Manager, Information Security (GRC) (Remote)
Indexed description
You will be the connective tissue between security engineering, legal, engineering, and executive leadership: translating regulatory and contractual requirements into practical controls, and translating control performance into risk language leadership can act on.
This role directly protects Neumo's ability to do business: Our certifications are foundational to customer trust and revenue. You will have the mandate to modernize how we manage risk and compliance, including building automation and AI-driven workflows that scale the program without scaling headcount linearly.
Duties and Responsibilities:
Leadership & Program Ownership
- Own and execute Neumo's GRC strategy and roadmap, in partnership with the CISO.
- Manage, mentor, and grow 1–2 direct reports supporting compliance, risk, and audit activities.
- Set the foundation for data governance: data classification, ownership, retention, and handling standards.
- Build and maintain the risk register; lead monthly, quarterly, and annual risk mitigation cycles.
- Own the risk acceptance and policy exception process, including documentation, approval workflows, and periodic review.
- Report on compliance posture, audit status, and risk trends to executive stakeholders and the board as needed.
- Own end-to-end readiness and execution for SOC 1, SOC 2, and PCI DSS audits, including evidence collection, auditor coordination, and remediation tracking.
- Maintain and continuously improve the internal control framework mapped to SOC 1/2, PCI, and other applicable frameworks (e.g., ISO 27001, NIST CSF).
- Track control ownership, testing cadence, and control health across the organization using the GRC platform and Jira.
- Partner with engineering and IT teams to close control gaps and drive remediation of audit findings within SLA.
- Design and implement control automation to reduce manual evidence collection and continuous control monitoring (CCM).
- Leverage AI/LLM tooling to accelerate evidence review, policy drafting, control testing, and risk analysis, with appropriate human oversight.
- Participate in incident management as the GRC/risk representative: assessing regulatory and contractual impact and ensuring proper documentation.
- Manage third-party/vendor risk assessments and questionnaires (customer security questionnaires, vendor due diligence).
- Partner with Legal and Privacy on data protection, regulatory, and contractual compliance requirements.
- 6+ years of experience in GRC, information security compliance, or IT audit, including experience managing or mentoring others.
- Direct experience owning SOC 1, SOC 2, and PCI DSS compliance programs end-to-end, including audit management.
- Hands-on experience with GRC platforms (e.g., Vanta, Drata, ServiceNow GRC, OneTrust, Archer, or similar).
- Experience building risk management programs: risk registers, risk acceptance/exception processes, and recurring risk mitigation cadences.
- Foundational experience with data governance concepts (classification, ownership, retention).
- Relevant certifications (e.g., CISA, CRISC, CISSP, CISM) are a plus but not required.
- Strong working knowledge of Jira for control tracking, remediation workflows, and cross-team coordination.
- Demonstrated ability to build or deploy control automation and continuous control monitoring.
- Comfort leveraging AI tools to scale GRC operations (evidence review, policy generation, risk analysis).
- Ability to participate effectively in incident management, translating technical incidents into risk and compliance impact.
- Excellent written and verbal communication skills; able to translate technical and regulatory detail for executive audiences.
- Office setting with a moderate noise level.
- The employee will work at an individual workstation, using a telephone and computer.
- Periodic flexibility outside standard business hours may be required to support audits or incident response.
- Must be able to remain seated for extended periods.
- Regular use of a computer and other office machinery, such as printers and copy machines.
- Occasional movement around the office.
- Frequent communication via telephone.
Neumo is committed to helping communities thrive and brings a wealth of experience combined with innovation. Today, Neumo offers more administrative and financial support to government officials than any other organization. And with a responsive, client-focused approach, we foster partnerships that give our customers the certainty they need to accomplish more.
Neumo offers a competitive benefits and compensation package and are looking for team members who will thrive in our dynamic environment.
Neumo is an Equal Opportunity Employer. Selection for a position will be made without regard to race, religion, national origin, sex, political affiliation, marital status, non-disqualifying physical handicap, and age.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search