Manager, Technology Governance, Risk and Compliance
ShipBobAbout the role
As a member of the ShipBob Team, you will benefit from an environment where everything is achievable. We aim to be a place where you can:
- Write Your Career Story. Because we are solving some of the most difficult problems in global commerce, you have the opportunity to write the story that will make your career.
- Experience Global Impact and Global Connection. At ShipBob we benefit from diverse cultures and perspectives in service of the global community.
- Grow With An Ownership Mindset. We believe that great innovation comes from great transparency. We are more resilient and more creative when we have an inclusive and transparent culture where everyone knows our strengths and opportunities.
Title: Manager, Tech Governance, Risk, & Compliance
Location: Remote in these states: AZ, CA, CO, FL, GA, KS, KY, IA, ID, IL, IN, MA, ME, MI, MN, MO, NC, NH, NJ, NV, NY, OH, OR, PA, RI, SC, SD, TN, TX, VA, VT, WA, WI
Role Description:
The Manager, Tech GRC will be responsible for managing and scaling programs and developing solutions that help ShipBob evaluate, measure, monitor and report on the state of information management and third-party information security risk. This role will partner with key stakeholders such as Legal/Privacy, Procurement and SFN management to ensure information security risks are accurately assessed and contract language appropriately protects ShipBob from information security risks posed by third-party entities. This role will also work with key functional leaders across the enterprise to understand and document information management at ShipBob including as data creation, classification, protection, transmission and retention. This position will report directly to the Director, Tech Governance Risk and Compliance.
The opportunities for you to solve:
Management
- Manage assessment intake and oversight to ensure pipeline of assessments is managed in a timely and efficient manner.
- Contribute to the team’s continuous improvement efforts by identifying opportunities and owning the development and implementation.
- Develop and mature processes for Information Management and Third-Party Risk Management based on industry best practices/generally accepted frameworks/standards.
- As the team grows, oversee day-to-day activities of junior team members and consultants.
Risk Assessments and Analysis
- Work with business to understand the “what” and “how” of third-party entities/services to accurately categorize, assess level of risk, and scope of assessment. Third parties include ShipBob Partners and entities providing third party services to ShipBob.
- Document data flow and classification of data being shared with third party entities/services.
- With Legal, identify data retention requirements and ensure appropriate backup obligations are agreed to with third party entities.
- Perform timely assessments of third-party controls to identify, document, and communicate key deficiencies to the business and Information Security management.
- Coordinate with Information Security Engineers to incorporate technical reviews into overall assessment (as needed).
- Coordinate with Legal to incorporate Privacy reviews into overall assessment (as needed).
- Report on assessment outcomes, risk level, and associated recommendations to remediate issues.
- Support periodic re-assessment activities to ensure third-party adherence to security requirements and to assess evolving risks and current threats.
Findings Management, Reporting and Analytics
- Monitor third-party corrective action plans against agreed upon timelines.
- Review third-party remediation evidence for closure of findings.
- Monitor the effectiveness of the third-party risk assessment process in accordance with agreed metrics and performance measures to drive continuous improvements.
- Assist with development and reporting of Key Performance Indicator metrics.
- Maintain timely, accurate, and complete third-party inventory and data within the identified system of record.
- With Procurement, track and monitor annual spend with third-party vendors to manage budget, identify areas for cost savings and reduce duplication of investment.
Contract Review
- Working with Procurement and Legal, review contracts to ensure appropriate data security terms are included to protect ShipBob from data and content security risks.
- Provide comments and acceptable alternatives to vendor contract revisions, in alignment with defined guidance.
- Stay abreast of existing and upcoming regulatory
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s