The Manager, Security Governance & Risk leads Emburse's security governance, risk, and compliance function, with primary focus on enterprise security risk management, security metrics and reporting ...
The Manager, Security Governance & Risk leads Emburse's security governance, risk, and compliance function, with primary focus on enterprise security risk management, security metrics and reporting ...
Security Risk & Engineering - Tech and Cyber Risk & Compliance - Senior Manager
Boston, MA · On-site
$124K - $280K/yr
... governance objectives - Promoting a culture of compliance and ethical behavior through training and development initiatives What You Must Have - At least a Bachelor's degree - At least 7 years of ...
Security Risk & Engineering - Tech and Cyber Risk & Compliance - Senior Manager
Boston, MA · On-site
$124K - $280K/yr
... governance objectives - Promoting a culture of compliance and ethical behavior through training and development initiatives What You Must Have - At least a Bachelor's degree - At least 7 years of ...
The Risk and Compliance Project Manager will manage projects related to compliance and ... governance, steering, and change control processes • Produce regular project reports and ...
The Risk and Compliance Project Manager will manage projects related to compliance and ... governance, steering, and change control processes • Produce regular project reports and ...
The Risk and Compliance Project Manager will be responsible for managing projects in Risk and ... Adhere to agreed project governance, steering, and change control processes * Produce regular ...
The Risk and Compliance Project Manager will be responsible for managing projects in Risk and ... Adhere to agreed project governance, steering, and change control processes * Produce regular ...
Director, Security Governance
Charlestown, MA · On-site
$176K - $205K/yr
The Director of Security Governance, Risk & Compliance, leads and manages the Governance Risk and Compliance (GRC) function and is responsible for partnering with the It Security Leader in managing ...
Director, Security Governance
Charlestown, MA · On-site
$176K - $205K/yr
The Director of Security Governance, Risk & Compliance, leads and manages the Governance Risk and Compliance (GRC) function and is responsible for partnering with the It Security Leader in managing ...
Lead Security Governance & Risk Engineer
Boston, MA · On-site
$140 - $210/hr
You will work alongside the Trust and Compliance team who are the custodians of our security ... Lead AI risk governance and ISO 42001 readiness. Maintain the AI risk assessment methodology and ...
Lead Security Governance & Risk Engineer
Boston, MA · On-site
$140 - $210/hr
You will work alongside the Trust and Compliance team who are the custodians of our security ... Lead AI risk governance and ISO 42001 readiness. Maintain the AI risk assessment methodology and ...
You will work alongside the Trust and Compliance team who are the custodians of our security ... Lead AI risk governance and ISO 42001 readiness. Maintain the AI risk assessment methodology and ...
You will work alongside the Trust and Compliance team who are the custodians of our security ... Lead AI risk governance and ISO 42001 readiness. Maintain the AI risk assessment methodology and ...
You will work alongside the Trust and Compliance team who are the custodians of our security ... Lead AI risk governance and ISO 42001 readiness. Maintain the AI risk assessment methodology and ...
You will work alongside the Trust and Compliance team who are the custodians of our security ... Lead AI risk governance and ISO 42001 readiness. Maintain the AI risk assessment methodology and ...
Role overview The information security risk and compliance analyst supports the organization's governance, risk, and compliance program by managing security risk, ensuring regulatory compliance and ...
Role overview The information security risk and compliance analyst supports the organization's governance, risk, and compliance program by managing security risk, ensuring regulatory compliance and ...
Developing AI-enabled capabilities that accelerate governance, risk, and compliance and cyber operations, including evidence summarization, control testing assist, policy question-and-answer ...
Developing AI-enabled capabilities that accelerate governance, risk, and compliance and cyber operations, including evidence summarization, control testing assist, policy question-and-answer ...
Risk & Compliance Project Manager
Boston, MA · On-site
$99K - $125K/yr
The Risk and Compliance Project Manager will be responsible for managing projects in Risk and ... Adhere to agreed project governance, steering, and change control processes * Produce regular ...
Risk & Compliance Project Manager
Boston, MA · On-site
$99K - $125K/yr
The Risk and Compliance Project Manager will be responsible for managing projects in Risk and ... Adhere to agreed project governance, steering, and change control processes * Produce regular ...
Clinical Compliance Director
Boston, MA · On-site
$180 - $240/hr
Provide strategic leadership for compliance governance, risk management, and regulatory oversight across all service lines. * Serve as the organization's primary compliance authority and advisor to ...
Clinical Compliance Director
Boston, MA · On-site
$180 - $240/hr
Provide strategic leadership for compliance governance, risk management, and regulatory oversight across all service lines. * Serve as the organization's primary compliance authority and advisor to ...
Clinical Compliance Director
Boston, MA · On-site
$145K - $165K/yr
Provide strategic leadership for compliance governance, risk management, and regulatory oversight across all service lines. * Serve as the organization's primary compliance authority and advisor to ...
Clinical Compliance Director
Boston, MA · On-site
$145K - $165K/yr
Provide strategic leadership for compliance governance, risk management, and regulatory oversight across all service lines. * Serve as the organization's primary compliance authority and advisor to ...
Clinical Compliance Director
Boston, MA · On-site
$145K - $165K/yr
Provide strategic leadership for compliance governance, risk management, and regulatory oversight across all service lines. * Serve as the organization's primary compliance authority and advisor to ...
Clinical Compliance Director
Boston, MA · On-site
$145K - $165K/yr
Provide strategic leadership for compliance governance, risk management, and regulatory oversight across all service lines. * Serve as the organization's primary compliance authority and advisor to ...
The role requires extensive experience in governance, risk and compliance, with the ability to navigate complex regulatory landscapes and lead multidisciplinary teams in a hybrid work environment. #J ...
The role requires extensive experience in governance, risk and compliance, with the ability to navigate complex regulatory landscapes and lead multidisciplinary teams in a hybrid work environment. #J ...
The role demands hands-on execution, deep expertise across governance, risk, compliance, and secure-by-design principles, and the ability to scale #J-18808-Ljbffr
The role demands hands-on execution, deep expertise across governance, risk, compliance, and secure-by-design principles, and the ability to scale #J-18808-Ljbffr
Cyber Policy Enforcement Lead, VP
$116K - $157K/yr
Prepare and present compliance, enforcement, and risk insights to senior leadership, risk committees, and governance forums. * Monitor compliance performance and risk trends, identify systemic issues ...
Cyber Policy Enforcement Lead, VP
$116K - $157K/yr
Prepare and present compliance, enforcement, and risk insights to senior leadership, risk committees, and governance forums. * Monitor compliance performance and risk trends, identify systemic issues ...
Cyber Policy Enforcement Lead, VP
Quincy, MA · On-site
$116K - $157K/yr
Prepare and present compliance, enforcement, and risk insights to senior leadership, risk committees, and governance forums. * Monitor compliance performance and risk trends, identify systemic issues ...
Cyber Policy Enforcement Lead, VP
Quincy, MA · On-site
$116K - $157K/yr
Prepare and present compliance, enforcement, and risk insights to senior leadership, risk committees, and governance forums. * Monitor compliance performance and risk trends, identify systemic issues ...
Information Technology Risk & Compliance Manager
Boston, MA · On-site
$140 - $160/hr
Lead the IT Compliance Program activities that will include risk assessments, IT governance, internal/external audit coordination, management reporting, and other compliance-related monitoring*
New
Information Technology Risk & Compliance Manager
Boston, MA · On-site
$140 - $160/hr
Lead the IT Compliance Program activities that will include risk assessments, IT governance, internal/external audit coordination, management reporting, and other compliance-related monitoring*
New
Director, Technology Risk
Boston, MA · On-site
Evolve Geode's use of Governance, Risk, & Compliance ('GRC') tool, including adoption of IT risk management, business continuity & disaster recovery modules. * Help establish and maintain a risk ...
Director, Technology Risk
Boston, MA · On-site
Evolve Geode's use of Governance, Risk, & Compliance ('GRC') tool, including adoption of IT risk management, business continuity & disaster recovery modules. * Help establish and maintain a risk ...
Governance Risk Compliance information
See Boston, MA salary details
$34.2K - $42.2K
12% of jobs
$42.2K - $50.1K
7% of jobs
$52.9K is the 25th percentile. Wages below this are outliers.
$50.1K - $58.1K
17% of jobs
$58.1K - $66K
10% of jobs
The median wage is $68.1K / yr.
$66K - $74K
16% of jobs
$74K - $81.9K
9% of jobs
$87K is the 75th percentile. Wages above this are outliers.
$81.9K - $89.9K
7% of jobs
$89.9K - $97.8K
5% of jobs
$97.8K - $105.8K
7% of jobs
$105.8K - $113.7K
5% of jobs
$113.7K - $121.7K
4% of jobs
$34.2K
$74.7K
$121.7K
How much do governance risk compliance jobs pay per year?
What is governance risk compliance?
What are jobs in governance risk compliance?
Governance risk compliance (GRC) is a method for managing and strategizing an organization's regulations regarding governance, financial or physical risk, and regulatory compliance. It aligns the IT aspects with business objectives and works to improve the efficiency of a company. There are GRC consultants and GRC analysts who provide an assessment of a business’s GRC, identify risks, analyze the data, develop policies to benefit the workplace, and consult on the best choice of action. Your duties may involve optimizing GRC systems, implementing tactics to lower risk, providing internal audits, assisting with cybersecurity, creating routine reports, and ensuring regulatory compliance.
What are the key skills and qualifications needed to thrive as a governance risk compliance professional?
How does a governance risk compliance professional typically collaborate with other departments within an organization?
What is the difference between Governance Risk Compliance vs Risk Analyst?
| Aspect | Governance Risk Compliance | Risk Analyst |
|---|---|---|
| Certifications | CRISC, CISA, CISSP | CFA, FRM, CRISC |
| Work Environment | Corporate, regulated industries | Financial, consulting firms |
| Employer & Industry Usage | Financial institutions, healthcare, government | Banking, investment firms, insurance |
Governance Risk Compliance focuses on establishing policies, ensuring regulatory adherence, and managing enterprise-wide risks. Risk Analysts primarily assess specific financial or operational risks through data analysis. While both roles involve risk management, Governance Risk Compliance has a broader scope related to organizational compliance and governance frameworks, whereas Risk Analysts concentrate on analyzing and quantifying particular risks.
What is the work of governance risk compliance?
What are the most commonly searched types of Governance Risk Compliance jobs in Boston, MA?
The most popular types of Governance Risk Compliance jobs in Boston, MA are:
What are popular job titles related to Governance Risk Compliance jobs in Boston, MA?
For Governance Risk Compliance jobs in Boston, MA, the most frequently searched job titles are:
What job categories do people searching Governance Risk Compliance jobs in Boston, MA look for?
The top searched job categories for Governance Risk Compliance jobs in Boston, MA are:
What cities near Boston, MA are hiring for Governance Risk Compliance jobs?
Cities near Boston, MA with the most Governance Risk Compliance job openings:

Full-time
This job post has expired today. Applications are no longer accepted.
Job description
The Manager, Security Governance & Risk leads Emburse's security governance, risk, and compliance function, with primary focus on enterprise security risk management, security metrics and reporting, and AI governance across both Emburse's AI-enabled products and internal AI use. This is a people-leadership role: the Manager leads a team of GRC professionals who independently manage day-to-day audit execution while the Manager owns the GRC operating model and platform strategy, governance, configuration standards, data integrity, automation, and reporting. This structure allows the Manager to focus on maturing how Emburse identifies, measures, and communicates security risk while maintaining accountability for the quality and effectiveness of the broader GRC program. The ideal candidate pairs credible GRC depth with genuine analytical rigor: someone who can turn control and risk data into decision-ready reporting for executives and the Board, establish governance for a fast-moving AI landscape, and grow the people on their team while doing it.
Lead, coach, and develop a team of GRC professionals by setting objectives, managing performance, and building career paths that deepen expertise across audit, privacy, and risk.
Own Emburse's GRC platform, including platform strategy, control architecture, integrations, data quality, automation, reporting, and continuous-control-monitoring maturity; delegate day-to-day platform administration and evidence operations to the team as appropriate.
Provide management oversight and quality assurance for security and compliance audits while delegating day-to-day audit planning, evidence coordination, auditor interaction, and execution; intervene directly on material findings, scope disputes, control deficiencies, or issues requiring management judgment.
Own the enterprise information security risk management program end to end, covering risk identification, assessment methodology, risk register maintenance, treatment planning, and tracking remediation to closure.
Continuously mature the risk program by improving the consistency, defensibility, and trend analysis behind how risk is scored and communicated, moving the organization beyond static point-in-time heat maps.
Own the Third-Party Risk Management program end to end, including vendor risk tiering, assessment methodology, due diligence standards, contractual security requirements, ongoing monitoring, and reassessment cadence, with ICs executing day-to-day vendor reviews and assessments against the standards and thresholds this role sets.
Build and own the security metrics and reporting framework, defining key risk and performance indicators, establishing authoritative data sources, and automating collection so reporting is repeatable rather than reassembled by hand each cycle.
Establish and lead Emburse's AI governance program, covering both AI capabilities within Emburse products and internal employee and vendor use of AI tools.
Track the evolving AI regulatory and framework landscape (e.g., EU AI Act, NIST AI RMF, ISO/IEC 42001, emerging state legislation) and translate obligations into concrete control and process requirements.
Own the security policy and standards lifecycle, ensuring alignment with industry frameworks (NIST, ISO 27001, PCI DSS, SOC 2) and keeping policies current, accessible, and enforceable.
Provide oversight of privacy program operations delivered by the team, ensuring obligations under GDPR, PIPEDA, CCPA/CPRA, and comparable regimes are met.
Partner with Engineering and Product on remediation of application and infrastructure security risk surfaced through risk assessments, penetration tests, and audit findings.
Sponsor continuous controls monitoring and automation initiatives that reduce manual evidence collection burden on the team and shorten audit cycles.
Education and Experience
Education:
Required: Bachelor's Degree; minimum 7+ years of information security, risk, or compliance experience, including 2+ years directly managing people or demonstrated equivalent team leadership (owning workstreams, mentoring, and developing others).
Experience:
Proven experience leading a security GRC function or team, with direct responsibility for the performance, development, and prioritization of team members.
Demonstrated ownership of an enterprise information security risk management program, including assessment methodology, risk register, and treatment tracking.
Strong track record building security metrics and reporting for executive, Board, or Audit Committee audiences, shaping what gets measured and why rather than only producing dashboards.
Working knowledge of security audit frameworks (PCI DSS, ISO 27001, ISO 27701, SOC 1, SOC 2, NIST, Tx-RAMP) sufficient to direct, quality-review, and defend audits executed by the team.
Familiarity with privacy frameworks and regulations (GDPR, CPRA/CCPA, PIPEDA) and how they translate into operational controls.
Experience with AI governance, AI risk assessment, or governance of other emerging technologies; familiarity with the EU AI Act, NIST AI RMF, or ISO/IEC 42001 strongly preferred.
Hands-on experience with GRC and compliance automation platforms (Drata, Vanta, or comparable), with enough depth to set direction and hold the team accountable for how the platform is configured and used.
Experience owning a third-party risk management program, including assessment methodology and vendor risk tiering, and managing commercial relationships with external audit firms, testing providers, and tooling vendors.
Demonstrable experience interacting with auditors and strategic partners in cloud-based environments similar to Emburse, relating to assurance frameworks such as SOX, PCI DSS, ISO 27001, SOC 2 Trust Principles, Business Continuity and Disaster Recovery, and Third-Party Risk Management.
Ability to remain organized and to elicit cooperation from a wide variety of sources, including team members, other internal departments, and external parties.
Ability to effectively prioritize and execute tasks in a high-pressure environment and react to project adjustments and alterations promptly and efficiently.
Ability to exercise good judgment and discretion in confidential matters.
Certifications:
Preferred: CISSP, CRISC, CISA, CIPP/E, CIPM, AIGP, PMP
Required Skills:
Strong analytical skills, with comfort pulling, structuring, and interpreting control and risk data, and building reporting that withstands scrutiny from auditors, executives, and customers.
Ability to explain risk in business terms and write clearly for executive audiences without oversimplifying the underlying technical reality.
Genuine people-leadership instincts: delegates real ownership, coaches rather than corrects, gives direct feedback, and creates room for the team to grow.
Comfortable operating with ambiguity in a domain where standards are still forming, and able to make defensible decisions before consensus exists.
Ability to influence without authority across Engineering, Product, Legal, Finance, and Sales.
Sound judgment about where to apply rigor and where to accept risk, rather than defaulting to maximum control.
Experience working on large cross-functional teams, representing GRC on initiatives such as change management, identity and access management, policy management, and data retention.
Ability to develop creative and adaptive solutions to unique and complex inquiries.
Comfortable with a rapid-paced working environment and meeting deadlines.
Team-focused, positive attitude, and good sense of humor.
About Emburse
Sourced by ZipRecruiter
Industry
Software development
Company size
11 - 50 Employees
Headquarters location
San Francisco, CA, US
Year founded
2014