Manager, Information Security GRC
Atlanta, GA, United States
OneTrust is the trust intelligence cloud platform organizations use to transform trust from an abstract concept into a measurable competitive advantage. Organizations globally use OneTrust to enable the responsible use of data while protecting the privacy rights of individuals, implement and report on their cyber security program, make their social impact goals a reality, and create a speak up culture of trust. Over 14,000 customers use OneTrust's technology, including half of the Global 2,000. OneTrust currently ranks #24 on the Forbes Cloud 100 list of top private cloud companies in the world and employs over 2,000 people in regions across North America, South America, Asia, Europe, and Australia.
The Challenge
We are looking for a
dynamic Information
Security GRC Manager to support IT and InfoSec by performing various governance, risk, and compliance activities as part of
the OneTrust InfoSec
GRC team, including Audits (internal and external), Policies (standards, procedures, SOPs), etc.
This role is critical to support OnePlan of maturing security processes and posture at OneTrust within the information security GRC domain.
Your Mission
Manage a team of GRC professionals in their daily activities
Collaborate with IT, InfoSec, and within the GRC team to mature the compliance process
Follow our ongoing risk and control self-assessment, audit management processes
Facilitate and manage multiple audits simultaneously
Manage policy and SOP requests and updates with key stakeholders
Become a trusted advisor to IT, InfoSec, and the business
You Are
A trusted advisor to IT, InfoSec, and the business
A Relationship builder: Ability to listen, build rapport, and credibility as a strategic partner vertically and horizontally
An Innovator: Possess the ability to seek alternatives and recommend best solutions that gain all parties support and lead to win-win results
Value Driven: You are detail oriented with an eye for quality
Ability to work with minimal
oversight
Ability to execute given high level direction
Asks good questions and always learning
Planning, supporting, and or executing audits (customer-driven, internal, external)
Understanding of applicable laws and regulations and security standards and frameworks including but not limited to, ISO 27001, 27017, 27701, SOC 2, PCI-DSS, HITRUST, etc.
Extra Awesome
3+ years’ experience as people manager
3+ years' experience in audit management
3+ years' experience policy management
3+ years’ experience in DR/BCP
>1 Certifications such as CISA (Certified Information Systems Auditor), CISSP, CISM, CRISC, etc.
For California, Colorado, Connecticut, Nevada, New York, Rhode Island, and Washington-based candidates: the annual base pay range for this role is listed below. Within this range, individual pay is determined by several factors, including location, job-related skills, work experience, and relevant education and/or training. This role may also be eligible for discretionary bonuses, equity, and/or commissions, as well as benefits.
Salary Range
$127,500
—
$191,250 USD
Where we Work
OneTrust embraces a hybrid working model. Our
Working@
OneTrust
initiative
is
our way of clarifying where we hire, how we work together, and where we’re located in that hybrid model.
The underlying “why” for Working@ is that we are intentional about the culture that we want to create together. That includes bringing teams together, in-person, throughout the year to collaborate, build connections, learn from each other, and celebrate our wins to
Finish Stronger .
We are committed to a
flexible
approach informed by a set of guiding principles. You’ll see that reflected in our worker designations: “Office-flex” and “Location-flex”.
Office-flex:
Like a traditional hybrid model,
OneTrust
“Office-flex” employees may be asked to
work in an office periodically if they are within a commutable distance to a
OneTrust
office.
This includes coming into the office for our Company Kickoff, Company All Hands, and other larger company events.
Beyond that, we give our leaders and teams the flexibility to set
additional
guidelines
based on
the nature of
your role.
Location-flex:
Similar to
other companies’ remote policies,
for
OneTrust
“Location-flex" roles
, you will primarily work from your home office location. However, you may
be
require
d
to
travel to
our
OneTrust
office
s or customer sites periodically based on
the nature
of your role.
Each
role may have specific
requirements
, so we encourage you to verify the location
of the role with your recruiter during your first interview.
As an employee at
OneTrust
, you will be part of the
OneTeam
. That means
you’ll
receive support physically, mentally, and emotionally so that you can do your best work both in and out of the office. This includes comprehensive healthcare coverage, flexible PTO, equity stock options, annual performance bonus opportunities, retirement account support, 14+ weeks of paid parental leave, career development opportunities, company-paid privacy certification exam fees, and much more. Specific benefits differ by country. For more information, talk to your recruiter or visit onetrust.com/careers.
Resources
Check out the following to learn more about OneTrust and its people:
You have the right to have your personal data updated or removed. You also have the right to have a copy of the information OneTrust holds about you. Further details about these rights are available on the website in our Privacy Overview
.
You can change your mind at any time and have your personal data removed from our database. In order to do this you must contact us and let us know you wish to be removed. The request should be made on the Data Subject Request Form .
Our Commitment to You
When you join OneTrust you are stepping onto a launching pad — the countdown has begun. The destination? A career without boundaries working alongside a diverse and inclusive crew who is passionate about doing meaningful work. As a pioneer, your voice and expertise will help chart the direction of an entirely new industry — Trust. Our commitment to putting people first starts with you. Your growth is part of the mission. Our goal is to give you the power to embark on the next phase of your uniquely, unique career
OneTrust provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by local laws.
Will you now or in the future require sponsorship for employment in the U.S.?
*
Are you legally authorized to work for any employer in the U.S.?
*
Data Protection Notice
*
Before you submit your application, please confirm that you have read and understood our Candidate Privacy Notice available
here
. In order to exercise your rights with respect to any Personal Information submitted as part of your application, please contact us using our
Data Subject Request Form
.
Voluntary Self-Identification
For government reporting purposes, we ask candidates to respond to the below self-identification survey.Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiringprocess or thereafter. Any information that you do provide will be recorded and maintained in aconfidential file.
As set forth in OneTrust’s Equal Employment Opportunity policy,we do not discriminate on the basis of any protected group status under any applicable law.
If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection.As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measurethe effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categoriesis as follows:
A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.
A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.
An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.
An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.
Voluntary Self-Identification of Disability
Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026
Voluntary Self-Identification
For government reporting purposes, we ask candidates to respond to the below self-identification survey.Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiringprocess or thereafter. Any information that you do provide will be recorded and maintained in aconfidential file.
As set forth in OneTrust’s Equal Employment Opportunity policy,we do not discriminate on the basis of any protected group status under any applicable law.
Gender
Are you Hispanic/Latino?
Race & Ethnicity Definitions
If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection.As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measurethe effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categoriesis as follows:
A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.
A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.
An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.
An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.
Veteran Status
Voluntary Self-Identification of Disability
Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026
Why are you being asked to complete this form?
We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.
Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp .
How do you know if you have a disability?
A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability.
Disabilities include, but are not limited to:
Alcohol or other substance use disorder (not currently using drugs illegally)
Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
Blind or low vision
Cancer (past or present)
Cardiovascular or heart disease
Celiac disease
Cerebral palsy
Deaf or serious difficulty hearing
Diabetes
Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
Epilepsy or other seizure disorder
Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
Intellectual or developmental disability
Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
Missing limbs or partially missing limbs
Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
Partial or complete paralysis (any cause)
Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
Short stature (dwarfism)
Traumatic brain injury
Disability Status
PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.
#J-18808-Ljbffr