Jobs and Careers
EM

Manager, Security Governance & Risk

Emburse
United Statesfull_timeVerifiedPosted 12 Aug 2026

About the role

Who We Are:
 
At Emburse, you’ll not just imagine the future – you’ll build it. As a leader in expense intelligence, we are creating a future where technology drives business value and inspires extraordinary results. Our AI-powered platform helps organizations modernize financial operations, increase visibility, and optimize spend across the enterprise.

The Manager, Security Governance & Risk leads Emburse's security governance, risk, and compliance function, with primary focus on enterprise security risk management, security metrics and reporting, and AI governance across both Emburse's AI-enabled products and internal AI use. This is a people-leadership role: the Manager leads a team of GRC professionals who independently manage day-to-day audit execution while the Manager owns the GRC operating model and platform strategy, governance, configuration standards, data integrity, automation, and reporting. This structure allows the Manager to focus on maturing how Emburse identifies, measures, and communicates security risk while maintaining accountability for the quality and effectiveness of the broader GRC program. The ideal candidate pairs credible GRC depth with genuine analytical rigor: someone who can turn control and risk data into decision-ready reporting for executives and the Board, establish governance for a fast-moving AI landscape, and grow the people on their team while doing it.

 

What you will do :

    Essential Functions

  • Lead, coach, and develop a team of GRC professionals by setting objectives, managing performance, and building career paths that deepen expertise across audit, privacy, and risk.

  • Own Emburse's GRC platform, including platform strategy, control architecture, integrations, data quality, automation, reporting, and continuous-control-monitoring maturity; delegate day-to-day platform administration and evidence operations to the team as appropriate.

  • Provide management oversight and quality assurance for security and compliance audits while delegating day-to-day audit planning, evidence coordination, auditor interaction, and execution; intervene directly on material findings, scope disputes, control deficiencies, or issues requiring management judgment.

  • Own the enterprise information security risk management program end to end, covering risk identification, assessment methodology, risk register maintenance, treatment planning, and tracking remediation to closure.

  • Continuously mature the risk program by improving the consistency, defensibility, and trend analysis behind how risk is scored and communicated, moving the organization beyond static point-in-time heat maps.

  • Own the Third-Party Risk Management program end to end, including vendor risk tiering, assessment methodology, due diligence standards, contractual security requirements, ongoing monitoring, and reassessment cadence, with ICs executing day-to-day vendor reviews and assessments against the standards and thresholds this role sets.

  • Build and own the security metrics and reporting framework, defining key risk and performance indicators, establishing authoritative data sources, and automating collection so reporting is repeatable rather than reassembled by hand each cycle.

  • Establish and lead Emburse's AI governance program, covering both AI capabilities within Emburse products and internal employee and vendor use of AI tools.

  • Track the evolving AI regulatory and framework landscape (e.g., EU AI Act, NIST AI RMF, ISO/IEC 42001, emerging state legislation) and translate obligations into concrete control and process requirements.

  • Own the security policy and standards lifecycle, ensuring alignment with industry frameworks (NIST, ISO 27001, PCI DSS, SOC 2) and keeping policies current, accessible, and enforceable.

  • Provide oversight of privacy program operations delivered by the team, ensuring obligations under GDPR, PIPEDA, CCPA/CPRA, and comparable regimes are met.

  • Partner with Engineering and Product on remediation of application and infrastructure security risk surfaced through risk assessments, penetration tests, and audit findings.

  • Sponsor continuous controls monitoring and automation initiatives that reduce manual evidence collection burden on the team and shorten audit cycles.

  •  

    Education and Experience

    Education:

  • Required:  Bachelor’s Degree; minimum 7+ years of information security, risk, or compliance experience, including 2+ years directly managing people or demonstrated equivalent team leadership (owning workstreams, mentoring, and developing others).

  •  

    Ex

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Emburse

View company profile →