Security GRC Manager

Job not on LinkedIn

🕒 April 15

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Hex

Hex

51 - 200 employees

🤖 Artificial Intelligence

☁️ SaaS

Artificial Intelligence • Data Analytics • SaaS

Hex is a collaborative, AI-powered workspace that brings teams together with data. It enables end-to-end workflows, from quick queries to deep-dive analyses, and facilitates the creation of interactive data apps. Hex integrates various tools such as SQL, Python, R, and spreadsheets in a modular, notebook-based canvas, allowing users to generate queries, create visualizations, and perform analyses with ease. The platform supports teamwork by allowing feedback from peers, alignment with stakeholders, and the building of reusable components. Hex also offers a drag-and-drop builder for creating interactive reports and dashboards. With built-in connections to popular data warehouses and databases, Hex simplifies data integration and collaboration for thousands of teams. Its deep integration with tools like dbt, Snowpark for Snowflake, and orchestration frameworks like Airflow enhances its functionality in data science and business intelligence. Hex is designed for security and offers enterprise-grade controls, making it a trusted platform for data teams worldwide.

📋 Description

• Own and mature Hex’s security and privacy compliance program across SOC 2, ISO 27001, ISO 27701, HIPAA, GDPR, CCPA, PCI DSS, and other frameworks relevant to our business • Ensure continuous audit readiness: maintain controls, gather evidence, manage auditors, and implement improvements. • Track regulatory and industry changes, advising Hex leadership on impact and recommended responses. • Maintain and develop core security policies, standards, and procedures, tailoring them to Hex’s real operating environment. • Own Hex’s risk management lifecycle: identify, assess, track, and drive mitigation of security, privacy, operational, and regulatory risks. • Build lightweight but effective governance processes, ensuring clear ownership, documentation, and accountability. • Serve as the primary owner of customer and prospect security questionnaires, risk assessments, and contractual security provisions. • Manage and improve Hex’s Trust Center / trust portal, ensuring accurate and compelling communication of Hex’s security posture. • Lead internal and external audits from planning through remediation. • Own Hex’s third-party risk management program, including vendor assessments, reviews, and ongoing monitoring. • Define and run security awareness training tailored to Hex’s environment.

🎯 Requirements

• 5–8+ years in GRC, compliance, security engineering, privacy, audit, or a related field • Deep familiarity with frameworks such as SOC 2, ISO 27001, ISO 27701, PCI DSS, HIPAA, GDPR, and associated security controls • Experience running or contributing significantly to audit cycles and certification processes • Technical literacy in cloud-native environments (AWS preferred), SaaS architectures, and modern security tooling • Ability to understand and explain product architecture, data flows, and control implementations to auditors and customers

🏖️ Benefits

• Competitive total rewards package • Comprehensive health benefits • Flexible paid time off

Apply Now

Similar Jobs

🕒 April 15

Polsinelli

1001 - 5000

🤝 B2B

📋 Compliance

Security Engineer ensuring secure operations of IT infrastructure and applications at Polsinelli. Focused on cybersecurity engineering, threat hunting, and team collaboration on security strategies.

Azure

Cyber Security

Python

Splunk

🕒 April 14

PwC

10,000+ employees

💸 Finance

☁️ SaaS

Senior Manager in cloud security at PwC focusing on cybersecurity threats. Leading development and implementation of cloud security strategies with advanced technologies.

AWS

Azure

Cloud

Cyber Security

Google Cloud Platform

Kubernetes

🕒 April 14

GEICO

10,000+ employees

💸 Finance

Senior Field Security Investigator conducting investigations of insurance fraud and illegal activities against GEICO. Evaluating information credibility and supporting claims handling departments.

🕒 April 14

NBCUniversal

10,000+ employees

📱 Media

Cyber Security Manager leading Cyber Security initiatives for NBCUniversal. Fostering collaboration across Studios, Film, and Television departments while mitigating risks in the operational framework.

Cyber Security

🕒 April 14

Jito Labs

1 - 10

Engineer strengthening security posture for Jito's infrastructure and supporting product security lifecycle. Owning broad operational and technical scope in a fast-moving environment.