All jobs

Security GRC Manager

100% Remote Full-time Open now

Job Description:

  • Own and mature Hex’s security and privacy compliance program across SOC 2, ISO 27001, ISO 27701, HIPAA, GDPR, CCPA, PCI DSS, and other frameworks relevant to our business
  • Ensure continuous audit readiness: maintain controls, gather evidence, manage auditors, and implement improvements.
  • Track regulatory and industry changes, advising Hex leadership on impact and recommended responses.
  • Maintain and develop core security policies, standards, and procedures, tailoring them to Hex’s real operating environment.
  • Own Hex’s risk management lifecycle: identify, assess, track, and drive mitigation of security, privacy, operational, and regulatory risks.
  • Build lightweight but effective governance processes, ensuring clear ownership, documentation, and accountability.
  • Serve as the primary owner of customer and prospect security questionnaires, risk assessments, and contractual security provisions.
  • Manage and improve Hex’s Trust Center / trust portal, ensuring accurate and compelling communication of Hex’s security posture.
  • Lead internal and external audits from planning through remediation.
  • Own Hex’s third-party risk management program, including vendor assessments, reviews, and ongoing monitoring.
  • Define and run security awareness training tailored to Hex’s environment.

Requirements:

  • 5–8+ years in GRC, compliance, security engineering, privacy, audit, or a related field
  • Deep familiarity with frameworks such as SOC 2, ISO 27001, ISO 27701, PCI DSS, HIPAA, GDPR, and associated security controls
  • Experience running or contributing significantly to audit cycles and certification processes
  • Technical literacy in cloud-native environments (AWS preferred), SaaS architectures, and modern security tooling
  • Ability to understand and explain product architecture, data flows, and control implementations to auditors and customers

Benefits:

  • Competitive total rewards package
  • Comprehensive health benefits
  • Flexible paid time off

Apply tot his job Apply To this Job

You might also like

Compliance Consultant – GRC Practice

100% Remote Full-time

Senior Governance, Risk, and Compliance Engineer

100% Remote Full-time

REMOTE - Information Security GRC Analyst III - R12694

100% Remote Full-time

IT GRC Advisor (100% Remote)

100% Remote Full-time

Governance, Risk & Compliance (GRC) Analyst

100% Remote Full-time

Senior QA Auditor - GCP Audits

100% Remote Full-time

Senior Risk Advisory GRC Consultant – Full Time- Remote in the USA

100% Remote Full-time

Risk Advisory GRC Consultant - Remote (USA)

100% Remote Full-time

Lead Quality Systems Auditor

100% Remote Full-time

SOC/SOX IT Audit Program Ops Manager

100% Remote Full-time

Junior Account Executive | SDR-to-AE Opportunity at Urrly

100% Remote Full-time

Experienced Junior Tech Support Specialist – Mobile and Online Banking Solutions

100% Remote Full-time

Freelance Filmmaker

100% Remote Full-time

Record Retrieval Call Support

100% Remote Full-time

Remote Data Entry Specialist – Work From Home Position | arenaflex Flexible Data Management Opportunities

100% Remote Full-time

Consultant for juvenile justice quality control and monitoring (open for National consultants only), remote, 29 months

100% Remote Full-time

Director Product, Delivery & Consulting (m/w/d) Digital-Health

100% Remote Full-time

Entertainment Partnerships Manager (Studio Pods) - FANDANGO

100% Remote Full-time

Entry-Level Medicare Insurance Agent – Training Provided | Remote & Flexible Schedule (Great First Job Opportunity) | Neighbor's Reliance | Handshake

100% Remote Full-time

Part-Time Remote Data Entry Associate – Home‑Based Data Management & Accuracy Specialist at arenaflex

100% Remote Full-time