This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Monte Carlo is seeking our first Global GRC Manager to lead our compliance efforts in a cloud-first environment. You’ll be instrumental in driving our governance, risk, and compliance initiatives and ensuring we continue to meet our customer, industry, and regulatory requirements. In this role, you will engage with customers, vendors, and internal stakeholders to oversee a wide array of compliance activities and security reviews. Although this is an individual contributor position, you will serve as a lead in your domain, leveraging your expertise to collaborate across the organization and drive critical initiatives.
Job Responsibility:
Manage and respond to customer security reviews, questionnaires, and audits
Serve as the primary liaison for security-related inquiries from prospects, customers, and partners
Oversee ongoing compliance initiatives (SOC 2, ISO 27001, 27017, 27018, GDPR etc.) and maintain the risk register
Collaborate with cross-functional teams (Engineering, Sales, Product, HR) on risk management strategies
Evaluate third-party vendors, manage due diligence processes, and coordinate remediation actions
Develop, refine, and maintain security and compliance policies, procedures, and standards
Support and promote security awareness initiatives, including employee training and phishing simulations
Lead and coordinate internal and external audits, ensuring continuous improvement in controls
Requirements:
Deep GRC Expertise: extensive knowledge of common frameworks (SOC 2, ISO 27001, NIST, GDPR, etc.) and experience managing end-to-end audit processes
Strong Communication Skills: translate security jargon into business language and effectively manage customer and vendor communications
Risk Management Mindset: balance business objectives with security requirements, prioritizing risk mitigation in a way that aligns with company goals
Team Player: thrive in cross-functional environments, effectively collaborating with engineering, legal, product, and other teams
Adaptability: flourish in a fast-paced environment, pivoting quickly when new threats, requirements, or business needs emerge
5+ years of experience in a GRC or compliance-focused role, ideally in a SaaS or technology company
Proven track record of managing third-party risk assessments, vendor security reviews, and compliance audits
Expertise in compliance frameworks such as SOC 1/2, ISO 27001| 27017 | 27018 | 27701 | 42001, and GDPR
Relevant certifications (e.g., CISA, CISSP, CRISC, or CISM) are highly desirable
Excellent written and verbal communication skills with a strong attention to detail
Bachelor’s degree in Information Security, Cybersecurity, or a related field (or equivalent experience)