SlipstreamJobsFresh Startup & VC-Backed Jobs

GRC Manager

G2 - Chicago, IL, United States - In-office - posted 2026-09-22

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

G2 is the world's largest software marketplace, recently merged with Capterra, SoftwareAdvice, and GetApp to create the largest source of online B2B software data and insights. The company serves 200M+ annual visitors and hosts 6M verified reviews, positioning itself as the trusted data foundation for software buyers and sellers in the age of AI. The GRC Manager is a senior individual-contributor role responsible for owning G2's day-to-day security compliance and risk program. This is a high-volume operation managing customer security questionnaires, vendor risk reviews, policy governance, DSAR processing, audit management, and risk register maintenance. The role requires judgment to prioritize competing demands, process discipline to scale growing workload, and maturity to represent G2 to customers, auditors, and executive stakeholders. Key responsibilities include: - Administering G2's security policy library (35+ documents), leading annual review cycles and managing approvals - Leading response to customer and prospect security questionnaires from short-form intake to 100+ question enterprise reviews - Owning G2's public Trust Center and serving as front-line representative on security and compliance matters - Running the third-party/vendor risk management program, reviewing AI-assisted assessments and driving remediation - Managing DSAR intake and fulfillment within regulatory timelines - Supporting security addendum and contract redlines in partnership with Legal - Maintaining and maturing enterprise risk registers across business functions - Leading SOC 2 Type II and ISO 27001 audit cycles end-to-end as primary auditor contact - Managing GRC tooling and vendor ecosystem including contract renewals and budget oversight - Building executive-level dashboards and reporting on program health, audit status, and risk posture - Advising internal teams on corrective action plans following audit findings or compliance incidents - Partnering cross-functionally as connective tissue between business goals and compliance requirements - Identifying process and automation opportunities to relieve bottlenecks Success depends on ability to work as trusted partner across Legal, Security Engineering, IT, Sales, and executive leadership. The ideal candidate has run a GRC program at this scale before, is comfortable with modern compliance tooling (e.g., Vanta), fluent in SOC 2 Type II and ISO 27001, and experienced translating technical risk into business language. QUALIFICATIONS: - 7–10 years of progressive experience in IT Governance, Risk, and Compliance or information security, including direct ownership of a compliance program - Deep working knowledge of SOC 2 Type II, ISO 27001, NIST CSF, and common SaaS/cloud security and privacy frameworks (PCI DSS, GDPR, CCPA) - Hands-on experience with modern GRC/compliance automation platform (Vanta, Drata, OneTrust, or similar) to manage controls, evidence, and risk at scale - Proven experience managing high-volume customer security questionnaires and knowledge-library programs, including large enterprise reviews - Experience running third-party/vendor risk management program, including risk scoring and remediation tracking - Experience managing DSAR or other privacy request workflows in line with regulatory timelines - Track record serving as primary point of contact for external auditors through full audit cycles, with strong control-testing and remediation experience - Excellent written and verbal communication skills, including experience presenting risk and compliance status to executive stakeholders and customers - Strong prioritization and program-management skills to manage high-volume, multi-workstream caseload independently as senior individual contributor - Demonstrated ability to influence and align cross-functional partners without formal authority PLUS (not required): - CISSP, CRISC, CISM, or CISA certification - Experience leading organization through initial ISO 27001 certification or comparable new-framework rollout - Familiarity with procurement-to-GRC integrations and automating vendor intake - Working knowledge of global privacy regulations and experience partnering with Legal on data protection - Experience managing GRC program budget and vendor/contract relationships - Track record as senior individual contributor driving outcomes through influence and cross-functional partnership

Similar roles