Manager, InfoSec Governance Risk and Compliance (GRC) jobs in United States
cer-icon
Apply on Employer Site
company-logo

Ivalua · 1 day ago

Manager, InfoSec Governance Risk and Compliance (GRC)

Ivalua is a leading global provider of cloud-based procurement solutions. They are seeking an experienced InfoSec Governance Risk and Compliance (GRC) Manager to lead a global team, manage compliance efforts, and serve as a subject matter expert on security frameworks and standards.

ProcurementSaaSSoftware
check
H1B Sponsor Likelynote

Responsibilities

Lead and own the Governance, Risk, and Compliance (GRC) program globally, managing and developing a high-performing team
Manage and drive compliance efforts and audits for certifications such as FedRAMP, IRAP, ISO 27001, HIPAA, SOC1/SOC2, PCI DSS, and others
Serve as the subject matter expert (SME) on security frameworks and standards including NIST SP 800-53 Rev 5, NIST 800-171, ITAR, FedRAMP, PCI DSS, SOC2, etc., providing guidance to internal stakeholders
Efficiently manage and respond to customer security audit and compliance requests in a timely manner
Maintain continuous compliance and monitoring of security controls to ensure ongoing adherence to standards
Collaborate closely with Sales, Marketing, and Customer Success teams to effectively communicate Ivalua’s security posture to prospects and customers
Review and negotiate information security exhibits and contractual terms in partnership with the legal team
Lead the Security Awareness and Training program to promote a culture of security across the organization
Track, manage, and drive remediation efforts for control deficiencies and gaps identified through internal and external audits
Oversee the Third Party Risk and Vendor Security Assessment program to mitigate supply chain risks
Develop, maintain, and enforce InfoSec policies, standards, and plans

Qualification

GRC program managementCompliance certifications managementSecurity frameworks expertiseStakeholder managementProject managementAnalytical skillsInterpersonal skillsCommunication skillsProblem-solving skillsTeam player

Required

At least 7+ years of proven experience leading GRC programs and managing compliance certifications and audits (FedRAMP, ISO 27001, HIPAA, SOC1/SOC2, PCI DSS, IRAP, etc.)
At least 3+ years experience as a direct leader, managing a team
Strong knowledge of security frameworks such as NIST SP 800-53, NIST 800-171, ITAR, PCI DSS, SOC2, and FedRAMP
Demonstrated ability to manage and influence stakeholders across multiple departments and time zones
Excellent project management, analytical, and problem-solving skills with keen attention to detail
Strong interpersonal and communication skills, capable of building trust and managing conflicts effectively
Self-motivated with a high degree of initiative and ability to work independently
Ability to handle multiple competing priorities and deadlines efficiently
Bachelor's degree in related field preferred or equivalent experience with proven skills

Benefits

Medical
Dental
Vision
Transportation

Company

Ivalua is a leading provider of cloud-based, AI-powered Spend Management software spanning the complete Source-to-Pay process

H1B Sponsorship

Ivalua has a track record of offering H1B sponsorships. Please note that this does not guarantee sponsorship for this specific role. Below presents additional info for your reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Trends of Total Sponsorships
2025 (12)
2024 (13)
2023 (8)
2022 (34)
2021 (19)
2020 (13)

Funding

Current Stage
Late Stage
Total Funding
$134.38M
Key Investors
Kohlberg Kravis RobertsArdian
2019-05-21Private Equity· $60M
2017-04-26Private Equity· $70M
2011-05-05Series Unknown· $4.38M

Leadership Team

leader-logo
David Khuat-Duy
Founder, Corporate CEO
linkedin
leader-logo
Arnaud Khuat-Duy
CTO
linkedin
Company data provided by crunchbase