Manager, Governance, Risk & Compliance

🏢 MRI Software · all MRI Software jobs
📍 United States
📅 Posted 2026-08-29 · via Himalayas
🏷 Governance-Risk-And-Compliance,Compliance-Management,Risk-Management,GRC-Leadership,Information-Security-Compliance,Governance-Risk-And-Compliance-Manager,Governance-And-Risk-Manager,Risk-and-Governance-Manager,Risk-And-Compliance-Manager,Cybersecurity-Governance-Risk-and-Compliance-Manager
Apply on original site ↗

MRI Software ’s Legal & Compliance team plays a critical role in protecting our organization and stakeholders through robust governance frameworks and proactive risk management. We are seeking an experienced Manager of Governance, Risk & Compliance (GRC) to lead and strengthen our compliance framework, risk management processes, and governance structures. You will serve as a trusted partner to internal teams across the organization, driving enterprise-wide compliance initiatives and ensuring MRI meets its regulatory obligations. In this role, you’ll report directly to the SVP of Legal and Compliance and have a seat at the table on strategic decisions affecting the business. This role offers meaningful impact: you’ll shape the GRC program strategy, mentor a team of analysts and specialists, and help build the infrastructure that supports MRI’s continued growth and success.

Key Responsibilities

-
Own and evolve MRI's GRC framework, including policies, procedures, internal controls, and risk appetite documentation, ensuring alignment with business objectives and regulatory requirements

-
Lead enterprise-wide risk assessments and work cross-functionally with Engineering, Product, IT, and business units to identify, evaluate, and mitigate operational, regulatory, cybersecurity, and strategic risks

-
Monitor the evolving regulatory landscape—including data privacy laws (GDPR, CCPA, state privacy regulations), financial services requirements, and industry standards—and translate regulatory changes into actionable compliance strategies

-
Drive SOC 2, ISO 27001, PCI-DSS and other compliance certifications, managing internal and external audit processes from planning through remediation

-
Design and deliver compliance training programs to promote a culture of accountability and ethical conduct across the organization

-
Develop and present executive-level risk and compliance dashboards, metrics, and reports to senior leadership, the board of directors, and key stakeholders

-
Oversee third-party risk management program, including vendor security assessments, contract risk review, due diligence, and ongoing monitoring of critical suppliers

-
Lead incident response and investigation efforts related to compliance breaches or policy violations

-
Manage and mentor a team of GRC analysts and specialists

-
Champion a compliance-forward culture by building relationships across the organization and making compliance accessible and practical for all teams

-
Partner with Legal, Sales, InfoSec, and Customer Success to support customer security questionnaires, RFP responses, and due diligence requests

Qualifications

-
Bachelor's degree in information security, business, law, or a related field; advanced degree (MBA, or Master’s in Cybersecurity/Risk Management) strongly preferred

-
8+ years of progressive experience in governance, risk, compliance, information security, or internal audit, with at least 4 years in a management or leadership capacity

-
Deep expertise in regulatory frameworks and standards including NIST, SOC 2, ISO 27001, NIST CSF, PCI, SaaS or technology industry experience required

-
Active professional certifications required: CISA, CRISC, CISSP, CIPP, CCEP, or equivalent; multiple certifications preferred

-
Proven track record of building, scaling, and maturing GRC programs in fast-growth technology environments

-
Executive presence with outstanding communication skills; ability to translate complex compliance requirements into business terms for technical and non-technical audiences

-
Hands-on experience implementing and optimizing GRC platforms (e.g., Jira, BitSite,OneTrust, Archer, LogicGate, Vanta, or Drata)

-
Experience managing customer-facing compliance activities, including security questionnaires, audits, and enterprise sales support

-
Strong business acumen with the ability to balance risk mitigation with business enablement

About Us

From the day we opened

← All remote jobs

Similar for you