SlipstreamJobsFresh Startup & VC-Backed Jobs

GRC Manager

Valence - Remote - Remote - posted 2026-07-25

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Valence is an AI-native coaching platform for enterprise leadership development, working with Fortune 500 companies across healthcare, financial services, manufacturing, and technology. The company is building the operational and governance infrastructure to scale AI-powered personalized coaching at enterprise scale. As GRC Manager, you will own the day-to-day operation of Valence's Governance, Risk & Compliance program. This is a highly cross-functional role requiring strong organizational skills, communication, and the ability to influence without direct authority. Key responsibilities include: - Maintain and continuously improve the Information Security and AI Management System for ISO 27001/42001 compliance - Coordinate SOC 2, ISO 27001, ISO 42001, and other certification efforts - Manage the security risk register and facilitate enterprise risk assessments - Coordinate internal and external audits - Manage security policies, standards, and control documentation - Track remediation activities and drive control improvements across Engineering, Product, IT, Sales, and Operations teams - Support customer security questionnaires, RFPs, and due diligence activities - Partner with Engineering to ensure technical controls meet compliance requirements - Develop security metrics and executive reporting - Coordinate annual control testing and evidence collection - Build scalable governance processes as the company grows You should have experience managing GRC or security compliance programs, strong understanding of SOC 2, ISO 27001, NIST CSF, and ISO 42001 frameworks, and experience with risk management methodologies. Experience coordinating internal and external audits, working cross-functionally with Engineering, IT, Legal, and Privacy teams is essential. Familiarity with GRC platforms (Vanta, Drata, Secureframe, OneTrust, Archer) is a plus. Knowledge of cloud security (AWS/Azure), privacy regulations (GDPR), and AI governance including the EU AI Act is valued. A desire to automate GRC tasks using AI aligns with the company's mission.

Similar roles