1

Grc Lead Jobs (NOW HIRING)

Job Summary The SAP GRC Lead is a senior specialist responsible for governing identity, access, risk, and compliance across the organization's SAP landscape. This role owns the end-to-end GRC ...

New

GRC Lead

New York, NY · On-site

$67 - $68/hr

GRC Lead requires: * Hands-on experience implementing or managing audit technology platforms, specifically AuditBoard (SOXHUB, OpsAudit, RiskOversight)., Proficiency with data analytics tools such as ...

We are seeking a highly skilled GRC Tech Lead with a strong focus on AuditBoard to join our team. The successful candidate will have extensive experience supporting/managing audit technology ...

New

SAP GRC Lead Hybrid Role in Plano, TX / Responsibilities > 10+ yrs of Experience in SAP GRC Access Control 12/10.x > SAP GRC Access Controls implementation project experience mandatory > Should be ...

Public Sector GRC Lead Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn't a buzzword -- it's a ...

Public Sector GRC Lead Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn't a buzzword -- it's a ...

GRC Lead

New York, NY · On-site

$232K - $273K/yr

You use AI tools daily in your own work and have specific, grounded views on which GRC workflows AI can run today and which it cannot. NICE TO HAVE * ISO 42001 Lead Auditor, ISO 27001 Lead Auditor ...

The IT Governance, Risk, and Compliance (GRC) Lead Analyst serves as a subject matter expert responsible for leading the design, implementation, maturity, and continuous improvement of the ...

Founding GRC Lead

San Francisco, CA · On-site

$175K - $225K/yr

You could be a GRC Lead anywhere, why us? * Join a well-funded, high-growth startup on the path to IPO ($50M raised, 700% revenue growth in 2 years, targeting a $6T market) * Work directly with our ...

The IT Governance, Risk, and Compliance (GRC) Lead Analyst serves as a subject matter expert responsible for leading the design, implementation, maturity, and continuous improvement of the ...

Senior Security GRC Lead Austin | Chicago | New York City | Salt Lake City | San Francisco Gong harnesses the power of AI to transform how revenue teams win. The Gong Revenue AI Operating System ...

As a Senior GRC Engineer, you will drive critical GRC processes that mitigate risk, keep us compliant, and build trust with our customers and partners. You'll evolve the technical foundation of our ...

The Public Sector GRC Lead role is part of Informatica's Security and Compliance organization, sitting at the heart of our public sector growth. Our team works to maintain and expand the compliance ...

R2R GRC Lead 0-4 month(s) SAN FRANCISCO CA 94105 $100/hr on c2c Configuration of AACG segregation of duty rules per requirements using the delivered Oracle AACG rules library, Accenture SOD models ...

Senior Security GRC Lead Austin | Chicago | New York City | Salt Lake City | San Francisco Gong harnesses the power of AI to transform how revenue teams win. The Gong Revenue AI Operating System ...

Senior Security GRC Lead Austin | Chicago | New York City | Salt Lake City | San Francisco Gong harnesses the power of AI to transform how revenue teams win. The Gong Revenue AI Operating System ...

Senior Security GRC Lead Austin | Chicago | New York City | Salt Lake City | San Francisco Gong harnesses the power of AI to transform how revenue teams win. The Gong Revenue AI Operating System ...

Senior Security GRC Lead Austin | Chicago | New York City | Salt Lake City | San Francisco Gong harnesses the power of AI to transform how revenue teams win. The Gong Revenue AI Operating System ...

next page

Showing results 1-20

Grc Lead information

What are some common challenges a GRC lead might face when implementing new compliance frameworks across an organization?

A GRC Lead often encounters challenges such as resistance to change from staff, aligning diverse departmental processes with new compliance requirements, and ensuring consistent communication across teams. Balancing the need for thorough documentation with operational efficiency can also prove difficult. Successfully overcoming these obstacles requires strong interpersonal skills, a strategic approach to change management, and the ability to educate and motivate stakeholders at all levels of the organization.

What are the key skills and qualifications needed to thrive as a GRC lead, and why are they important?

To thrive as a GRC Lead, you need expertise in governance, risk management, and compliance frameworks, often supported by a relevant degree and certifications such as CISA, CRISC, or CISSP. Familiarity with GRC platforms like RSA Archer, ServiceNow GRC, or MetricStream is typically required. Strong analytical thinking, leadership, and communication skills distinguish top performers in this role. These capabilities are crucial for ensuring organizational compliance, minimizing risks, and effectively aligning security strategies with business goals.

Is GRC still in demand?

GRC (Governance, Risk, and Compliance) roles are currently in high demand due to increasing regulatory requirements and cybersecurity concerns. Professionals with skills in risk management, compliance frameworks, and familiarity with tools like RSA Archer or ServiceNow are sought after across various industries. Certifications such as CISA or CISSP can enhance job prospects in this field.

Are GRC Lead jobs hard to get?

GRC Lead jobs can be competitive due to the specialized skills required, such as knowledge of governance, risk management, and compliance frameworks. Candidates with relevant certifications like CISA or CISSP, along with experience in cybersecurity or audit, tend to have better prospects. Strong communication and leadership skills also enhance employability in this role.

What is a GRC lead?

GRC Leads are professionals responsible for overseeing Governance, Risk, and Compliance (GRC) programs within an organization. They ensure that the company adheres to legal, regulatory, and internal policy requirements while managing risks and maintaining effective controls. GRC Leads coordinate across departments to implement frameworks, conduct risk assessments, and drive compliance initiatives. Their role is crucial in protecting the organization from legal and reputational risks and ensuring operational integrity.

What is the difference between Grc Lead vs Grc Analyst?

AspectGrc LeadGrc Analyst
CredentialsCertifications like CISA, CRISC often preferredSimilar certifications, often entry to mid-level
Work EnvironmentLeads teams, manages projects, strategic planningPerforms analysis, audits, and reporting tasks
Employer & Industry UsageUsed in large organizations for governance, risk, complianceCommon in security and compliance departments
Search & Comparison IntentOften searched for career progression or role differencesOften searched for entry-level or role clarification

The Grc Lead typically oversees GRC teams, manages strategic initiatives, and requires advanced certifications. The Grc Analyst focuses on conducting audits, analyzing risks, and supporting compliance activities. While both roles require similar certifications, the Lead has more managerial responsibilities, whereas the Analyst is more hands-on with analysis and reporting.

More about Grc Lead jobs
What cities are hiring for Grc Lead jobs? Cities with the most Grc Lead job openings:
What states have the most Grc Lead jobs? States with the most job openings for Grc Lead jobs include:
What job categories do people searching Grc Lead jobs look for? The top searched job categories for Grc Lead jobs are:
Infographic showing various Grc Lead job openings in the United States as of August 2026, with employment types broken down into 87% Full Time, 10% Part Time, and 3% Contract. Highlights an 91% Physical, 3% Hybrid, and 6% Remote job distribution.

Full-time

Medical, Dental, Vision, Retirement, PTO

Posted 3 days ago

New


Job description

At GAF, we cover more than buildings. We cover each other. No matter what role, tenure, or track, under this roof you are empowered to be there for your teammates, your customers, and especially your community. Under this roof, we don't back down from hard work- we support one another in pursuit of something bigger. We define the future while leading the present. And under this roof, we own our opportunities. Becoming the market leader only happens when everyone feels they have the opportunity, and the support, to thrive. We are GAF. And under this roof, we protect what matters most.

Job Summary
The SAP GRC Lead is a senior specialist responsible for governing identity, access, risk, and compliance across the organization's SAP landscape. This role owns the end-to-end GRC strategy covering SAP GRC Access Control, SAP Identity Access Governance (IAG) on BTP, and the security models for all SAP SaaS platforms - including SAP Ariba, SAP Analytics Cloud (SAC), and SAP Integrated Business Planning (IBP). The GRC Lead acts as the primary point of accountability for SoD risk mitigation, access provisioning governance, and audit readiness across on-premise and cloud-based SAP systems.
Essential Duties

  • GRC Strategy & Governance
    Define and maintain the enterprise GRC framework spanning SAP on-premise and cloud, aligned with internal audit, legal, and regulatory requirements
    Own the SoD (Segregation of Duties) rule-set across all connected SAP systems; manage conflict detection, mitigation controls, and compensating control documentation
    Lead periodic access review and certification campaigns; drive remediation to closure
    Establish policies and procedures for privileged access, emergency access management (EAM / Firefighter), and periodic user access reviews

  • SAP GRC Access Control
    Administer and configure SAP GRC AC modules: Access Request Management (ARM), Access Risk Analysis (ARA), Emergency Access Management (EAM), and Business Role Management (BRM)
    Design and maintain the GRC connector landscape for S/4HANA, ECC, and connected SaaS systems
    Manage workflow configuration, MSMP routing rules, and approval hierarchies within GRC AC
    Perform ruleset reviews and fine-tune risk definitions to minimize false positives while maintaining SOX/audit coverage

  • SAP Identity Access Governance (IAG) on BTP
    Own the SAP IAG deployment on BTP: tenant configuration, IAS integration, access analysis, and role assignment workflows
    Manage BTP trust configuration between IAG and SaaS platform connectors
    Coordinate with the BTP Integration Lead on XSUAA scoping, role collection design, and subaccount trust settings relevant to IAG

  • SaaS Platform Security Models
    Govern the security model for SAP Ariba:
    Procurement and sourcing role design, user provisioning, and SoD rules for Ariba Buying, Invoicing, and Contracts
    Ariba Network realm administration and supplier access governance
    Govern the security model for SAP Analytics Cloud (SAC):
    Team and role model design; story, model, and data access permissions
    Integration with CDS view security for governed data access
    Govern the security model for SAP Integrated Business Planning (IBP):
    Supply-chain planning user roles, keyfigure-level access, and planning area security
    IBP-to-S/4HANA integration security and cross-system SoD alignment
    Maintain consistent naming conventions, provisioning workflows, and access certification cycles across all three SaaS platforms

  • Stakeholder Engagement & Team Leadership
    Partner with Business Process Owners, IT Security, and Internal Audit to align GRC priorities and risk appetite
    Mentor GRC analysts and role administrators; build team capability on IAG, SaaS security models, and audit processes
    Engage with SAP and third-party vendors on GRC product roadmap, patches, and best practices

Qualifications Required

  • Bachelor's Degree is required

  • 8+ years of SAP security and GRC experience, with at least 3 years in a lead or architect capacity

  • Deep hands-on expertise with SAP GRC Access Control (AC 12.x): ARM, ARA, EAM, BRM modules

  • Proven experience implementing and administering SAP IAG on BTP

  • Demonstrated experience governing the security model for at least two of the three key SaaS platforms: SAP Ariba, SAP Analytics Cloud, or SAP IBP

  • Strong understanding of SoD concepts, audit principles, and access control frameworks (SOX, ITGC)


General Knowledge, Skills and Abilities

  • Proficient level: Strategic and Visionary Leadership: Strategic Thinking, innovation driving, Decision making

  • Proficient level: Change Management and Adaptability: Managing resistance, adaptability, resilience

  • Proficient level: People and Relationship Management: Emotional Quotient, Communication, collaboration

  • Proficient level: Technical and Business Acumen: Digital Literacy, Business/Finance Acumen, Process Design

  • Proficient level:: Personal Drive and Mindset: Growth mindset, action oriented, courage


Technical Knowledge, Skills and Abilities

  • SAP authorization concepts: authorization objects, PFCG role design, structural profiles, and S/4HANA role design

  • SCIM API integration for automated provisioning across SaaS platforms

  • Working knowledge of SAP BTP XSUAA and role collections

  • GRC reporting: exposure to SAP GRC dashboards, custom ABAP reports, or BI-based access reporting


Qualifications Preferred

  • SAP Certified Application Associate - SAP GRC Access Control or equivalent certification

  • Experience with SAP Identity Authentication Service (IAS) and Identity Provisioning Service (IPS) for automated lifecycle management

  • Experience integrating GRC workflows with ITSM platforms (ServiceNow, Jira) for automated access requests

  • Knowledge of S/4HANA CDS view-level access control and ABAP-level authorization debugging (SU53, ST01, SU24)

  • Flexibilty to travel: Travel may be extensive at times to accommodate program needs, including support for program activities, vendor meetings, and site visits as necessary.

Base salary and/or rate of pay ranges listed are exclusive of fringe benefits and potential bonuses. Individual compensation offers will be determined based on a variety of factors, including but not limited to geographic location, relevant candidate experience and skill, education, and/or qualifications.Base Salary Range: $140,000-$192,500

How We Protect What Matters Most:

1. We offer a wide range of health insurance options that include medical, dental, and vision for you and your family. 2. Our Family-Building benefits support the many different journeys to fertility and parenthood. 3. Our robust 401K plan includes an employer match contribution with your pre-tax and/or Roth contributions. 4. Other exciting programs and perks are available to help employees achieve work-life balance, including (but not limited to) a wellness program, free financial coaching, a referral program, and product rebates when purchased for an employee's primary residence. 5. Professional growth and development are very important to us! We offer internal training programs and courses, as well as a generous tuition reimbursement program. 6. We're committed to fostering a culture that reflects our values to connect, empower, evolve, and inspire. We offer many opportunities for employees to connect with one another, including through our Employee Resource Groups who focus on education and allyship for all of our employees.

GAF complies with federal, state, and local disability laws and makes reasonable accommodations for applicants and employees with disabilities. If a reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact HR Services at 833-HR-XPERT.

We believe our employees are our greatest resource. We offer competitive salary, benefits, 401k, and vacation packages for all full time permanent positions. We are proud to be an equal opportunity workplace. We are committed to equal employment opportunity on the basis of each candidate's qualifications, experience, and merit, without regard to race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity, or Veteran status. If you have a disability or special need that requires accommodation, please let us know. If applying for positions in the U.S., must be eligible to work in the U.S. without need for employer sponsored visa (work permit).

GAF logo

About GAF

Sourced by ZipRecruiter

With 130+ years in the industry, GAF is the leading roofing manufacturer in North America. As a member of the Standard Industries family of companies, we are also part of the largest roofing and waterproofing business in the world. Our communities help give our work meaning and the products we manufacture help protect what matters most. The shingles help to shelter the families living in the homes in our towns. The TPO helps protect what is under that hospital’s roof. In addition to quality products, we make sure they are installed by quality craftsmen and women. The full GAF portfolio of solutions is supported by an extensive national network of factory-certified contractors. GAF continues to be the leader in quality and offers comprehensive warranty protection on its products and systems. Our success is driven by a commitment to empowering our people to deliver advanced quality and purposeful innovation and the desire to protect what matters most. ​

Industry

Construction materials wholesalers

Company size

1,001 - 5,000 Employees

Headquarters location

Parsippany, NJ, US

Year founded

1886