1

Grc Compliance Manager Jobs (NOW HIRING)

Manage and track remediation of audit findings, exceptions, and risk acceptances, and conduct ... Hands-on experience administering a GRC or compliance automation platform such as Vanta, Drata ...

Manage and track remediation of audit findings, exceptions, and risk acceptances, and conduct ... Hands-on experience administering a GRC or compliance automation platform such as Vanta, Drata ...

$98K - $132K/yr

Your Day to Day As a Senior GRC Compliance Analyst you would be working on : * Serve as a senior ... Experience managing audit evidence and remediation during live audit cycles, with a bias toward ...

Serve as the definitive GRC/Compliance deep domain expert across the organization, translating ... Manage and mentor a high-performing organization of Product Managers, fostering a culture of ...

Director, Product, GRC/Compliance

San Jose, CA ยท On-site

$188K - $282K/yr

Serve as the definitive GRC/Compliance deep domain expert across the organization, translating ... Manage and mentor a high-performing organization of Product Managers, fostering a culture of ...

GRC Compliance Analyst

Bethpage, NY ยท On-site

$96K - $96K/yr

Job Summary This position is a direct report to the Technology Group Product Manager. The NERC ... GRC Compliance Analyst Location_formattedLocationLong: Bethpage, New York US

Cybersecurity GRC Compliance Lead

Chicago, IL ยท On-site

$83K - $141K/yr

The Cybersecurity GRC Compliance Lead will act as a subject matter expert in the delivery of the ... Strong knowledge of cyber regulations, risk management frameworks, and methodologies. * Strategic ...

Cybersecurity GRC Compliance Lead

Chicago, IL ยท On-site

$83K - $141K/yr

The Cybersecurity GRC Compliance Lead will act as a subject matter expert in the delivery of the ... Strong knowledge of cyber regulations, risk management frameworks, and methodologies. * Strategic ...

next page

Showing results 1-20

Grc Compliance Manager information

See salary details

$38.5K

$95.1K

$157K

How much do grc compliance manager jobs pay per year?

As of Jul 27, 2026, the average yearly pay for grc compliance manager in the United States is $95,103.00, according to ZipRecruiter salary data. Most workers in this role earn between $70,000.00 and $116,500.00 per year, depending on experience, location, and employer.

What is the difference between Grc Compliance Manager vs Risk Analyst?

AspectGrc Compliance ManagerRisk Analyst
CertificationsISO 27001 Lead Auditor, CISA, CISMFRM, CRM, CIA
Work EnvironmentCorporate, compliance departments, consulting firmsFinancial institutions, consulting, corporate risk teams
Employer & Industry UsageFinancial services, healthcare, technologyBanking, insurance, investment firms

The Grc Compliance Manager focuses on establishing and maintaining compliance frameworks, policies, and audits, ensuring organizations meet regulatory standards. The Risk Analyst evaluates potential risks, analyzes data, and develops strategies to mitigate financial and operational risks. While both roles require understanding of regulations and risk management, the Compliance Manager emphasizes compliance programs, whereas the Risk Analyst concentrates on risk assessment and data analysis.

What are the key skills and qualifications needed to thrive as a GRC Compliance Manager, and why are they important?

To thrive as a GRC Compliance Manager, you need a deep understanding of governance, risk management, and compliance frameworks, often supported by a relevant degree and certifications like CISA, CRISC, or CISSP. Familiarity with GRC tools such as RSA Archer, ServiceNow, or MetricStream, as well as knowledge of regulatory standards (e.g., SOX, GDPR), is typically required. Exceptional analytical, communication, and problem-solving skills help build strong policies and foster cross-departmental collaboration. These capabilities are vital for ensuring organizational adherence to regulations, minimizing risk, and maintaining a strong compliance posture.

What are some of the most common challenges faced by a GRC Compliance Manager, and how can they effectively address them?

GRC Compliance Managers often encounter challenges such as keeping up with evolving regulations, aligning organizational policies with industry standards, and fostering a culture of compliance across different departments. To effectively address these issues, they must stay current on regulatory updates, implement robust training programs, and collaborate closely with stakeholders in IT, legal, and business units. Regular risk assessments and clear communication channels are also key to proactively identifying and mitigating compliance gaps.

What is a GRC Compliance Manager?

A GRC Compliance Manager is a professional responsible for overseeing an organization's Governance, Risk Management, and Compliance (GRC) programs. They ensure that the company adheres to regulatory requirements, manages risks effectively, and implements policies and procedures to maintain compliance. Their role often includes assessing internal controls, performing audits, and facilitating training to promote a culture of compliance. By proactively identifying potential risks and gaps, GRC Compliance Managers help protect the organization from legal, financial, and reputational harm.
What cities are hiring for Grc Compliance Manager jobs? Cities with the most Grc Compliance Manager job openings:
What states have the most Grc Compliance Manager jobs? States with the most job openings for Grc Compliance Manager jobs include:
Manager - Cybersecurity GRC Compliance

Manager - Cybersecurity GRC Compliance

Ford Motor Company

Dearborn, MI โ€ข On-site, Remote

Full-time

Medical, Dental, Vision, Life, PTO

Posted 3 days ago


Job description


The Enterprise GRC (Governance, Risk, and Compliance) team functions as a second line of defense, responsible for developing and maintaining Enterprise Technology (ET) risk management and compliance in alignment with the organization's aligned framework. As regulatory landscapes grow more complex and cybersecurity threats continue to evolve, the need for a robust GRC framework has become mission-critical to the business.
The Cyber GRC Compliance & Certification Service Manager sits at the intersection of cybersecurity, regulatory compliance, and business operations - ensuring the organization maintains and demonstrates adherence to industry standards, regulatory requirements, and internal security policies. This role will lead efforts to continuously strengthen the organization's compliance posture across relevant frameworks (e.g., ISO 27001, SOC 2, NIST CSF, GDPR, CCPA, etc.) by managing certification lifecycles and serving as a key liaison between technical teams, auditors, and business stakeholders.
Responsibilities
Responsibilities:
A particular focus of this role is driving the organization's certification expansion roadmap, maintaining continuous evidence readiness, and ensuring ongoing internal and external audit preparedness - while proactively monitoring and mitigating risks that could impact certification scope or annual audit outcomes.
  • Audit & certification lifecycle management directs the end-to-end lifecycle of internal cybersecurity audits and compliance certifications, serving as the primary liaison for auditors while maintaining continued alignment with ISO27001, NIST CSF, SOC 2, CCPA and GDPR.
  • Certification expansion & readiness: Develops and executes a multi-year certification roadmap while driving continuous readiness through proactive gap analyses, mock audits, and a centralized, continuous evidence repository mapped to business and regulatory demands
  • Certification risk assessment & mitigation: Leads enterprise risk assessments, including internal self-risk assessments to identify compliance gaps, maintaining a continuous risk register with clear mitigation timelines while driving cross-functional corrective actions (CAPAs) through verified closure.
  • Stakeholder Partnership & Governance: Partners cross-functionally with engineering, legal, IT, cybersecurity, and business leadership to embed audit readiness into daily operations, translating complex regulatory requirements into actionable guidance while continuously updating security policies and control narratives.
  • Automation & Continuous Improvement: Optimizes GRC tooling to automate compliance processes and continuous control monitoring, streamlining evidence collection while tracking emerging regulations to proactively adapt the certification roadmap.
  • Reporting to Leadership: Delivers executive-level compliance metrics and risk dashboards that track certification roadmap progress, audit statuses, and open findings, providing leadership with the actionable visibility needed to support strategic decision-making

Qualifications
Basic Qualifications:
  • Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Risk Management, or equivalent professional experience.
  • At least 5+ years of experience in cybersecurity compliance, GRC, IT audit, or certification management.
  • Demonstrated hands-on experience managing initial certification, scope expansion, and annual/surveillance audits, such as ISO 27001, SOC2, NIST CSF, or similar.
  • Proven experience building and maintaining audit readiness programs, including continuous evidence management processes.
  • Proficiency with GRC platforms/tools for evidence, control management, and continuous monitoring (e.g., Archer GRC, ServiceNow GRC, OneTrust)
  • Exceptional verbal and written communication skills to effectively translate technical issues to non-technical audiences.
  • Experience directly interfacing with external auditors/certification bodies and managing audit logistics.
  • Strong program management skills with the ability to balance multiple concurrent audit timelines.

Preferred Qualifications:
  • Active industry credential certification such as ISO 27001 lead auditor/implementer, CISA, CRISC CISSP, or CISM.
  • Strong knowledge of NIST or ISO, and familiar with global data privacy regulations including GDPR, CCPA, and their intersection with technology risk management.
  • Experience operating within a three-line-of-defense(3LOD) risk governance model, particularly within a second-line GRC/risk oversight function.
  • Prior experience managing certification scope expansion (e.g., adding new sites, business units, or product lines to an existing certification with business/IT alignment)
  • Familiarity with continuous control monitoring (CCM) approaches and GRC tool compliance features.
  • Experience managing relationships with multiple certification bodies/external audit firms simultaneously.
  • Background in leading mock audits or internal audit programs

You may not check every box, or your experience may look a little different from what we've outlined, but if you think you can bring value to Ford Motor Company, we encourage you to apply!
As an established global company, we offer the benefit of choice. You can choose what your Ford future will look like: will your story span the globe, or keep you close to home? Will your career be a deep dive into what you love, or a series of new teams and new skills? Will you be a leader, a changemaker, a technical expert, a culture builder...or all of the above? No matter what you choose, we offer a work life that works for you, including:
โ€ข Immediate medical, dental, vision and prescription drug coverage
โ€ข Flexible family care days, paid parental leave, new parent ramp-up programs, subsidized back-up child care and more
โ€ข Family building benefits including adoption and surrogacy expense reimbursement, fertility treatments, and more
โ€ข Vehicle discount program for employees and family members and management leases
โ€ข Tuition assistance
โ€ข Established and active employee resource groups
โ€ข Paid time off for individual and team community service
โ€ข A generous schedule of paid holidays, including the week between Christmas and New Year's Day
โ€ข Paid time off and the option to purchase additional vacation time.
This position is leadership level 6 and ranges from $115,500-$218,100.
Final determination of salary grade will be based on candidate's skills and experience, and base salary will be set within the applicable range according to job scope, responsibility and competitive market value.
For more information on salary and benefits, click here: https://fordcareers.co/LL6
Visa sponsorship is not available for this position.
Candidates for positions with Ford Motor Company must be legally authorized to work in the United States. Verification of employment eligibility will be required at the time of hire.
We are an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, age, sex, national origin, sexual orientation, gender identity, disability status or protected veteran status. In the United States, if you need a reasonable accommodation for the online application process due to a disability, please call 1-888-336-0660.
#LI-Remote
#LI-GR1
About Us
At Ford Motor Company, we believe freedom of movement drives human progress. With our incredible plans for the future of mobility, we have a wide variety of opportunities for you to accelerate your career and help us define tomorrow's transportation.
About the Team
We believe that freedom of movement drives human progress. Ford Information Technology (IT) is shaping the future of mobility by redefining the transportation landscape, enhancing the customer experience and improving people's lives. Join the Ford family as we change the way the world moves.

Ford logo

About Ford

Sourced by ZipRecruiter

At Ford Motor Company, we believe freedom of movement drives human progress. With our incredible plans for the future of mobility, we have a wide variety of opportunities for you to accelerate your career and help us define tomorrow's transportation.

Industry

Civil engineering construction

Company size

51 - 200 Employees

Headquarters location

Doral, FL, US

Year founded

1982