Astra
GRC Program Manager
Remote - US Only
Sponsorship not specifiedDetected 109 days ago
Cloud PlatformsCybersecurityComplianceProject ManagementSalesLeadershipCommunicationCollaborationOrganizational Skills
About the role
- Because this is an early hire on the compliance team, you'll have direct input into how Astra structures its audit programs, risk management processes, vendor due diligence workflows, and compliance tooling.
Responsibilities
- Audit Execution & Readiness: Own day-to-day execution of SOC 1, SOC 2, PCI DSS, and ISO 27001 readiness and audit cycles - including scoping, control testing, evidence collection, auditor coordination, and remediation tracking.
- Control Design & Documentation: Develop and maintain policies, procedures, risk assessments, control narratives, and supporting documentation that meet auditor expectations and scale with the business.
- Risk Management: Facilitate risk assessments for systems, vendors, products, and business initiatives. Maintain risk registers, mitigation plans, and executive reporting on residual risk.
- Engineering Partnership: Partner with engineering and infrastructure teams to translate security requirements into practical technical controls across cloud infrastructure, SDLC, access management, logging, monitoring, and incident response.
- Vendor Risk Management: Manage vendor security reviews, questionnaires, evidence validation, risk scoring, and ongoing monitoring for critical third parties and partners.
- Customer Trust & Due Diligence: Support customer security reviews, security questionnaires, and trust documentation that enable enterprise sales and bank partnerships.
- Continuous Compliance: Help build scalable compliance workflows, tooling, and automation to reduce manual effort and improve evidence quality as Astra grows.
- driving SOC 1, SOC 2, PCI DSS, and ISO 27001 programs end-to-end, translating regulatory requirements into practical technical controls, building high-quality documentation and evidence, and helping teams embed security and compliance into everyday operations.
- Small team, big impact - your work directly supports Astra's ability to scale responsibly
- Mission-driven - build infrastructure that powers financial innovation while meeting the highest regulatory standards
Requirements
- 3-6+ years of experience in governance, risk, compliance, audit, or information security rolls.
- Strong working knowledge of compliance frameworks (SOC, ISO 27001, NIST CSF, PCI DSS) and how controls operate in practice.
- Experience working cross-functionally with engineering, product, and operations teams in a technical environment.
- Comfort operating in fast-moving environments where priorities evolve and ambiguity is common.
- Bachelor's degree in Information Systems, Computer Science, Business, Risk Management, or related field (or equivalent practical experience).
- Ability to translate regulatory requirements into clear, testable, and scalable controls.
- Strong ability to produce clear policies, procedures, narratives, and evidence artifacts.
Nice to have
- experience with PCI DSS and ISO 27001 is strongly preferred.
- Hands-on experience supporting or leading SOC 1 and/or SOC 2 audits
Skills
- Audit Operations: Scoping, walkthroughs, evidence management, remediation tracking, auditor coordination.
- Risk Assessment: Experience performing system, vendor, and operational risk assessments with structured methodologies.
- Documentation & Writing: Strong ability to produce clear policies, procedures, narratives, and evidence artifacts.
- Operational Rigor: Highly organized with strong attention to detail and follow-through.
- As a GRC Program Manager, your work will directly:
- Enable Astra to scale responsibly while maintaining strong audit outcomes and regulatory credibility.
- Trust is foundational to everything Astra builds.
- Improve operational maturity through automation, documentation quality, and continuous improvement.
- Working understanding of cloud infrastructure, identity and access management, logging, monitoring, SDLC, and security tooling.
Compensation
- Our platform processes billions in annual transaction volume with 99.9%+ uptime, powering real-time transfers, bank debits, card disbursements, and complex financial compliance systems.
Benefits
- Competitive compensation with equity in a growing fintech company.
- Maintain dashboards and reporting on audit status, control health, remediation progress, and risk posture for leadership.
- Remote-first culture with flexible working arrangements
Company info
- Our customers, bank partners, and regulators depend on the strength of our control environment, operational discipline, and risk management practices.
Equal opportunity
- equal opportunity employer and are committed to building a diverse and inclusive team.
This listing is sourced directly from Astra's careers page and normalized into a canonical job model.