G2 Logo

G2

GRC Manager

Posted 4 Days Ago
Be an Early Applicant
In-Office
Chicago, IL, USA
120K-131K Annually
Senior level
In-Office
Chicago, IL, USA
120K-131K Annually
Senior level
Own G2’s security governance, risk, and compliance program, including policy management, customer security questionnaires, Trust Center operations, vendor risk, DSAR workflows, risk registers, and SOC 2 and ISO 27001 audits. Manage GRC tools and vendors, coordinate with Legal, Security, IT, Sales, auditors, customers, and executives, and deliver risk reporting, remediation oversight, and process automation as a senior individual contributor.
The summary above was generated by AI

About G2 - The Company

G2 is the world's largest and most trusted software marketplace. When you join G2, you’re joining the industry’s leading team that helps businesses reach their peak potential by powering decisions and strategies with trusted insights from real software users.

Now, we have joined forces with Capterra, SoftwareAdvice, and GetApp to create the largest source of online data and software insights to fuel intelligent buying in the age of AI. With 200M+ combined annual visitors and 6M verified reviews, we are now the centralized place to enable software buyers to make better and faster decisions with confidence.

And we are just getting started! We are setting out to transform the global B2B software industry and become the most trusted data foundation for buyers and sellers of software for the age of AI.

Does that sound exciting to you? Come join us as we try to reach our next PEAK!

About G2 - Our People

At G2, everything we are and what we do is grounded in our PEAK values— (Performance + Entrepreneurship + Authenticity + Kindness. Working at G2 means you are part of a value-driven, growing global community that climbs PEAKs together. We cheer for each other’s successes, learn from our mistakes, and support and lean on one another during challenging times. With ambition and entrepreneurial spirit we push each other to take on challenging work, which will help us all to grow and learn.

You will be part of a global, diverse team of smart, dedicated, and kind individuals - each with unique talents, aspirations, and life experiences. At the heart of our community and culture are our people-led ERGs, which celebrate and highlight the diverse identities of our global team. As an organization, we are intentional about our DEI and philanthropic work (like our G2 Gives program) because it encourages us all to be better people.

About The Role

Summary of Responsibilities:

The Governance, Risk, and Compliance (GRC) Manager owns G2's day-to-day security compliance and risk program, and is the senior operator responsible for keeping our customer trust commitments, audit obligations, and risk posture on track. This role runs a high-volume operation: customer security questionnaires, vendor risk reviews, policy governance, DSAR processing, audit management, and risk register maintenance. This manager is expected to bring the judgment to prioritize competing demands, the process discipline to scale a growing workload, and the maturity to represent G2 directly to customers, auditors, and executive stakeholders.

This is a senior individual-contributor role. Success depends on the ability to work as a trusted partner across the business: Legal, Security Engineering, IT, Sales, and executive leadership all rely on this person to move their goals forward, whether that's closing a deal that's stuck on a security questionnaire, unblocking an audit finding, or getting a policy approved. The ideal candidate has run a GRC program at this scale before: comfortable working inside modern compliance tooling (e.g., Vanta), fluent in SOC 2 Type II and ISO 27001, and experienced translating technical risk into business language for both customers and leadership.

Detailed Responsibilities:

In this role, you will be responsible for the following:

  • Own and administer G2's security policy library (35+ documents), leading the annual review cycle, managing approvals, and ensuring no policy lapses past its renewal date.

  • Lead response to customer and prospect security questionnaires — from short-form intake to 100+ question enterprise reviews — and maintain the security knowledge library that powers fast, accurate answers at scale.

  • Own G2's public Trust Center and serve as the company's front-line representative to customers and partners on security and compliance matters.

  • Run the third-party/vendor risk management program, reviewing AI-assisted vendor risk assessments, making final risk-level determinations, and driving remediation of high-risk findings.

  • Manage data subject access request (DSAR) intake and fulfillment, ensuring requests are documented and resolved within regulatory timelines.

  • Support security addendum and contract redlines, partnering with Legal and counterparties through multiple negotiation rounds to close terms.

  • Maintain and mature enterprise risk registers across business functions, driving treatment plans, control linkage, and quarterly reassessment to closure.

  • Lead SOC 2 Type II and ISO 27001 audit cycles end-to-end — evidence collection, control testing, and serving as primary point of contact for auditors.

  • Manage the GRC tooling and vendor ecosystem (compliance platforms, audit firms, privacy tooling), including contract renewals and budget oversight.

  • Build and deliver executive-level dashboards and reporting on program health, audit status, and risk posture to leadership.

  • Advise internal teams on the effectiveness of corrective action plans following audit findings, control gaps, or compliance incidents.

  • Partner cross-functionally with Legal, Security Engineering, IT, Sales, and other business functions as the connective tissue between their goals and G2's compliance and risk requirements.

  • Identify where process or automation would relieve bottlenecks, and build the business case for that investment.

Qualifications:

  • 7–10 years of progressive experience in IT Governance, Risk, and Compliance or information security, including direct ownership of a compliance program.

  • Deep working knowledge of SOC 2 Type II, ISO 27001, NIST CSF, and common SaaS/cloud security and privacy frameworks (e.g., PCI DSS, GDPR, CCPA).

  • Hands-on experience with a modern GRC/compliance automation platform (e.g., Vanta, Drata, OneTrust, or similar) used to manage controls, evidence, and risk at scale.

  • Proven experience managing high-volume customer security questionnaires and knowledge-library programs, including large enterprise reviews.

  • Experience running a third-party/vendor risk management program, including risk scoring and remediation tracking.

  • Experience managing DSAR or other privacy request workflows in line with regulatory timelines.

  • Track record serving as primary point of contact for external auditors through full audit cycles, with strong control-testing and remediation experience.

  • Excellent written and verbal communication skills, including experience presenting risk and compliance status to executive stakeholders and customers.

  • Strong prioritization and program-management skills, with the ability to manage a high-volume, multi-workstream caseload independently as a senior individual contributor.

  • Demonstrated ability to influence and align cross-functional partners (Legal, Engineering, IT, Sales) without formal authority over their teams.

What Can Help Your Application Stand Out:

  • CISSP, CRISC, CISM, or CISA certification.

  • Experience leading an organization through initial ISO 27001 certification or a comparable new-framework rollout.

  • Familiarity with procurement-to-GRC integrations and automating vendor intake into a risk workflow.

  • Working knowledge of global privacy regulations (GDPR, CCPA, LGPD) and experience partnering with Legal on data protection matters.

  • Experience managing a GRC program budget and vendor/contract relationships (audit firms, tooling, advisory partners).

  • Track record operating as a senior individual contributor who drives outcomes through influence and cross-functional partnership rather than direct authority.

Our Commitment to Inclusivity and Diversity

At G2, we are committed to creating an inclusive and diverse environment where people of every background can thrive and feel welcome. We consider applicants without regard to race, color, creed, religion, national origin, genetic information, gender identity or expression, sexual orientation, pregnancy, age, or marital, veteran, or physical or mental disability status. Learn more about our commitments here. 

--


For job applicants in California, the United Kingdom, and the European Union, please review this applicant privacy notice before applying to this job.

How We Use AI Technology in Our Hiring Process
G2 incorporates AI-powered technology to enhance our candidate evaluation process. These tools may assist with initial application screening, skills assessment analysis, and identifying candidates whose qualifications align with specific role requirements. While AI technology supports our recruitment workflow, all final hiring decisions remain under human oversight and judgment.

Your Choice Matters: If you would prefer that your application be reviewed without AI assistance, you can opt out by entering your email address in the email entry field at the bottom of the Automated Processing Legal Notice. Choosing to opt out will not disadvantage your application in any way—we will ensure your materials receive a thorough manual review by our hiring team.
For additional details about how we handle your information throughout the application process, please review G2's Applicant Privacy Notice.

HQ

G2 Chicago, Illinois, USA Office

Our Chicago office serves as G2's global headquarters and is located in the heart of downtown. Our office is easily accessible by a number of public transportation options include the CTA, Metra, and bus. We're just minutes away from Chicago's most iconic landmarks and world class dining options.

Similar Jobs

3 Days Ago
Hybrid
Chicago, IL, USA
143K-238K Annually
Senior level
143K-238K Annually
Senior level
Big Data • Fintech • Information Technology • Business Intelligence • Financial Services • Cybersecurity • Big Data Analytics
Leads Global Cyber Governance, Risk & Compliance strategy, operating plans, reporting, performance metrics, executive communications, and transformation initiatives. Advises senior leadership, manages governance dashboards and risk indicators, oversees budgeting and workforce planning, and leads a team responsible for reporting and analytics. Modernizes GRC processes through artificial intelligence, automation, and emerging technologies while coordinating with security, audit, legal, compliance, privacy, and enterprise risk stakeholders.
Top Skills: Analytics PlatformsArtificial IntelligenceCis ControlsCobitFfiecIso/Iec 27001Microsoft 365Nist Cybersecurity FrameworkNist Sp 800-53Pci DssPower BISoxWorkflow Automation
28 Days Ago
Remote or Hybrid
US
120K-145K Annually
Senior level
120K-145K Annually
Senior level
Information Technology • Insurance • Professional Services • Software • Analytics
Owns the GRC product strategy, 12-month roadmap, feature backlog, and Agile delivery process. Partners with Engineering, stakeholders, marketing, and operations to translate business needs into requirements, prioritize development, validate software quality, and deliver customer value. Uses AI-assisted tools, data analytics, experimentation, and responsible AI practices to guide discovery, prototyping, prioritization, and product improvement.
Top Skills: AgileArtificial IntelligenceGrcSaaSScrumSoftware Development Lifecycle (Sdlc)
28 Days Ago
Remote or Hybrid
US
145K-185K Annually
Entry level
145K-185K Annually
Entry level
Information Technology • Insurance • Professional Services • Software • Analytics
Leads and mentors Product Managers and Product Analysts across GRC products, setting product vision, strategy, and roadmap priorities. Oversees customer research, competitive analysis, AI adoption throughout the SDLC, experimentation, KPI measurement, and cross-functional product delivery. The role advocates for customers, ensures alignment across roadmaps, promotes innovation, and manages team development and performance evaluations.
Top Skills: AIGovernance Risk And Compliance (Grc)SaaSSoftware Development Lifecycle (Sdlc)

What you need to know about the Chicago Tech Scene

With vibrant neighborhoods, great food and more affordable housing than either coast, Chicago might be the most liveable major tech hub. It is the birthplace of modern commodities and futures trading, a national hub for logistics and commerce, and home to the American Medical Association and the American Bar Association. This diverse blend of industry influences has helped Chicago emerge as a major player in verticals like fintech, biotechnology, legal tech, e-commerce and logistics technology. It’s also a major hiring center for tech companies on both coasts.

Key Facts About Chicago Tech

  • Number of Tech Workers: 245,800; 5.2% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: McDonald’s, John Deere, Boeing, Morningstar
  • Key Industries: Artificial intelligence, biotechnology, fintech, software, logistics technology
  • Funding Landscape: $2.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Pritzker Group Venture Capital, Arch Venture Partners, MATH Venture Partners, Jump Capital, Hyde Park Venture Partners
  • Research Centers and Universities: Northwestern University, University of Chicago, University of Illinois Urbana-Champaign, Illinois Institute of Technology, Argonne National Laboratory, Fermi National Accelerator Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account