GRC Manager
Valence has built the only first-to-market AI native coaching platform for enterprise, offering personalized, expert, and human-like guidance and support to any leader or employee. We’re partnering with the most innovative Fortune 500 companies across healthcare, financial services, manufacturing, and technology to redefine how AI transforms work.
About Valence
We're the only company pioneering leadership coaching for large enterprises in an AI-first way. Our mission is to transform how the world's biggest companies approach learning and development, helping teams work better together through AI-powered personalization that adapts to individual goals and organizational culture. We've been featured in Harvard Business Review, TIME, World Economic Forum, Financial Times, Forbes, and Inc. 5000. Our clients include Coca-Cola, Delta, Nestlé, General Mills, Schneider Electric, Deutsche Telekom, AstraZeneca, Prudential, CVS, and Bristol Myers Squibb.
Responsibilities
- Own the day-to-day operation of Valence's GRC program.
- Maintain and continuously improve our Information Security and Artificial Intelligence Management System for ISO 27001/42001.
- Coordinate SOC 2, ISO 27001, ISO 42001, and other certification efforts.
- Manage the security risk register and facilitate enterprise risk assessments.
- Coordinate internal and external audits.
- Manage security policies, standards, and control documentation.
- Track remediation activities and drive control improvements across teams.
- Support customer security questionnaires, RFPs, and due diligence activities.
- Partner with Engineering to ensure technical controls meet compliance requirements.
- Help develop security metrics and executive reporting.
- Coordinate annual control testing and evidence collection.
- Build scalable governance processes as the company grows.
Requirements
- Experience managing GRC or security compliance programs.
- A desire to automate GRC tasks, including with the use of AI.
- Strong understanding of security frameworks such as SOC 2, ISO 27001, NIST CSF, and ISO 42001.
- Experience with risk management methodologies and maintaining risk registers.
- Experience coordinating internal and external audits.
- Experience working cross-functionally with Engineering, IT, Legal, Privacy, and business stakeholders.
- Strong organizational and project management skills.
- Excellent written and verbal communication.
- Comfortable interpreting control requirements and translating them into practical implementation guidance.
- Familiarity with cloud security concepts and requirements (AWS/Azure preferred).
- Experience with GRC platforms such as Vanta, Drata, Secureframe, OneTrust, or Archer is a plus.
- Familiarity with privacy regulations and AI governance, including GDPR and the EU AI Act.
Benefits
- Competitive salary including base + bonuses.
- Comprehensive health coverage (medical, dental, vision) from day one.
- Generous PTO, company-wide R&R shutdowns, and paid parental leave.
- Retirement plan support for US and global employees.
- A WFH stipend, phone stipend, and support to work in a WeWork or other space as preferred.
- Meaningful equity ownership in a venture-backed company at a growth inflection point.
- Top-up grants as we scale and you deliver exceptional performance.
Pay
Competitive salary including base + bonuses.
Schedule
This is a full-time role. Candidates must be available during Eastern Time working hours and have valid travel documents without work authorization restrictions in the US.