SIGN IN
Cybersecurity Manager - GRC jobs in United States
info-icon
This job has closed.
company-logo

Playlist · 1 month ago

Cybersecurity Manager - GRC

Playlist is a company focused on connecting people with inspiring experiences in fitness and wellness. They are seeking a Cybersecurity Manager - GRC to lead a team responsible for governance, risk, and compliance across a multi-brand environment, ensuring effective risk management and compliance with various frameworks.
AppsArtificial Intelligence (AI)WellnessSaaSFitness
check
H1B Sponsor Likelynote

Responsibilities

Manage and develop a team of 3–5 GRC team members, set quarterly OKRs, run 1:1s, hire to fill gaps, and coach on technical depth, stakeholder management, and audit discipline
Own the third-party risk management workflow end-to-end across Playlist’s multi-brand vendor footprint, vendor intake, risk tiering, due diligence, contract risk review, and ongoing monitoring and continuously tune the program as vendor volume scales with acquisitions
Lead Playlist’s compliance program portfolio across SOC 1 Type II, ISO 27001, HITRUST, NIST CSF/800-53, and IT SOX scope, control design, evidence collection, and external audit coordination across the brand footprint
Serve as primary point of contact for external auditors and assessors, manage audit timelines and finding remediation, and challenge scope and interpretation when it matters
Own the GRC team’s operating cadence, planning rhythms, staff meetings, intake queues, and how the team interfaces with Security Engineering, Legal, Privacy, and Procurement
Drive Playlist’s compliance automation platform forward, design how controls and evidence flow through the tool, automate high-volume evidence collection, and evolve the tooling strategy as the program scales
Partner with Legal, Security Engineering, Product, and Finance to surface compliance and third-party risk early in product and infrastructure decisions, with clear accept, mitigate, reject recommendations for partner teams

Qualification

Information Security GRCCompliance Program ManagementAudit ManagementSOC 1 Type IIISO 27001HITRUSTNIST CSFNIST 800-53IT SOXThird-Party Risk ManagementCompliance Automation PlatformsVendor Risk AssessmentStakeholder ManagementCoachingProject Management

Required

7+ years of progressive Information Security GRC, Compliance, or Audit experience, including at least 2 years of direct people management
Hands-on program ownership across multiple compliance frameworks: SOC 1 Type II is required, plus working depth in at least two of ISO 27001, HITRUST, NIST CSF/800-53, or IT SOX, with the ability to map and rationalize controls across frameworks
Demonstrated ownership of a third-party risk management workflow at scale, vendor intake, risk tiering, diligence, and ongoing monitoring including the operating standards and SLAs that hold the program together
Hands-on experience with a compliance automation platform (Drata, Vanta, Hyperproof, Secureframe, Optro or similar) and a clear point of view on how tooling should scale with program growth
Strong project management skills, can run multiple audits and integration workstreams in parallel without dropping deadlines
Direct experience managing external auditors and assessors, including comfort challenging scope and interpretation
Excellent written and verbal communication, with the ability to translate compliance and risk findings into clear executive and partner-team updates

Preferred

Experience integrating acquired companies into an existing compliance program, including control harmonization and audit scope decisions
Background working in a multi-brand or SaaS / consumer-marketplace environment
CISA, CIPP/US or CIPP/E, ISO 27001 Lead Implementer / Lead Auditor, or PCI ISA certification
Detection or security engineering literacy strong enough to partner technically with Security Engineering on control design

Benefits

The total compensation package for this position may also include a performance bonus, benefits, and/or other applicable incentive compensation plan.

Company

Playlist

twitterlinkedincrunchbase
company-logo
Playlist is the parent company that operates various physical and mental fitness tech companies.

H1B Sponsorship

Playlist has a track record of offering H1B sponsorships. Please note that this does not guarantee sponsorship for this specific role. Below presents additional info for your reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Marketing
Trends of Total Sponsorships
*2025 (1)

Funding

Current Stage
Late Stage
Total Funding
$785M
Key Investors
Affinity Partners
2026-01-15Private Equity· $785M
Company data provided by crunchbase