Sr Project Manager, GRC (Governance Risk and Compliance)

🏒 Coterie Insurance · all Coterie Insurance jobs
πŸ“ United States
πŸ’° USD 115,000 - 140,000 / annual
πŸ“… Posted 2026-08-24 Β· via Himalayas
🏷 GRC-Project-Management,Compliance-Project-Management,Security-Project-Management,IT-Governance,Risk-Management,Compliance-Project-Manager,Cybersecurity-Governance-Risk-and-Compliance-Manager,Sr.-Project-Management-Office-Manager,Project-Manager
Apply on original site β†—

Who we are:
Through a partnership-based approach, Coterie helps insurance professionals unlock untapped revenue in the small commercial space. With an innovative quoting platform that delivers accurate pricing and bindable quotes in less than one minute, Coterie makes small business insurance effortless.

We are on a mission to build and foster a world-class team to bring speed, simplicity, and service to commercial insurance. We value integrity, humility, passion, and intelligence. If you want to push yourself and reshape a $200B+ market, we’re excited to talk to you!

Position Summary:

Coterie's GRC team is hiring a Senior Project Manager to own remediation projects tied to SOC 2, ITGC, and regulatory compliance requirements, including emerging regulations in privacy, AI governance, and security. The role also supports recurring compliance programs, such as the annual risk assessment cycle, from a scheduling and tracking standpoint, maintaining visibility into risk treatment plan status. While the role reports through GRC, projects may span security, legal, compliance, finance, and other functions depending on business need. The ideal candidate combines strong project management discipline with enough technical fluency to work credibly with engineers and security practitioners including translating security and compliance requirements into work technical teams can execute, along with the ability to build the reporting and dashboards leadership needs to track progress.

Key Responsibilities:

Remediation Project Management

- Own end-to-end delivery of remediation projects tied to SOC 2, ITGC, and regulatory compliance requirements, translating audit findings, control gaps, and new regulatory obligations (privacy, AI governance, security) into scoped plans, milestones, and assigned owners, and driving them to closure.

- Manage 2 to 4 concurrent projects across security, legal, compliance, finance, or other functions, maintaining a project plan with tracked risks, issues, and dependencies, and escalating blockers before they affect timelines.

- Translate security and compliance requirements into clear, actionable work for engineering and technical teams

- Apply Agile, waterfall, or hybrid methodologies as fits the regulatory deadline driving the work.

Risk & Compliance Program Tracking

- Support the annual risk assessment cycle and similar recurring compliance programs by maintaining schedules, coordinating stakeholder input and deadlines, and keeping deliverables on time.

- Track and report the status of risk treatment plans across owners and due dates, flagging at-risk items.

- Maintain project and risk-tracking data in the team's project management or GRC/IRM platform (e.g., Jira, Optro) as the accurate source of truth.

- Coordinate with external auditors as needed to confirm remediation deliverables meet audit requirements.

Stakeholder & Executive Reporting

- Serve as the primary point of contact for remediation and project status across Security, Legal, Compliance, Finance, and other business stakeholders.

- Build and maintain leadership-facing reporting and dashboards showing remediation progress and risk treatment plan status.

- Deliver clear, concise status updates and risk escalations to executive leadership and governance forums.

- Facilitate project meetings and working sessions, documenting decisions and action items and tracking them to closure.

Process Improvement

- Improve project management and tracking processes, templates, and tooling to increase consistency and efficiency across GRC's remediation project portfolio.

- Help mature GRC's approach to intake, prioritization, and resourcing of new remediation and compliance tracking work.

Required Qualifications:

- 6+ years of project management experience, including leading complex, cross-functional projects; 2+ years running remediation projects tied to security, compliance, or regulatory findings strongly preferred.

- Experie

← All remote jobs