Manager, InfoSec Governance Risk and Compliance (GRC)

Remote Full-time
About the position At Ivalua we are a global community of exceptional professionals, who believe that digital transformation revolutionizes supply chain sustainability and resiliency to unlock the power of supplier collaboration. We achieve this through our leading cloud-based spend management platform that empowers hundreds of the world's most admired brands to effectively manage all categories of spend and all suppliers to increase profitability, improve ESG (environmental, social, and corporate governance) performance, lower risk, and improve productivity. Driven by our passions and fueled by our shared ambitions, we empower and challenge each other to create meaningful experiences for our colleagues, customers, partners, and communities. Our InfoSec team is dedicated to building, maintaining, and continuously improving Ivalua's Information Security program globally. We provide peace of mind and assurance of protection and safety to our customers. In this fast-growing environment, the GRC program is critical to ensuring compliance with industry standards and certifications, managing risks, and supporting business growth. Responsibilities • Lead and own the Governance, Risk, and Compliance (GRC) program globally, managing and developing a high-performing team. • Manage and drive compliance efforts and audits for certifications such as FedRAMP, IRAP, ISO 27001, HIPAA, SOC1/SOC2, PCI DSS, and others. • Serve as the subject matter expert (SME) on security frameworks and standards including NIST SP 800-53 Rev 5, NIST 800-171, ITAR, FedRAMP, PCI DSS, SOC2, etc., providing guidance to internal stakeholders. • Efficiently manage and respond to customer security audit and compliance requests in a timely manner. • Maintain continuous compliance and monitoring of security controls to ensure ongoing adherence to standards. • Collaborate closely with Sales, Marketing, and Customer Success teams to effectively communicate Ivalua's security posture to prospects and customers. • Review and negotiate information security exhibits and contractual terms in partnership with the legal team. • Lead the Security Awareness and Training program to promote a culture of security across the organization. • Track, manage, and drive remediation efforts for control deficiencies and gaps identified through internal and external audits. • Oversee the Third Party Risk and Vendor Security Assessment program to mitigate supply chain risks. • Develop, maintain, and enforce InfoSec policies, standards, and plans. Requirements • At least 7+ years of proven experience leading GRC programs and managing compliance certifications and audits (FedRAMP, ISO 27001, HIPAA, SOC1/SOC2, PCI DSS, IRAP, etc.). • Strong knowledge of security frameworks such as NIST SP 800-53, NIST 800-171, ITAR, PCI DSS, SOC2, and FedRAMP. • Demonstrated ability to manage and influence stakeholders across multiple departments and time zones. • Excellent project management, analytical, and problem-solving skills with keen attention to detail. • Strong interpersonal and communication skills, capable of building trust and managing conflicts effectively. • Self-motivated with a high degree of initiative and ability to work independently. • Ability to handle multiple competing priorities and deadlines efficiently. • Bachelor's degree in related field preferred or equivalent experience with proven skills. Nice-to-haves • Excellent interpersonal, communication, and organizational skills. • Team player with the ability to interface effectively with a broad range of individuals and roles, including IT and vendors. • High degree of initiative, dependable, and able to work well with limited supervision. Benefits • Medical, dental, vision and transportation benefits. • Hybrid working model (3 days in the office per week). • Snacks and weekly lunches in the office. • Exceptional training and career development program. • Regular social events, competitive outings, team running events, and musical activities. Apply tot his job
Apply Now →

Similar Jobs

Experienced Registered Behavior Technician for In-Home ABA Therapy - Atlanta, GA

Remote

Immediate Hiring: Experienced Registered Behavioral Technician (RBT) for Clinic-Based ABA Therapy Services

Remote

Experienced Registered Behavioral Technician (RBT) - ABA Therapy for Children with Autism Spectrum Disorder

Remote

Experienced Registered Nurse - Telehealth: Providing Remote Care Coordination and Patient Support

Remote

Experienced Substitute Teacher for Riverside County Schools - Join Scoot Education's Innovative Team

Remote

Experienced Substitute Teacher for San Bernardino County - Flexible Schedules & Competitive Pay

Remote

Experienced School Year Instructional Coach for High-Dosage Tutoring Programs in Edgewater Park, NJ

Remote

Experienced School Year Tutor for K-8 Students in Math and Literacy - Mickleton, NJ

Remote

Experienced Secondary Social Studies Teacher for Kansas - Flexible Hybrid Remote Arrangement

Remote

USPS Office Helper

Remote

Lead Supply Chain Management Consultant, Microsoft D365 FO

Remote

Nurse Consultant- California

Remote

Experienced Customer Service Representative - Flexible Part-Time Remote Opportunity with Teleperformance

Remote

Litigation Insurance Adjuster (Remote)

Remote

Experienced Clinical Customer Service Representative - Remote Opportunity with blithequark

Remote

**Experienced Part-Time Evening Data Entry Specialist – Remote Opportunity for Flexible Work-Life Balance**

Remote

Remote Customer Service Operations Manager – Front‑End Retail Experience, Team Leadership & Continuous Improvement

Remote

VA Exp. Remote IP PTF Medical Coders-FT & PT Positions Available

Remote

Behavioral Health Safety Officer

Remote

Experienced Virtual Assistant for Data Entry and Administrative Support – Remote Work Opportunity with arenaflex

Remote
← Back