InfoSec GRC Manager

BILL • South Bay

Company

BILL

Location

South Bay

Type

Full Time

Job Description

Do the best work of your career as a champion for small and mid-size businesses.

BILL is a leader in financial automation software for small and midsize businesses (SMBs). As a champion of SMBs, we are dedicated to automating the future of finance so businesses can thrive. Hundreds of thousands of businesses trust BILL solutions to manage financial workflows, including payables, receivables, and spend and expense management. With BILL, businesses are connected to a network of millions of members, so they can pay or get paid faster. Through our automated solutions, we help SMBs simplify and control their finances, so they can confidently manage their businesses, and succeed on their terms. 

BILL is a trusted partner of leading U.S. financial institutions, accounting firms, and accounting software providers. We have operations in San Jose, CA, Draper, UT, Houston, TX and are continuing to expand into other geographic locations. If you’re looking for a place that helps you do the best work of your career, look no further than BILL.

Make your impact within a rapidly growing Fintech Company

The Governance, Risk and Compliance (GRC) team at BILL facilitates information security risk management, enables risk-based decision-making in alignment with business goals, and drives compliance with standards, policies and applicable regulations globally. We are looking for a talented, enthusiastic, and authentic InfoSec GRC Manager to join our team. This position offers an outstanding opportunity to create a variety of cross-functional partnerships. Reporting to the Director of GRC Customer Audit and Assurance, the InfoSec GRC manager serves as the focal point for overseeing the enterprise-wide security compliance program, responsible for implementing, maintaining, and improving security controls to ensure compliance with company policies, applicable regulatory and legal requirements, as well as best practices. This role also oversees customer and partner security assessments and assurance, building strong bonds of trust with our customers and business partners enabling business growth. Being successful in this role requires the desire and ability to influence, uplift, collaborate, and empower individuals that also includes a strong technical background.

In this role you will:

  • Lead cross-functionally to maintain annual compliance certification such as SOC1 and SOC2 Type II, and/or other new certifications that exhibit assurance internally and externally
  • Project manage external security audit, assessment, and/or due diligence requests from regulators, business partners and customers, demonstrating compliance with applicable laws and regulations as well as contractual obligations
  • Implement processes to continuously monitor information security control, and validate effectiveness of the controls in the face of changing business strategies, technologies, and threats
  • Lead planning, scope developments, and project execution for technical compliance related self-assessments, including design and operating effectiveness testing and ensure results are appropriately documented and communicated
  • Drive remediation of process and control deficiencies and improvements identified internally and externally
  • Educate process/control owners to better understand the security controls framework and their responsibilities, advising them on the preparation and on-going maintenance of controls and control documentation 
  • Provide guidance for various technology projects, including the evaluation and recommendation of technical controls
  • Enable self-service consumption of BILL security information, compliance credentials and collateral to effectively support our Sales team and customers while reducing friction in partners and customers across all GRC domain
  • Proactively identify opportunities for control automation
  • Establish center of excellence by centralizing and maintaining currency of program documentation, SOP, control database, control ownership, narratives and evidence artifacts 
  • Effectively report program execution status, compliance status, key accomplishments and risks to senior management both within Security and to our business partners
  • Support the GRC team in establishing OKRs, defining audit & compliance strategies, objectives, metrics, and reporting mechanisms
  • Stay abreast of the latest developments, threats, and trends in cybersecurity

We’d love to chat if you have:

  • Combined 8+ years of experience in Technology risk and compliance roles. Preferably at a technology or SaaS / Cloud and / or as an auditor at Big 4 firm
  • Deep understanding of and experience achieving/maintaining compliance with risk management methodologies, frameworks, and principles (e.g. SOX, COBIT, NIST, CSA, ITIL, PCI, GDPR, PCI-DSS, ISO 27001, NIST CSF, NIST 800-53)
  • Strong ability to analyze complex data, interpret compliance requirements, develop effective solutions, and achieve agreement
  • Strong oral and written communication skills along with refined presentation skills and the ability to communicate with customer, technical and management personnel at multiple levels
  • Ability to build relationships with and influence cross-functional stakeholders, both internally and externally
  • Proficiency in planning, executing, and monitoring multiple projects simultaneously to ensure they are completed on time and within budget
  • Action-oriented with the ability to multi-task and work in agile, changing and fast growing environments
  • You prefer working in a collaborative environment. You embrace the team player concept with willingness to share knowledge, to jump in and help colleagues, to ask for help when you need it
  • Bachelor's Degree in Business, Security, Computer Science, Data, or Risk
  • CISSP, CRISC, CISA, CIPP, CRMA, PMP or similar license/certification
  • A commitment to keeping up to date with the latest developments in the GRC field, including evolving laws and regulations, emerging risks, and best practices in GRC management

The estimated salary  range for this role is noted below for our San Jose based role.  Our ranges for each role and job level are based on a variety of factors including candidate experience, expertise, and geographic location and may vary from the amounts listed above. The role is also eligible for a competitive benefits package that includes: medical, dental, vision, life and disability insurance, 401(k) retirement plan, flexible spending & health savings account, paid holidays, paid time off, and other company benefits.

San Jose pay range

$145,600—$174,700 USD

Let’s talk about benefits

  • 100% paid employee health, dental, and vision plans (choose HMO, PPO, or HDHP)
  • HSA & FSA accounts 
  • Life Insurance, Long & Short-term disability coverage
  • Employee Assistance Program (EAP)
  • 11+ Observed holidays and wellness days and flexible time off 
  • Employee Stock Purchase Program with employee discounts
  • Wellness & Fitness initiatives
  • Employee recognition and referral programs
  • And much more

For positions that are in office we support a hybrid work environment with on-site and remote work days. Check out our LinkedIn Life Page for each location and Discover BILL.   

We live our culture and values every day

At BILL, we’re different by design—it's our culture. Our CEO is a trusted entrepreneur who lives our cultural values: Humble, Authentic, Passionate, Accountable, and Fun. People here love being their authentic selves, contributing unique experiences, sharing ideas, perspectives, and intellectual curiosity. We celebrate our diversity as the heart and soul of how we work, grow, and succeed together. Inspiring people with meaningful career experiences they love really does make the dream work and our successes just keep getting better. There’s no limit to what we can build and where we can go from here. We’d love you to join us.
BILL is proudly an Equal Opportunity Employer where everyone is welcome. Our innovation and technology are inspired by an inclusive culture unlike any other. Everyone brings a different personal story and perspective and this diverse mix of minds, backgrounds, and experiences is where our greatest ideas come from. We welcome people of all races, ethnicities, ages, religions, abilities, genders, and sexual orientations to make us an even more vibrant company. We want everyone to bring their authentic selves here, to share our values, shape our vision, drive innovation, and become part of a culture we celebrate every day.

Our promise to our candidates is to be transparent, diligent, and engaging while guiding individuals through each step of our hiring process. At BILL we strive to achieve an inclusive and positive candidate experience that aligns with our core values and focuses on diversity. If you require a reasonable accommodation for your application, interviews, or another aspect of the hiring process, please contact [email protected].

BILL Culture:

  • Humble - We check our egos at the door. We are curious. We listen, accept feedback.
  • Authentic - We earn and show trust by being real—embracing our authentic selves.
  • Passionate - We care deeply about each other and our customers.
  • Accountable - We are duty-bound to each other, our customers, and society.
  • Fun - We wrap it all together by building connections and enjoying time spent together.

Our Applicant Privacy Notice describes how BILL treats the personal information it receives from applicants

Apply Now

Date Posted

03/15/2024

Views

5

Back to Job Listings ❤️Add To Job List Company Info View Company Reviews
Positive
Subjectivity Score: 0.8

Similar Jobs

AI Solution Manager, ServiceNow Platform - ServiceNow

Views in the last 30 days - 0

ServiceNow a global market leader in AIenhanced technology is seeking an AI Solution Manager to lead the implementation of AI solutions for complex bu...

View Details

Solution Manager, Workday - BlackLine

Views in the last 30 days - 0

BlackLine is a leading provider of cloud software that automates and controls the entire financial close process The company is committed to modernizi...

View Details

Senior Program Manager, Global Occupational Health & Safety - ServiceNow

Views in the last 30 days - 0

ServiceNow is seeking a Health Safety Program Manager to design implement and lead a comprehensive corporate safety program The role involves develop...

View Details

Client Support Specialist (Healthcare Facilities - B2B) - Clipboard Health

Views in the last 30 days - 0

Clipboard Health is seeking customerfocused individuals to join their team as B2B Support Specialists also known as HCF Agents This role involves bein...

View Details

Senior Finance Manager, Central FP&A - Palo Alto Networks

Views in the last 30 days - 0

Palo Alto Networks is seeking a Senior Finance Manager with 10 years of experience in FPA The role involves leading ad hoc projects collaborating with...

View Details

District Sales Manager - Manufacturing - Grainger

Views in the last 30 days - 0

The company a leading industrial distributor with operations in North America Japan and the UK is seeking a sales leader with 5 years of experience Th...

View Details