Manager, Governance, Risk & Compliance
CareersElite.com · New Year, MT · 2 wk ago
Sales$110k–$130k/yrFull-time
We are seeking an experienced Manager of Governance, Risk & Compliance (GRC) to lead and strengthen our compliance framework, risk management processes, and governance structures. You will serve as a trusted partner to internal teams across the organization, driving enterprise-wide compliance initiatives and ensuring MRI meets its regulatory obligations. In this role, you'll report directly to the SVP of Legal and Compliance and have a seat at the table on strategic decisions affecting the business.
About the role
This role offers meaningful impact: you'll shape the GRC program strategy, mentor a team of analysts and specialists, and help build the infrastructure that supports MRI's continued growth and success.
Responsibilities
- Own and evolve MRI's GRC framework, including policies, procedures, internal controls, and risk appetite documentation, ensuring alignment with business objectives and regulatory requirements
- Lead enterprise-wide risk assessments and work cross-functionally with Engineering, Product, IT, and business units to identify, evaluate, and mitigate operational, regulatory, cybersecurity, and strategic risks
- Monitor the evolving regulatory landscape—including data privacy laws (GDPR, CCPA, state privacy regulations), financial services requirements, and industry standards—and translate regulatory changes into actionable compliance strategies
- Drive SOC 2, ISO 27001, PCI-DSS and other compliance certifications, managing internal and external audit processes from planning through remediation
- Design and deliver compliance training programs to promote a culture of accountability and ethical conduct across the organization
- Develop and present executive-level risk and compliance dashboards, metrics, and reports to senior leadership, the board of directors, and key stakeholders
- Oversee third-party risk management program, including vendor security assessments, contract risk review, due diligence, and ongoing monitoring of critical suppliers
- Lead incident response and investigation efforts related to compliance breaches or policy violations
- Manage and mentor a team of GRC analysts and specialists
- Champion a compliance-forward culture by building relationships across the organization and making compliance accessible and practical for all teams
- Partner with Legal, Sales, InfoSec, and Customer Success to support customer security questionnaires, RFP responses, and due diligence requests
Requirements
- Bachelor's degree in information security, business, law, or a related field; advanced degree (MBA, or Master's in Cybersecurity/Risk Management) strongly preferred
- 8+ years of progressive experience in governance, risk, compliance, information security, or internal audit, with at least 4 years in a management or leadership capacity
- Deep expertise in regulatory frameworks and standards including NIST, SOC 2, ISO 27001, NIST CSF, PCI, SaaS or technology industry experience required
- Active professional certifications required: CISA, CRISC, CISSP, CIPP, CCEP, or equivalent; multiple certifications preferred
- Proven track record of building, scaling, and maturing GRC programs in fast-growth technology environments
- Executive presence with outstanding communication skills; ability to translate complex compliance requirements into business terms for technical and non-technical audiences
- Hands-on experience implementing and optimizing GRC platforms (e.g., Jira, BitSite, OneTrust, Archer, LogicGate, Vanta, or Drata)
- Experience managing customer-facing compliance activities, including security questionnaires, audits, and enterprise sales support
- Strong business acumen with the ability to balance risk mitigation with business enablement
Pay
$110k - $130k / year