Mediabistro logo
job logo

Manager, InfoSec Governance Risk and Compliance (GRC) New York City, New York, U

Ivalua, New York, NY, United States


Manager, InfoSec Governance Risk and Compliance (GRC)
New York City, New York, US

Manager, InfoSec Governance Risk and Compliance (GRC)

(New York City, New York, United States)

Founded in 2000, Ivalua is a leading global provider of cloud-based procurement solutions.

COMPANY OVERVIEW
At Ivalua we are a global community of exceptional professionals who believe that digital transformation revolutionizes supply chain sustainability and resiliency to unlock the power of supplier collaboration.

We achieve this through our leading cloud-based spend management platform that empowers hundreds of the world's most admired brands to effectively manage all categories of spend and all suppliers to increase profitability, improve ESG (environmental, social, and corporate governance) performance, lower risk, and improve productivity. Driven by our passions and fueled by our shared ambitions, we empower and challenge each other to create meaningful experiences for our colleagues, customers, partners, and communities.

Our InfoSec team is dedicated to building, maintaining, and continuously improving Ivalua’s Information Security program globally. We provide peace of mind and assurance of protection and safety to our customers. In this fast‑growing environment, the GRC program is critical to ensuring compliance with industry standards and certifications, managing risks, and supporting business growth.

ROLE:
We are currently looking for an experienced InfoSec Governance Risk and Compliance (GRC) Manager to lead a global team and own the GRC program worldwide. Reporting to the InfoSec leadership, you will manage and develop a high‑performing team, drive compliance efforts, and serve as a subject matter expert on security frameworks and standards.

WHAT YOU WILL DO WITH US

Lead and own the Governance, Risk, and Compliance (GRC) program globally, managing and developing a high‑performing team.

Manage and drive compliance efforts and audits for certifications such as FedRAMP, IRAP, ISO 27001, HIPAA, SOC1/SOC2, PCI DSS, and others.

Serve as the subject matter expert (SME) on security frameworks and standards including NIST SP 800-53 Rev 5, NIST 800-171, ITAR, FedRAMP, PCI DSS, SOC2, etc., providing guidance to internal stakeholders.

Efficiently manage and respond to customer security audit and compliance requests in a timely manner.

Maintain continuous compliance and monitoring of security controls to ensure ongoing adherence to standards.

Collaborate closely with Sales, Marketing, and Customer Success teams to effectively communicate Ivalua’s security posture to prospects and customers.

Review and negotiate information security exhibits and contractual terms in partnership with the legal team.

Lead the Security Awareness and Training program to promote a culture of security across the organization.

Track, manage, and drive remediation efforts for control deficiencies and gaps identified through internal and external audits.

Oversee the Third Party Risk and Vendor Security Assessment program to mitigate supply chain risks.

Develop, maintain, and enforce InfoSec policies, standards, and plans.

YOUR PROFILE
If you have the below experience and strengths this role could be for you:

Skills and Experience:

At least 7+ years of proven experience leading GRC programs and managing compliance certifications and audits (FedRAMP, ISO 27001, HIPAA, SOC1/SOC2, PCI DSS, IRAP, etc.).

At least 3+ years experience as a direct leader, managing a team. The position will be part of an established global team with opportunity to grow the team.

Strong knowledge of security frameworks such as NIST SP 800-53, NIST 800-171, ITAR, PCI DSS, SOC2, and FedRAMP.

Demonstrated ability to manage and influence stakeholders across multiple departments and time zones.

Excellent project management, analytical, and problem‑solving skills with keen attention to detail.

Strong interpersonal and communication skills, capable of building trust and managing conflicts effectively.

Self‑motivated with a high degree of initiative and ability to work independently.

Ability to handle multiple competing priorities and deadlines efficiently.

Bachelor’s degree in related field preferred or equivalent experience with proven skills.

Soft Skills:

Excellent interpersonal, communication, and organizational skills.

Team player with the ability to interface effectively with a broad range of individuals and roles, including IT and vendors.

High degree of initiative, dependable, and able to work well with limited supervision.

WHAT HAPPENS NEXT
If your application fits this specific position’s needs, our skilled Talent team will reach out to schedule an initial screening call. Get one step closer to achieving your goals – apply today!

Our Talent team will guide you through every step of the interview process - from preparation to completion. They're here to support you!

Our recruitment process is designed to assess your competencies through a series of personalized interviews with internal stakeholders relevant to the role.

Interviews will be conducted virtually via video or on-site with face‑to‑face meetings.

LIFE AT IVALUA

Hybrid working model (3 days in the office per week)

We're a team dedicated to pushing the boundaries of product innovation and technology

Sustainable Growth, Privately Held

A stable and cash‑flow positive Company since 10 years

Snacks and weekly lunches in the office

Feel empowered to pursue your goals with improved team collaboration and increased creativity/productivity

Unlock and unleash your full professional potential with our exceptional training and career development program

Join a dynamic and international team of top‑notch professionals who are experts in their respective fields. Collaborate with like‑minded individuals who are deeply passionate and highly motivated about their work. Experience a truly diverse and inclusive work environment where your unique contributions are highly valued

Regular social events, competitive outings, team running events, and musical activities

United by our values we embrace diversity and equity in the broadest possible sense to create an inclusive workplace. We believe in equal opportunity and in diversity as a driver of innovation that cultivates a spirit of inclusiveness, creates a productive and fun place to work, and provides fulfilling career opportunities for all Ivaluans.

Experience life at Ivalua – check out our captivating video! Gain insight into our unique company culture and get a glimpse of what it’s like to work with us.

Ivalua’s core values include a priority on Care & Grow People. We take matters like pay equity very seriously and strive to reward our employees appropriately and fairly for their talents.

The compensation range for this position reflects the cost of labor across our US locations and is based upon careful and continual market research. In addition to location, compensation may also vary based on job‑related knowledge, skills, and experience.

Title: Manager, InfoSec Governance Risk and Compliance (GRC)

Range minimum: USD 112,000

Range maximum: USD 208,000

Additional compensation / rewards: Ivalua also offers exceptional benefits including medical, dental, vision and transportation.

#LI-SG1

#LI-HYBRID

Interested in building your career at Ivalua? Get future opportunities sent straight to your email.

Voluntary Self-Identification
For government reporting purposes, we ask candidates to respond to the below self‑identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Ivalua’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service‑connected disability.

A "recently separated veteran" means any veteran during the three‑year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Voluntary Self-Identification of Disability
Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form? We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp .

How do you know if you have a disability? A disability is a condition that substantially limits one or more of your "major life activities." If you have or have ever had such a condition, you are a person with a disability.

Disabilities include, but are not limited to:

Alcohol or other substance use disorder (not currently using drugs illegally)

Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS

Blind or low vision

Cancer (past or present)

Cardiovascular or heart disease

Celiac disease

Cerebral palsy

Deaf or serious difficulty hearing

Diabetes

Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders

Epilepsy or other seizure disorder

Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome

Intellectual or developmental disability

Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD

Missing limbs or partially missing limbs

Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports

Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)

Neurodivergence, for example, attention‑deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities

Partial or complete paralysis (any cause)

Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema

Short stature (dwarfism)

Traumatic brain injury

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.

#J-18808-Ljbffr