About the job
Global Manager of InfoSec Governance, Risk, and Compliance
(San Francisco Bay Area, California, United States)
Founded in 2000, Ivalua is a prominent global provider of cloud-based procurement solutions.
COMPANY OVERVIEW
At Ivalua, we are a dynamic community of outstanding professionals who believe that digital transformation can revolutionize supply chain sustainability and resilience, unlocking the potential of supplier collaboration.
Through our leading cloud-based spend management platform, we empower numerous renowned brands to effectively oversee all categories of spending and supplier relationships. This increases profitability, enhances ESG (environmental, social, and corporate governance) performance, mitigates risks, and boosts productivity. Driven by our passions and shared ambitions, we empower and challenge one another to create impactful experiences for our colleagues, customers, partners, and communities.
Visit us at www.ivalua.com. Connect with us on LinkedIn and Twitter.
THE OPPORTUNITY
CONTEXT:
Our InfoSec team is committed to the establishment, maintenance, and continuous enhancement of Ivalua’s global Information Security program. We provide assurance and peace of mind regarding protection and safety for our customers. In this rapidly evolving environment, the GRC program is vital for ensuring compliance with industry standards and certifications, managing risks, and supporting business growth.
ROLE:
We are in search of an experienced InfoSec Governance, Risk, and Compliance (GRC) Manager to lead our global team and oversee the GRC program worldwide. Reporting directly to the InfoSec leadership, you will be responsible for managing and nurturing a high-performing team, driving compliance initiatives, and acting as a subject matter expert on security frameworks and standards.
WHAT YOU WILL DO WITH US
- Lead and manage the Governance, Risk, and Compliance (GRC) program globally, while developing a high-performing team.
- Oversee compliance efforts and audits for certifications such as FedRAMP, IRAP, ISO 27001, HIPAA, SOC1/SOC2, PCI DSS, and others.
- Act as the subject matter expert (SME) on security frameworks and standards.

