Back to jobs
New

Manager of Governance, Risk and Compliance (GRC)

Austin, Texas | Remote

SpyCloud is on a mission to make the internet a safer place by disrupting the criminal underground. SpyCloud’s solutions thwart cyberattacks and protect more than 4 billion accounts worldwide. Cybersecurity is an exciting, evolving space, and being at the forefront of the fight to disrupt cybercrime makes SpyCloud a special place to work. If you’re driven to align your career with a fantastic mission, look no further!

SpyCloud is seeking a hands-on and operationally focused Manager of Governance, Risk and Compliance (GRC) to lead and mature critical compliance, governance, and risk management initiatives across the organization. This role will own day-to-day execution of SpyCloud’s compliance and security governance programs while helping scale operational processes that support the company’s security posture and customer trust objectives.

The ideal candidate brings strong experience operating security compliance programs within cloud-native and SaaS environments and has deep familiarity with frameworks such as SOC 2, ISO 27001, NIST, and CMMC 2.0. This individual will work cross-functionally with Privacy, Security Engineering, DevOps, Legal, Product Engineering, and business stakeholders to drive compliance readiness, risk mitigation, policy governance, third-party risk management, and audit coordination.

This role is highly collaborative and execution-oriented, requiring both strategic judgment and operational ownership. The Manager of GRC will also directly manage at least one team member while helping evolve SpyCloud’s overall security governance maturity.

 

What You'll Do:

  • Governance & Compliance Operations
    • Own and manage SpyCloud’s day-to-day GRC and compliance operations across multiple frameworks, including SOC 2, ISO 27001, NIST, and CMMC 2.0.
    • Lead internal and external audit coordination activities, evidence collection, remediation tracking, and control validation efforts.
    • Maintain and improve security policies, standards, procedures, and governance documentation.
    • Drive ongoing compliance readiness activities and operationalize scalable compliance processes across the business.
    • Partner closely with Legal, Security Engineering, DevOps, and Engineering teams to ensure alignment on security and regulatory requirements.
  • Risk Management
    • Conduct enterprise risk assessments and facilitate ongoing risk identification, tracking, remediation, and reporting processes.
    • Develop and maintain risk registers and support leadership reporting on security and compliance risks.
    • Lead third-party/vendor risk management activities, including security reviews and vendor assessments.
    • Support customer trust initiatives, including security questionnaires, compliance inquiries, and due diligence requests.
  • Cloud Security & Security Governance
    • Partner with DevOps and Security Engineering teams to strengthen cloud security governance across AWS and cloud-native environments.
    • Ensure security controls are aligned with compliance frameworks and operational best practices.
    • Support implementation and monitoring of governance controls related to cloud infrastructure, identity management, logging, vulnerability management, and secure development practices.
    • Contribute to ongoing security awareness and compliance education initiatives across the organization.
  • Leadership & Cross-Functional Collaboration
    • Manage and mentor direct report(s), supporting professional growth and operational excellence within the GRC function.
    • Collaborate with technical and non-technical stakeholders to drive accountability and operational maturity.
    • Help prioritize remediation efforts and compliance initiatives based on business risk and organizational goals.
    • Support the Senior Director of Governance, Risk and Information Security in scaling SpyCloud’s overall security governance program.

 

Requirements:

  • Experience
    • 6+ years of experience in Governance, Risk, and Compliance (GRC), Information Security, Security Compliance, or related fields.
    • Demonstrated hands-on experience managing operational compliance programs within SaaS, cloud, or cybersecurity environments.
    • Proven experience supporting and maintaining compliance frameworks such as:
      • SOC 2
      • ISO 27001
      • NIST
      • CMMC 2.0
    • Experience leading audits, managing evidence collection, and coordinating remediation activities.
    • Experience with third-party/vendor risk management and enterprise risk assessment processes.
    • Experience working cross-functionally with Legal, Engineering, DevOps, Security, and executive stakeholders.
  • Education
    • Bachelor’s degree in Cybersecurity, Information Security, Computer Science, Business, or related field, or equivalent practical experience.
  • Skills
    • Strong understanding of security governance, compliance operations, and risk management practices.
    • Familiarity with cloud security concepts and governance within AWS or similar cloud environments.
    • Strong organizational and project management skills with the ability to manage multiple priorities simultaneously.
    • Excellent written and verbal communication skills.
    • Ability to translate compliance requirements into practical operational processes.
    • Strong analytical, documentation, and problem-solving skills.

 

Nice to Have:

  • Prior people management or mentorship experience preferred.
  • Certifications
    • One or more of the following certifications strongly preferred:
      • CISSP
      • CISA
      • CRISC
      • CISM
    • ISO 27001 Lead Auditor or Lead Implementer
  • Experience within cybersecurity SaaS organizations.
  • Experience supporting customer-facing security and trust initiatives.
  • Familiarity with security tooling, cloud-native environments, and DevSecOps practices.
  • Experience with AI governance, security governance automation, or modern GRC tooling.
  • Experience working in fast-paced, high-growth technology environments.

SpyCloud is not sponsoring visas at this time.

For applicants residing in California, please click here to read SpyCloud's CCPA Notice.

For applicants residing in the UK, please click here to read SpyCloud's Employee Privacy Notice.

U.S.-Based Benefits + Perks (for Full Time Employees):

At SpyCloud, we are committed to working alongside individuals who are equally passionate about preventing cybercrime, regardless of their department or role. Guided by our core values in all business decisions, we prioritize unity in our mission and ensure all SpyCloud employees have the support and benefits they need to stay focused on our goals. In addition to our engaging workspace in South Austin, flexible and remote-friendly work options, and competitive salary package, we offer our employees a comprehensive benefits package that includes:

  • 401(k) with Employer Contribution
  • Health, Vision, and Dental Insurance
    • Health Savings Account (HSA) available with Employer Contribution
  • Employer Paid Life, Short-term, and Long-term Disability Insurance
  • Generous PTO Plan and 16 paid holidays per year

U.K.-Based Benefits + Perks (for Full Time Employees):

  • Retirement Savings Plan with Employer Contribution
  • Employer Provided Private Health Insurance and Healthcare Cashplan
  • Employer Paid Life Insurance and Income Replacement
  • Generous Holiday Plan and 14 paid holidays per year

About SpyCloud:

SpyCloud transforms recaptured darknet data to disrupt cybercrime. Its automated identity threat protection solutions leverage advanced analytics and AI to proactively prevent ransomware and account takeover, detect insider threats, safeguard employee and consumer identities, and accelerate cybercrime investigations. SpyCloud's data from breaches, malware-infected devices, and successful phishes also powers many popular dark web monitoring and identity theft protection offerings. Customers include seven of the Fortune 10, along with hundreds of global enterprises, mid-sized companies, and government agencies worldwide. Headquartered in Austin, TX, SpyCloud is home to more than 200 cybersecurity experts whose mission is to protect businesses and consumers from the stolen identity data criminals are using to target them now.

To learn more and see insights on your company’s exposed data, visit spycloud.com.

Our Mission:

Our mission is to make the internet a safer place by disrupting the criminal underground. Together with our customers and partners, we aim to end criminals’ ability to profit from stolen information.

Who We Are:

SpyCloud is a place for innovative, collaborative, and problem-solvers to thrive. Individually, we’re amazing, but together, we’re unstoppable. We celebrate diversity and various perspectives and aim to create an inclusive and supportive environment for all. We are proud to be an Equal Employment Opportunity and Affirmative Action employer of choice. All aspects of employment decisions will be based on merit, performance, and business needs. We do not discriminate on the basis of any status protected under federal, state, or local law. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or other applicable legally protected characteristics. Women, minorities, individuals with disabilities, and protected veterans are encouraged to apply. SpyCloud complies with applicable state and local laws governing nondiscrimination in employment. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training.

SpyCloud expressly prohibits any form of workplace harassment. Improper interference with the ability of SpyCloud's employees to perform their job duties may result in discipline up to and including discharge. SpyCloud shares the right to work and participates in the E-Verify program in all locations.

If you need assistance or accommodation due to a disability, you may contact us.

Our Culture:

Our culture is something really special. We’re all driven to disrupt the cybercriminal economy as we keep customer accounts safe from compromise. We support a truly worthy and serious mission, but we have fun doing it together. If you are driven, inventive, and collaborative, you’ll fit right in.

SpyCloud’s Recruitment Policy:

We will never ask an applicant for sensitive or personal financial information during the recruitment process. We advise all applicants seeking employment with SpyCloud to review available information on recruitment fraud. Anyone who suspects that they have been contacted by someone falsely representing SpyCloud should email careers@spycloud.com.

Compensation Transparency Policy: 

At SpyCloud, we believe in transparency and fairness in compensation. We strive to ensure that all employees are fairly compensated for their contributions, and we openly discuss our compensation philosophy and structure. We are committed to providing competitive salaries and benefits packages to attract and retain top talent, and we encourage open dialogue and feedback regarding compensation matters.

Learn more and apply: SpyCloud Careers

Create a Job Alert

Interested in building your career at SpyCloud? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Education

Select...
Select...
Select...
Select...
Select...

Select...
Select...
Select...
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in SpyCloud’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.