's GRC team is hiring a Senior Project Manager to own remediation projects tied to SOC 2, ITGC, and regulatory compliance requirements, including emerging regulations in privacy, AI governance, and security. The role also supports recurring compliance programs, such as the annual risk assessment cycle, from a scheduling and tracking standpoint, maintaining visibility into risk treatment plan status. While the role reports through GRC, projects may span security, legal, compliance, finance, and other functions depending on business need. The ideal candidate combines strong project management discipline with enough technical fluency to work credibly with engineers and security practitioners including translating security and compliance requirements into work technical teams can execute, along with the ability to build the reporting and dashboards leadership needs to track progress.

Requirements

  • 6+ years of project management experience, including leading complex, cross-functional projects; 2+ years running remediation projects tied to security, compliance, or regulatory findings strongly preferred.
  • Experience translating Compliance & Security requirements into technical work and managing requirements traceability through delivery.
  • Demonstrated experience building leadership-facing reporting and dashboards to track project, remediation, or risk status.
  • Familiarity with frameworks such as SOC 2, ITGC, or similar regulatory and compliance standards, and how audit findings and risk treatment plans translate into scoped remediation work.
  • Working technical fluency: comfortable discussing cloud infrastructure, APIs, the software development lifecycle, and core security concepts with engineering and security stakeholders.
  • Proven experience managing multiple concurrent projects with competing deadlines and stakeholders.
  • Strong command of project management methodologies (Agile, waterfall, or hybrid) and tools (Jira, MS Project, or similar).
  • Excellent verbal communication skills, including experience presenting to executive audiences.
  • Applicants must have authorization to work in the United States without the need for sponsorship now or in the future.

Nice To Haves

  • Experience with written executive communication, such as executive summaries or briefing memos.
  • Experience with GRC/IRM platforms (e.g.Optro).
  • PMP, CAPM, or equivalent project management certification.
  • Security certifications (Security+, CISA, CISSP).
  • Experience in insurance, fintech, or another regulated industry.

Responsibilities

  • Own end-to-end delivery of remediation projects tied to SOC 2, ITGC, and regulatory compliance requirements, translating audit findings, control gaps, and new regulatory obligations (privacy, AI governance, security) into scoped plans, milestones, and assigned owners, and driving them to closure.
  • Manage 2 to 4 concurrent projects across security, legal, compliance, finance, or other functions, maintaining a project plan with tracked risks, issues, and dependencies, and escalating blockers before they affect timelines.
  • Translate security and compliance requirements into clear, actionable work for engineering and technical teams.
  • Apply Agile, waterfall, or hybrid methodologies as fits the regulatory deadline driving the work.
  • Support the annual risk assessment cycle and similar recurring compliance programs by maintaining schedules, coordinating stakeholder input and deadlines, and keeping deliverables on time.
  • Track and report the status of risk treatment plans across owners and due dates, flagging at-risk items.
  • Maintain project and risk-tracking data in the team's project management or GRC/IRM platform (e.g., Jira, Optro) as the accurate source of truth.
  • Coordinate with external auditors as needed to confirm remediation deliverables meet audit requirements.
  • Serve as the primary point of contact for remediation and project status across Security, Legal, Compliance, Finance, and other business stakeholders.
  • Build and maintain leadership-facing reporting and dashboards showing remediation progress and risk treatment plan status.
  • Deliver clear, concise status updates and risk escalations to executive leadership and governance forums.
  • Facilitate project meetings and working sessions, documenting decisions and action items and tracking them to closure.
  • Improve project management and tracking processes, templates, and tooling to increase consistency and efficiency across GRC's remediation project portfolio.
  • Help mature GRC's approach to intake, prioritization, and resourcing of new remediation and compliance tracking work.

Benefits

  • 100% remote
  • Health insurance through Aetna (we pay 100% of premiums)
  • Dental and vision insurance through Guardian (we pay 100% of premiums)
  • Basic life insurance (we pay 100% of premiums)
  • Access to flexible spending account (FSA) or health savings account (HSA) (for those using HSA eligible plans)
  • 401K plan (up 4% match with immediate vest). Must be 21 years of age or older to participate
  • Flexible PTO policy offering employees up to 4 weeks of PTO in their first 12 months. Thereafter, PTO usage aligns with company standards and typically does not exceed 5 weeks per calendar year.
  • 12 company-paid holidays each year
  • Continuing education annual stipend
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service