Manager, Governance, Risk & Compliance
🏢 MRI Software · all MRI Software jobs
📍 United States
📅 Posted 2026-08-11 · via Himalayas
🏷 Governance-Risk-And-Compliance,Compliance-Management,Risk-Management,GRC-Leadership,Information-Security-Compliance,Governance-Risk-And-Compliance-Manager,Governance-And-Risk-Manager,Risk-and-Governance-Manager,Risk-And-Compliance-Manager
Apply on original site ↗MRI Software ’s Legal & Compliance team plays a critical role in protecting our organization and stakeholders through robust governance frameworks and proactive risk management. We are seeking an experienced Manager of Governance, Risk & Compliance (GRC) to lead and strengthen our compliance framework, risk management processes, and governance structures. You will serve as a trusted partner to internal teams across the organization, driving enterprise-wide compliance initiatives and ensuring MRI meets its regulatory obligations. In this role, you’ll report directly to the SVP of Legal and Compliance and have a seat at the table on strategic decisions affecting the business. This role offers meaningful impact: you’ll shape the GRC program strategy, mentor a team of analysts and specialists, and help build the infrastructure that supports MRI’s continued growth and success.
Key Responsibilities
-
Own and evolve MRI's GRC framework, including policies, procedures, internal controls, and risk appetite documentation, ensuring alignment with business objectives and regulatory requirements
-
Lead enterprise-wide risk assessments and work cross-functionally with Engineering, Product, IT, and business units to identify, evaluate, and mitigate operational, regulatory, cybersecurity, and strategic risks
-
Monitor the evolving regulatory landscape—including data privacy laws (GDPR, CCPA, state privacy regulations), financial services requirements, and industry standards—and translate regulatory changes into actionable compliance strategies
-
Drive SOC 2, ISO 27001, PCI-DSS and other compliance certifications, managing internal and external audit processes from planning through remediation
-
Design and deliver compliance training programs to promote a culture of accountability and ethical conduct across the organization
-
Develop and present executive-level risk and compliance dashboards, metrics, and reports to senior leadership, the board of directors, and key stakeholders
-
Oversee third-party risk management program, including vendor security assessments, contract risk review, due diligence, and ongoing monitoring of critical suppliers
-
Lead incident response and investigation efforts related to compliance breaches or policy violations
-
Manage and mentor a team of GRC analysts and specialists
-
Champion a compliance-forward culture by building relationships across the organization and making compliance accessible and practical for all teams
-
Partner with Legal, Sales, InfoSec, and Customer Success to support customer security questionnaires, RFP responses, and due diligence requests
Qualifications
-
Bachelor's degree in information security, business, law, or a related field; advanced degree (MBA, or Master’s in Cybersecurity/Risk Management) strongly preferred
-
8+ years of progressive experience in governance, risk, compliance, information security, or internal audit, with at least 4 years in a management or leadership capacity
-
Deep expertise in regulatory frameworks and standards including NIST, SOC 2, ISO 27001, NIST CSF, PCI, SaaS or technology industry experience required
-
Active professional certifications required: CISA, CRISC, CISSP, CIPP, CCEP, or equivalent; multiple certifications preferred
-
Proven track record of building, scaling, and maturing GRC programs in fast-growth technology environments
-
Executive presence with outstanding communication skills; ability to translate complex compliance requirements into business terms for technical and non-technical audiences
-
Hands-on experience implementing and optimizing GRC platforms (e.g., Jira, BitSite,OneTrust, Archer, LogicGate, Vanta, or Drata)
-
Experience managing customer-facing compliance activities, including security questionnaires, audits, and enterprise sales support
-
Strong business acumen with the ability to balance risk mitigation with business enablement
About Us
From the day we opened