Accela Logo

Accela

Manager, Governance, Risk & Compliance

Posted 18 Days Ago
Be an Early Applicant
In-Office or Remote
Hiring Remotely in Basel, KS
150K-170K Annually
Senior level
In-Office or Remote
Hiring Remotely in Basel, KS
150K-170K Annually
Senior level
Lead security governance, risk, and compliance programs including policy and control management, audit readiness (SOC 2, ISO, GovRAMP, PCI, HIPAA, NIST), third-party risk, evidence collection, remediation tracking, metrics/dashboarding, and executive/auditor communications. Partner cross-functionally to operationalize controls, support customer security reviews, and improve GRC automation and processes.
The summary above was generated by AI

ABOUT THE ROLE

 The Manager, Governance, Risk, and Compliance leads Accela security governance, risk, compliance, audit, and customer trust programs. This role owns security policies, standards, risk management processes, control evidence, audit readiness, and third-party risk management.

The Manager, GRC partners with Security, Legal, IT, Engineering, Product, Finance, People, and customer-facing teams to ensure Accela meets regulatory, contractual, audit, and customer trust obligations.

This role is the primary owner for compliance programs and audit readiness across SOC 2, ISO 27001, GovRAMP, PCI DSS, HIPAA, NIST CSF, NIST 800-53, CCPA/GDPR, and other customer or regulatory requirements.

SPECIFIC RESPONSIBILITIES

  • Lead the governance, risk, and compliance function across security policies, standards, risk management, audits, third-party risk, and control operations.
  • Develop, maintain, and operationalize global security policies, standards, procedures, control documentation, and exception processes.
  • Own audit readiness and ongoing compliance programs across frameworks such as SOC 2, ISO 27001, GovRAMP, PCI DSS, HIPAA, NIST CSF, NIST 800-53, CCPA/GDPR, and other customer or regulatory requirements.
  • Lead GovRAMP and PCI DSS readiness, including control mapping, evidence collection, remediation tracking, stakeholder coordination, audit preparation, and audit support.
  • Coordinate audit evidence collection, control testing, remediation tracking, auditor communication, and management responses.
  • Maintain the security risk register, including identification, assessment, ownership, remediation, acceptance, exception tracking, and executive reporting of security risks.
  • Partner with control owners across Security, IT, Engineering, Legal, HR, Finance, Product, and Operations to ensure control effectiveness and accountability.
  • Manage third-party and supply chain risk management, including vendor security reviews, due diligence, risk assessments, contract security input, and remediation tracking.
  • Support customer security reviews, questionnaires, trust center content, security documentation, and customer-facing compliance responses.
  • Develop metrics and dashboards for audit status, control health, risk posture, vendor risk, policy exceptions, compliance readiness, and remediation progress.
  • Support incident response and privacy incident processes by ensuring regulatory, contractual, audit, and customer notification obligations are understood and tracked.
  • Partner with the CISO to communicate security posture, compliance progress, key risks, control gaps, and trade-offs to executives, customers, auditors, and regulators.
  • Drive continuous improvement of the GRC operating model, including automation, evidence reuse, control rationalization, risk prioritization, and policy lifecycle management.

REQUIRED QUALIFICATIONS

  • 6+ years of experience in security governance, risk management, compliance, audit, third-party risk, or related cybersecurity roles.
  • Experience managing or supporting audits and compliance programs for SOC 2, ISO 27001, GovRAMP, PCI DSS, HIPAA, NIST 800-53, or similar frameworks.
  • Strong understanding of security controls, policy management, risk assessment, control testing, evidence collection, and audit readiness practices.
  • Experience working with auditors, customers, internal stakeholders, and executive leadership.
  • Experience managing third-party risk or vendor security review programs.
  • Ability to translate complex compliance obligations into practical business and technical requirements.
  • Strong project management skills with the ability to manage multiple audits, risks, remediation efforts, and stakeholder workstreams simultaneously.
  • Excellent written and verbal communication skills.

DESIRED QUALIFICATIONS

  • Experience in SaaS, cloud, public-sector technology, government technology, or regulated environments.
  • Experience with GovRAMP, FedRAMP Moderate or High, PCI DSS, NIST 800-53, or other public-sector and payment security compliance frameworks.
  • Experience with GRC platforms, trust centers, vendor risk platforms, policy management platforms, or control automation tools.
  • Experience supporting privacy programs involving CCPA, GDPR, HIPAA, or similar requirements.
  • Experience developing executive-level risk and compliance reporting.
  • Relevant certifications such as CISSP, CISM, CISA, CRISC, ISO 27001 Lead Implementer, or ISO 27001 Lead Auditor.

Other

  • May support incident response activities related to evidence preservation, notification obligations, contractual obligations, and control impact analysis.
  • Very light travel may be expected for team or company offsites and industry conferences.

ABOUT ACCELA
For nearly 20 years, Accela has been an industry leader in designing and delivering government software to improve efficiency, increase citizen engagement and enable the development of thriving communities. Today, citizens are savvy to how services should be delivered, and expect a consistently convenient, openly transparent view into their local government. While government agencies struggle to do more with less, our mission has never been more critical. Accela provides a robust, cloud-based platform of government software solutions that accelerate growth, efficiency, and transparency in communities of all sizes. From planning, to building, to service request management and more, Accela’s SaaS offerings level the playing field for small and medium governments and enable smaller agencies to leverage larger city technologies. Our open and flexible technology helps agencies address specific needs today, while ensuring they are well prepared for the emerging challenges of the future.

OUR COMMITMENT TO DIVERSITY, EQUITY, AND INCLUSION
Accela believes in developing and nurturing a workplace community where our differences are celebrated, and everyone feels a sense of psychological safety and belonging. Accela is committed to putting resources and attention towards evolving our practices, policies, and philosophies to enable diversity to thrive and to support equity in opportunity for everyone.

COMPENSATION AND WELL-BEING
The annual base salary range for this full-time position is $150,000-$170,000(less applicable taxes). The actual annual base salary offered may be adjusted based on a variety of factors, including but not limited to, location, education, skills, training, and experience. In addition to an annual base salary, this position is eligible for an annual bonus target. This is a discretionary bonus awarded based on company and individual goal achievement.
 
Accela’s U.S. team members will receive a generous benefits package consisting of options including flexible time off, comprehensive medical, dental, and vision plans, family planning benefits, 401(k) retirement savings plan with company match, health savings account with company contributions, flexible spending account, life, accident, and disability coverage, business travel insurance, employee assistance programs, and other well-being benefits.

Accela is an Equal Opportunity Employer/Affirmative Action Employer and will respond to requests for job accommodations.

All qualified applicants will receive consideration for employment without regard to race, sex, color, religion, national origin, protected veteran status, or based on disability, gender identity, and sexual orientation

#LI-Remote

Similar Jobs

Yesterday
Remote
USA
115K-140K Annually
Senior level
115K-140K Annually
Senior level
Healthtech • Professional Services
Lead and manage the GRC program and team across third-party risk, internal audit, compliance, and ISMS. Develop policies, run risk assessments (SOC2, ISO27001, PCI-DSS), maintain risk registers and CAPAs, manage client security questionnaires and business continuity planning, build security KPIs, and drive cross-functional compliance and improvement initiatives.
Top Skills: HipaaIsmsIso 27001Nist CsfPci-DssSoc 2
Yesterday
Remote
USA
162K-209K Annually
Senior level
162K-209K Annually
Senior level
Healthtech • Social Impact
Lead Virta's Governance, Risk, and Compliance program by maturing policies, automating evidence collection with GRC platforms, managing HIPAA/HITRUST/SOC 2 compliance, supporting sales on security reviews and RFPs, conducting risk assessments, designing frictionless employee SaaS and access workflows, coordinating cross-functional security alignment including AI governance, and delivering security awareness training and executive reporting.
Top Skills: AIDrataHipaaHitrust CsfIso 42001JIRANist Ai RmfSaaSSoc 2VantaZendesk
7 Minutes Ago
Remote or Hybrid
United States
129K-174K Annually
Senior level
129K-174K Annually
Senior level
Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Lead client engagements to assess business challenges, define enterprise data and AI strategies, develop roadmaps, guide solution design and delivery, provide technical leadership and mentoring, and support practice growth via presales and thought leadership.
Top Skills: AnalyticsAzureBusiness IntelligenceCloud Data PlatformsCopilotsData AgentsData WarehousingDatabricksGenerative AiMicrosoft FabricSnowflake

What you need to know about the Chicago Tech Scene

With vibrant neighborhoods, great food and more affordable housing than either coast, Chicago might be the most liveable major tech hub. It is the birthplace of modern commodities and futures trading, a national hub for logistics and commerce, and home to the American Medical Association and the American Bar Association. This diverse blend of industry influences has helped Chicago emerge as a major player in verticals like fintech, biotechnology, legal tech, e-commerce and logistics technology. It’s also a major hiring center for tech companies on both coasts.

Key Facts About Chicago Tech

  • Number of Tech Workers: 245,800; 5.2% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: McDonald’s, John Deere, Boeing, Morningstar
  • Key Industries: Artificial intelligence, biotechnology, fintech, software, logistics technology
  • Funding Landscape: $2.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Pritzker Group Venture Capital, Arch Venture Partners, MATH Venture Partners, Jump Capital, Hyde Park Venture Partners
  • Research Centers and Universities: Northwestern University, University of Chicago, University of Illinois Urbana-Champaign, Illinois Institute of Technology, Argonne National Laboratory, Fermi National Accelerator Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account