Accela
Accela

Manager, Governance, Risk & Compliance

legalfull-timeRemote Based - US
SALARY
Not listed
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
general
Apply for this position
✦ AutoApply Let us apply to roles like this on your behalf.
Learn more

About the role

About the Role

The Manager, Governance, Risk, and Compliance leads Accela security governance, risk, compliance, audit, and customer trust programs. This role owns security policies, standards, risk management processes, control evidence, audit readiness, and third-party risk management.

The Manager, GRC partners with Security, Legal, IT, Engineering, Product, Finance, People, and customer-facing teams to ensure Accela meets regulatory, contractual, audit, and customer trust obligations.

This role is the primary owner for compliance programs and audit readiness across SOC 2, ISO 27001, GovRAMP, PCI DSS, HIPAA, NIST CSF, NIST 800-53, CCPA/GDPR, and other customer or regulatory requirements.

Specific Responsibilities

  • Lead the governance, risk, and compliance function across security policies, standards, risk management, audits, third-party risk, and control operations.
  • Develop, maintain, and operationalize global security policies, standards, procedures, control documentation, and exception processes.
  • Own audit readiness and ongoing compliance programs across frameworks such as SOC 2, ISO 27001, GovRAMP, PCI DSS, HIPAA, NIST CSF, NIST 800-53, CCPA/GDPR, and other customer or regulatory requirements.
  • Lead GovRAMP and PCI DSS readiness, including control mapping, evidence collection, remediation tracking, stakeholder coordination, audit preparation, and audit support.
  • Coordinate audit evidence collection, control testing, remediation tracking, auditor communication, and management responses.
  • Maintain the security risk register, including identification, assessment, ownership, remediation, acceptance, exception tracking, and executive reporting of security risks.
  • Partner with control owners across Security, IT, Engineering, Legal, HR, Finance, Product, and Operations to ensure control effectiveness and accountability.
  • Manage third-party and supply chain risk management, including vendor security reviews, due diligence, risk assessments, contract security input, and remediation tracking.
  • Support customer security reviews, questionnaires, trust center content, security documentation, and customer-facing compliance responses.
  • Develop metrics and dashboards for audit status, control health, risk posture, vendor risk, policy exceptions, compliance readiness, and remediation progress.
  • Support incident response and privacy incident processes by ensuring regulatory, contractual, audit, and customer notification obligations are understood and tracked.
  • Partner with the CISO to communicate security posture, compliance progress, key risks, control gaps, and trade-offs to executives, customers, auditors, and regulators.
  • Drive continuous improvement of the GRC operating model, including automation, evidence reuse, control rationalization, risk prioritization, and policy lifecycle management.

Required Qualifications

  • 6+ years of experience in security governance, risk management, compliance, audit, third-party risk, or related cybersecurity roles.
  • Experience managing or supporting audits and compliance programs for SOC 2, ISO 27001, GovRAMP, PCI DSS, HIPAA, NIST 800-53, or similar frameworks.
  • Strong understanding of security controls, policy management, risk assessment, control testing, evidence collection, and audit readiness practices.
  • Experience working with auditors, customers, internal stakeholders, and executive leadership.
  • Experience managing third-party risk or vendor security review programs.
  • Ability to translate complex compliance obligations into practical business and technical requirements.
  • Strong project management skills with the ability to manage multiple audits, risks, remediation efforts, and stakeholder workstreams simultaneously.
✦ Let us apply for you
We find roles like this and apply on your behalf. Cover letter written for each one. Plans from $15/mo. Cancel anytime.
Get AutoApply
Apply now
Manager, Governance, Risk & Compliance at Accela — Remote