Accela
Manager, Governance, Risk & Compliance
Remote Based - US · Full-time
Sponsorship not specified$53k-$800kDetected 8 days ago
CybersecurityIncident ResponseComplianceProject ManagementSupply ChainHIPAACommunicationCISSP
About the role
- Coordinate audit evidence collection, control testing, remediation tracking, auditor communication, and management responses.
Responsibilities
- Lead the governance, risk, and compliance function across security policies, standards, risk management, audits, third-party risk, and control operations.
- Develop, maintain, and operationalize global security policies, standards, procedures, control documentation, and exception processes.
- Lead GovRAMP and PCI DSS readiness, including control mapping, evidence collection, remediation tracking, stakeholder coordination, audit preparation, and audit support.
- Maintain the security risk register, including identification, assessment, ownership, remediation, acceptance, exception tracking, and executive reporting of security risks.
- Partner with control owners across Security, IT, Engineering, Legal, HR, Finance, Product, and Operations to ensure control effectiveness and accountability.
- Manage third-party and supply chain risk management, including vendor security reviews, due diligence, risk assessments, contract security input, and remediation tracking.
- Support customer security reviews, questionnaires, trust center content, security documentation, and customer-facing compliance responses.
- Support incident response and privacy incident processes by ensuring regulatory, contractual, audit, and customer notification obligations are understood and tracked.
- Drive continuous improvement of the GRC operating model, including automation, evidence reuse, control rationalization, risk prioritization, and policy lifecycle management.
- Own audit readiness and ongoing compliance programs across frameworks such as SOC 2, ISO 27001, GovRAMP, PCI DSS, HIPAA, NIST CSF, NIST 800-53, CCPA/GDPR, and other customer or regulatory requirements.
Requirements
- 6+ years of experience in security governance, risk management, compliance, audit, third-party risk, or related cybersecurity roles.
- Experience managing or supporting audits and compliance programs for SOC 2, ISO 27001, GovRAMP, PCI DSS, HIPAA, NIST 800-53, or similar frameworks.
- Strong understanding of security controls, policy management, risk assessment, control testing, evidence collection, and audit readiness practices.
- Experience managing third-party risk or vendor security review programs.
- Ability to translate complex compliance obligations into practical business and technical requirements.
- Experience in SaaS, cloud, public-sector technology, government technology, or regulated environments.
- Experience with GovRAMP, FedRAMP Moderate or High, PCI DSS, NIST 800-53, or other public-sector and payment security compliance frameworks.
- Experience with GRC platforms, trust centers, vendor risk platforms, policy management platforms, or control automation tools.
- Experience supporting privacy programs involving CCPA, GDPR, HIPAA, or similar requirements.
- For nearly 20 years, Accela has been an industry leader in designing and delivering government software to improve efficiency, increase citizen engagement and enable the development of thriving communities.
- Experience developing executive-level risk and compliance reporting.
- Relevant certifications such as CISSP, CISM, CISA, CRISC, ISO 27001 Lead Implementer, or ISO 27001 Lead Auditor.
- May support incident response activities related to evidence preservation, notification obligations, contractual obligations, and control impact analysis.
- Very light travel may be expected for team or company offsites and industry conferences.
Compensation
- The annual base salary range for this full-time position is $150,000-$170,000(less applicable taxes).
- The actual annual base salary offered may be adjusted based on a variety of factors, including but not limited to, location, education, skills, training, and experience.
- In addition to an annual base salary, this position is eligible for an annual bonus target.
Benefits
- Our open and flexible technology helps agencies address specific needs today, while ensuring they are well prepared for the emerging challenges of the future.
- Accela is committed to putting resources and attention towards evolving our practices, policies, and philosophies to enable diversity to thrive and to support equity in opportunity for everyone.
- Develop metrics and dashboards for audit status, control health, risk posture, vendor risk, policy exceptions, compliance readiness, and remediation progress.
- This is a discretionary bonus awarded based on company and individual goal achievement.
Company info
- Partner with the CISO to communicate security posture, compliance progress, key risks, control gaps, and trade-offs to executives, customers, auditors, and regulators.
- While government agencies struggle to do more with less, our mission has never been more critical.
Equal opportunity
- Accela is an Equal Opportunity Employer/Affirmative Action Employer and will respond to requests for job accommodations.
- All qualified applicants will receive consideration for employment without regard to race, sex, color, religion, national origin, protected veteran status, or based on disability, gender identity, and sexual orientation
Visa & Work Authorization
- ars, Accela has been an industry leader in designing and delivering government software to improve efficiency, increase citizen engagement and enable the development of thriving communities
This listing is sourced directly from Accela's careers page and normalized into a canonical job model.