GRC Manager
Uplight
Posted
Mar 26, 2026
Location
Remote (US)
Type
Full-time
Compensation
$160000 - $180000
Mission
What you will drive
- Leadership: Leads the GRC program and a team of security professionals.
- Governance: Develop, document, and implement internal policies and procedures to ensure compliance with industry standards and legal requirements. Map requirements to controls and manage the company’s execution of the controls.
- Risk Management: Conduct regular enterprise-wide risk assessments, maintain a risk register, and develop mitigation strategies for identified threats. Co-lead Risk Management committees.
- Compliance: Lead audits and manage compliance efforts for frameworks such as SOC 2, ISO 27001, PCI-DSS, NERC-CIP, and privacy principles. Manage CAPAs for non-compliance.
- Third-Party Risk: Manage vendor risk management processes, including vendor assessments and contract reviews.
- Sales-cycle Support: Manage security and privacy responses to client questions and questionnaires, including RFPs, RFIs, annual risk reviews, and ad-hoc communication requests.
- Business Continuity: Manage and update business continuity and disaster recovery documentation, including BIAs, plan revisions, team rosters, and dependencies. Plan, coordinate, and document annual exercises, such as tests, tabletops, and other exercises.
- Awareness & Training: Oversee rollout of cybersecurity and privacy awareness campaigns and required annual training and policy attestations. Monitor participation, ensure compliance, and support content preparation aligned with company and regulatory requirements.
- Metrics: Build and manage security and privacy metrics program
- Technology & Reporting: Select and manage GRC software tools to automate processes, monitor controls, and provide reports to executives.
- Collaboration: Collaborate with IT, Security, Legal, and People teams to drive risk-informed decision-making and build a culture of compliance.
- Experience: Previous experience in GRC, risk management, or internal audit, often with a mid-level leadership background.
- Framework Knowledge: Proficiency in frameworks like SOC2, NIST CSF, ISO 27001, and NERC-CIP.
- Analytical Skills: Strong ability to analyze risk data and translate complex regulations into actionable controls.
- Communication: Excellent communication skills to interact with stakeholders and lead team efforts.
- Experience with 3rd party/vendor risk management processes
- Experience in working with sales teams to complete Requests for Proposals and security questionnaires
- Understanding of GRC processes such as policy management, risk assessment, and IT audits
- Exposure to public cloud and cloud security concepts in environments like AWS, Azure or GCP
- Exceptional verbal and written communication skills
- GRC or Privacy certifications (e.g. CISA, CIPP, etc)
- Make a Meaningful Impact: Your work directly impacts our mission of decarbonization and building a more sustainable future.
- Grow Your Career: We offer ample advancement opportunities, robust learning and development programs, and a supportive team environment that fosters collaboration and innovation.
- Thrive: We offer comprehensive benefits, including flexible time off, generous parental leave, a wellness stipend, and work flexibility to help you thrive both personally and professionally.
- Belong to an Inclusive Community: We celebrate diversity and foster an inclusive workplace where everyone feels respected, empowered, and heard. Our Employee Resource Groups offer opportunities to connect with colleagues who share your interests and backgrounds.
- Be Part of a Growing Movement: Join a team of dedicated individuals who are passionate about creating a more sustainable future. We offer a collaborative environment where your ideas are valued and your contributions recognized. Together, we can build a brighter tomorrow.
Profile
What makes you a great fit
- Leadership: Leads the GRC program and a team of security professionals.
- Governance: Develop, document, and implement internal policies and procedures to ensure compliance with industry standards and legal requirements. Map requirements to controls and manage the company’s execution of the controls.
- Risk Management: Conduct regular enterprise-wide risk assessments, maintain a risk register, and develop mitigation strategies for identified threats. Co-lead Risk Management committees.
- Compliance: Lead audits and manage compliance efforts for frameworks such as SOC 2, ISO 27001, PCI-DSS, NERC-CIP, and privacy principles. Manage CAPAs for non-compliance.
- Third-Party Risk: Manage vendor risk management processes, including vendor assessments and contract reviews.
- Sales-cycle Support: Manage security and privacy responses to client questions and questionnaires, including RFPs, RFIs, annual risk reviews, and ad-hoc communication requests.
- Business Continuity: Manage and update business continuity and disaster recovery documentation, including BIAs, plan revisions, team rosters, and dependencies. Plan, coordinate, and document annual exercises, such as tests, tabletops, and other exercises.
- Awareness & Training: Oversee rollout of cybersecurity and privacy awareness campaigns and required annual training and policy attestations. Monitor participation, ensure compliance, and support content preparation aligned with company and regulatory requirements.
- Metrics: Build and manage security and privacy metrics program
- Technology & Reporting: Select and manage GRC software tools to automate processes, monitor controls, and provide reports to executives.
- Collaboration: Collaborate with IT, Security, Legal, and People teams to drive risk-informed decision-making and build a culture of compliance.
- Experience: Previous experience in GRC, risk management, or internal audit, often with a mid-level leadership background.
- Framework Knowledge: Proficiency in frameworks like SOC2, NIST CSF, ISO 27001, and NERC-CIP.
- Analytical Skills: Strong ability to analyze risk data and translate complex regulations into actionable controls.
- Communication: Excellent communication skills to interact with stakeholders and lead team efforts.
- Experience with 3rd party/vendor risk management processes
- Experience in working with sales teams to complete Requests for Proposals and security questionnaires
- Understanding of GRC processes such as policy management, risk assessment, and IT audits
- Exposure to public cloud and cloud security concepts in environments like AWS, Azure or GCP
- Exceptional verbal and written communication skills
- GRC or Privacy certifications (e.g. CISA, CIPP, etc)
- Make a Meaningful Impact: Your work directly impacts our mission of decarbonization and building a more sustainable future.
- Grow Your Career: We offer ample advancement opportunities, robust learning and development programs, and a supportive team environment that fosters collaboration and innovation.
- Thrive: We offer comprehensive benefits, including flexible time off, generous parental leave, a wellness stipend, and work flexibility to help you thrive both personally and professionally.
- Belong to an Inclusive Community: We celebrate diversity and foster an inclusive workplace where everyone feels respected, empowered, and heard. Our Employee Resource Groups offer opportunities to connect with colleagues who share your interests and backgrounds.
- Be Part of a Growing Movement: Join a team of dedicated individuals who are passionate about creating a more sustainable future. We offer a collaborative environment where your ideas are valued and your contributions recognized. Together, we can build a brighter tomorrow.
About
Inside Uplight
Accelerating clean energy through personalized experiences and carbon reduction with leading utilities worldwide.