GRC Manager
WFA Digital Insight
Valence’s GRC Manager sits at the intersection of security, product, and rapid‑growth engineering, turning compliance from a checkbox exercise into a strategic asset. The role isn’t about maintaining static policies; you’ll actively shape ISO 27001/42001 and SOC 2 frameworks while feeding risk insights back into product roadmaps. Because Valence builds an AI‑first coaching platform for Fortune 500 clients, the GRC function must keep pace with fast‑moving tech releases and diverse industry regulations. Expect daily collaboration with engineers to embed controls, and regular interaction with sales and operations to translate security assurances into client wins. Candidates who thrive on cross‑functional influence and enjoy translating complex standards into actionable processes will feel right at home.
Job Description
Valence has built the only first-to-market AI native coaching platform for enterprise, offering personalized, expert, and human-like guidance and support to any leader or employee. We’re not just talking about the future of work — we’re building it now, with the most innovative Fortune 500 companies across healthcare, financial services, manufacturing, and technology. Learn more about our work with Microsoft: Valence Brings AI Coaching More Deeply Into the Flow of Work with Microsoft 365 https://www.valence.co/blog/valence-microsoft-365-may-2026 Our focus is on the problems that actually decide whether AI changes how organizations operate — the ones with no playbook, no obvious answers, and no guarantee of success. If you want to be part of the small group that defines how AI transforms the future at a global scale, this is your chance. And this isn’t for everyone. We’re not looking for people who want predictability or incremental progress. We only want those who are restless at the edge of what’s possible, who get bored when things feel “done,” and who are driven to redefine what AI can mean for leaders, companies, and the world. Because at Valence, the work worth doing is the kind that redefines work itself. THE ROLE We are seeking an experienced Governance, Risk & Compliance (GRC) Manager to help mature and scale Valence's security and compliance program. In this role, you will partner with Engineering, Product, IT, Sales, and Operations to ensure our security program remains effective while enabling the business to move quickly. You'll own the operational side of our GRC program: managing audits, coordinating risk assessments, maintaining policies and controls, supporting customer assurance, and helping turn compliance from a reactive exercise into a scalable business capability. This is a highly cross-functional role where success depends on organization, communication, and the ability to influence without authority. ABOUT VALENCE We're the only company pioneering leadership coaching for large enterprises in an AI-first way. Our mission is to transform how the world's biggest companies approach learning and development, helping teams work better together through AI-powered personalization that adapts to individual goals and organizational culture using the latest advances in machine learning and natural language processing. We've been featured in Harvard Business Review, TIME, World Economic Forum, Financial Times, Forbes and an Inc. 5000 fastest-growing private companies in America. Our clients represent the most diverse and sophisticated enterprise AI implementations globally, including Coca-Cola, Delta, Nestlé, General Mills, Schneider Electric, Deutsche Telekom, AstraZeneca, Prudential, CVS and Bristol Myers Squibb. Working at Valence means you'll work directly with Fortune 500 technology leaders, building expertise through the most complex enterprise deployments while gaining insight into diverse organizational approaches to AI transformation. These aren't just any enterprise clients - they're the companies defining what AI-first business transformation looks like across every major industry. WHAT YOU'LL DO - Own the day-to-day operation of Valence's GRC program.
- Maintain and continuously improve our Information Security and Artificial Intelligence Management System for ISO 27001/42001.
- Coordinate SOC 2, ISO 27001, ISO 42001, and other certification efforts.
- Manage the security risk register and facilitate enterprise risk assessments.
- Coordinate internal and external audits.
- Manage security policies, standards, and control documentation.
- Track remediation activities and drive control improvements across teams.
- Support customer security questionnaires, RFPs, and due diligence activities.
- Partner with Engineering to ensure technical controls meet compliance requirements.
- Help develop security metrics and executive reporting.
- Coordinate annual control testing and evidence collection.
- Build scalable governance processes as the company grows.
- A desire to automate GRC tasks, including with the use of AI.
- Strong understanding of security frameworks such as SOC 2, ISO 27001, NIST CSF and ISO 42001.
- Experience with risk management methodologies and maintaining risk registers.
- Experience coordinating internal and external audits.
- Experience working cross-functionally with Engineering, IT, Legal, Privacy and business stakeholders.
- Strong organizational and project management skills.
- Excellent written and verbal communication.
- Comfortable interpreting control requirements and translating them into practical implementation guidance.
- Familiarity with cloud security concepts and requirements (AWS/Azure preferred).
- Experience with GRC platforms such as Vanta, Drata, Secureframe, OneTrust, Archer or similar is a plus.
- Familiarity with privacy regulations and AI governance, including GDPR and the EU AI Act.
How to Stand Out
- Highlight concrete examples of ISO 27001, SOC 2 or ISO 42001 projects you have led, including the specific controls you implemented.
- Prepare to discuss how you have used Excel to track risk registers, remediation plans or audit evidence.
- Emphasize any experience working with engineering teams to embed security controls into product pipelines.
- Bring a brief case study showing how you turned a compliance requirement into a measurable business benefit.
- Ask interviewers about the current state of their GRC tooling and how the team measures success; this shows proactive thinking.
- Be ready to demonstrate clear communication skills by explaining a complex security concept in plain language.
- If offered, inquire about equity participation and professional development support to ensure the package aligns with your career goals.
This is a remote position listed on WFA Digital, the platform for professionals who work from anywhere. Browse more remote jobs across all categories.