Upstart

Information Security Program Manager - Governance, Risk, & Compliance (GRC)


PayCompetitive
LocationMyrtle Point/Oregon
Employment typeFull-Time
  • Job Description

      Req#: 7586531
      Employer Industry: Financial Technology

      Why consider this job opportunity:
      - Salary up to $194,000
      - Target bonuses and equity compensation included in the total compensation package
      - Generous benefits package, including medical, dental, vision, and a 401(k) plan with employer matching
      - Flexible remote work opportunity, with regular in-person collaboration sessions
      - Support for professional growth and personal development through wellness and productivity allowances

      What to Expect (Job Responsibilities):
      - Act as a trusted GRC partner, translating audit, risk, and compliance requirements into practical guidance for teams
      - Coordinate core assurance activities, including SOX IT and SOC 2 audits, across various teams
      - Manage security due diligence requests from business partners to protect customer trust
      - Own policy management, including drafting and maintaining information security policies and standards
      - Support the information security third-party risk management program, including vendor assessments and remediation follow-up

      What is Required (Qualifications):
      - 5+ years of experience in information security, GRC, or IT/Information Security audit
      - Demonstrated experience operating GRC programs in a regulated technology or financial services environment
      - Working knowledge of common security and compliance frameworks (SOC 2, NIST CSF 2.0, etc.)
      - Strong written and verbal communication skills with both technical and non-technical audiences
      - Ability to design metrics, KRIs, and reporting for diverse stakeholders

      How to Stand Out (Preferred Qualifications):
      - Experience in cloud-native environments (AWS preferred)
      - Familiarity with GRC automation tools
      - Relevant certifications (CISSP, CISA, CRISC, CISM)
      - Scripting or light coding skills to automate workflows and system integrations
      - Understanding of privacy and data protection requirements (e.g., GDPR, CCPA)

      #FinancialTechnology #InformationSecurity #RemoteWork #CareerGrowth #CompetitiveCompensation

      We prioritize candidate privacy and champion equal-opportunity employment. Central to our mission is our partnership with companies that share this commitment. We aim to foster a fair, transparent, and secure hiring environment for all. If you encounter any employer not adhering to these principles, please bring it to our attention immediately.
      We are not the EOR (Employer of Record) for this position. Our role in this specific opportunity is to connect outstanding candidates with a top-tier employer.
  • About the company

      Upstart's lending platform provides direct-to-consumer personal loans from $1,000 to $50,000 and automated borrowing technology for banks and credit unions.

Notice

Talentify is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status.

Talentify provides reasonable accommodations to qualified applicants with disabilities, including disabled veterans. Request assistance at accessibility@talentify.io or 407-000-0000.

Federal law requires every new hire to complete Form I-9 and present proof of identity and U.S. work eligibility.

An Automated Employment Decision Tool (AEDT) will score your job-related skills and responses. Bias-audit & data-use details: www.talentify.io/bias-audit-report. NYC applicants may request an alternative process or accommodation at aedt@talentify.io or 407-000-0000.