Jobs and Careers
DR

Senior Manager, GRC (Remote)

Drata
United States, United StatesRemotefull_timeVerifiedPosted 18 Mar 2025
💰 $229,800/yr($148,900/yr$229,800/yr)

About the role

At Drata, members of the GRC team have a rare opportunity to be Customer Zero—we actively use the same GRC platform that our customers rely on. This means your work as Senior Manager, GRC will directly shape the product we’re continually developing and improving, and it directly impacts Drata’s core mission. Your insights will help define and refine Drata’s product journey, user experience, and strategic objectives. You’ll be collaborating with product, engineering, and leadership teams, providing crucial feedback that ensures our solution exceeds the needs of both our own compliance program and those of our global clientele. This isn’t just a GRC role—it’s a chance to be at the forefront of innovation, influencing Drata’s success every step of the way!

Drata’s Senior Manager, GRC will drive the strategic vision and execution of governance, risk, compliance, and trust management initiatives, enabling Drata’s customers to achieve and maintain adherence with security and compliance standards, frameworks, applicable laws and regulations, industry best practices, and all relevant internal policies. In this role, the ideal candidate will collaborate with external and internal assessors and senior stakeholders across the organization, fostering strong partnerships to help ensure successful ongoing operations and completion of compliance processes, testing, and continuous improvement of controls and risk mitigation plans. As a leader, you will champion process optimization, enhance operational efficiencies, and oversee the development of mature compliance programs that align with organizational objectives. Proficiency in industry-related audits, such as SOC 2 Type 2, HIPAA, ISO 27001/27017/27018/42001, NIST CSF, NIST 800-171, FedRAMP, and CMMC is essential. Familiarity with the GDPR, data privacy, and data security regulations is also a must.

What you'll do: 

  • Champion Continuous Improvement:
    Don’t just trust the process—elevate it. Drive strategic initiatives to automate and enhance Drata’s compliance operations, helping ensure our platform remains the industry leader for Trust Management and GRC. Offer actionable insights to product teams based on daily platform usage, and devise cutting-edge solutions for complex challenges such as vendor management, onboarding/offboarding, and internal/external assessments. Identify control requirement best practices and guide us on how to best implement their security controls – expanding our current external assessment compliance attestation footprint to include applicable requirements for customers needing to obtain and comply with even the most stringent requirements such as FedRAMP (all impact levels) and others.
  • Maintain Oversight and Accountability:
    Provide executive-level oversight of company-wide compliance-related functions to confirm we’re meeting all of Drata’s security and compliance mandates. Serve as the driving force behind rigorous standards and the catalyst for continuous improvement, maintaining a culture of excellence. 
  • Inspire Customer Confidence:
    Solidify Drata’s reputation as a trusted partner by responding to customer inquiries—whether through our Trust Center, via questionnaires, or one-off diligence questions—and by working closely with internal and external assessors. Help ensure they receive – in a timely and responsive manner – the necessary artifacts and guidance to validate our comprehensive compliance posture.
  • Foster a Culture of Proactive GRC:
    Collaborate with organizational leaders on initiatives like policy management, risk management and mitigation, compliance, customer due diligence, vendor due diligence, privacy requests, and additional engagements. Leverage these insights to strengthen Drata’s GRC posture and maturity journey and promote an environment of innovative, forward-looking GRC and Trust Management.
  • Drive Clear, Strategic Communications:
    Lead cross-functional alignment by articulating the “why” behind controls, processes, and requirements. Provide executive-level insight into risks and state of compliance with controls to help ensure all stakeholders understand the strategic intent and can collaborate effectively toward shared goals. Inform management of changes and updates to key frameworks, requirements and regulations regarding compliance and security.
  • Establish Robust Standards, Supported by Repeatable Procedures:
    Create and maintain a comprehensive, business-aligned GRC Program and supporting documentation—from a well established and documented GRC program, policies, and procedures to compliance standards—that resonates with auditors, customers, and internal teams, ensuring clarity and accountab

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Drata

View company profile →