Deputy
Security
GRCProgramManager
Neural analysis suggests this role is
optimal for Manager candidates.
“GRC Program Manager at Deputy. Skills: GRC, AI Governance, Data Governance, Compliance workflows. Design internal controls for ISO 42001. Implement internal controls for ISO 42001”
Industry & Context.
Problem solving
What They're Looking For.
Must Have
5+ years of hands-on experience in GRC roles, Experience executing audits, Experience building compliance workflows from scratch, Ability to pivot between policy writing and evidence, Comfortable operating as an individual contributor, Owns strategy and administrative execution, Working knowledge of ISO 27001, Working knowledge of SOC2, Working knowledge of PCI-DSS, Working knowledge of ISO 42001 (AI), Exceptional active listening skills, Exceptional interpersonal skills, Ability to influence cross-functional decisions, Ability to adapt strategies to company priorities
Nice to Have
Advanced security certifications, Advanced privacy certifications
What You'll Do.
Design internal controls for ISO 42001
Implement internal controls for ISO 42001
Monitor internal controls for ISO 42001
Design internal controls for ISO 27001
Implement internal controls for ISO 27001
Monitor internal controls for ISO 27001
Achieve ISO 42001 certifications
Maintain ISO 42001 certifications
Achieve ISO 27001 certifications
Maintain ISO 27001 certifications
Adhere to NIST AI Frameworks
Adhere to NIST Privacy Frameworks
Coordinate internal audits
Coordinate external audits
Collect audit evidence
Track audit remediation
Execute daily operational GRC pipeline
Manage third-party vendor risk assessments
Manage customer security questionnaires
Embed into product lifecycles
Embed into engineering lifecycles
Attend project kick-offs
Translate business targets into GRC requirements
Author company policies
Update company policies
Roll out company policies
Align risk activities with operational goals
Align compliance activities with operational goals
Perform cross-functional risk assessments
Provide actionable mitigation steps
Serve as escalation for security inquiries
Maintain standard response repositories
How You'll Work.
Team & Collaboration
Cross-functional decisions; Product lifecycles; Engineering lifecycles
Communication Scope
Active listening; Interpersonal skills; Influence decisions
Full Job Description
## Description Deputy is a global SaaS workforce management company with hubs in Sydney, Melbourne, San Francisco and London, plus team members working remotely across the United States. Our platform serves over 1.5 million workers and 375,000 workplaces across 100+ countries. We are backed by top global investors and recently achieved Unicorn status. At Deputy, we’re improving the world of work, one shift at a time, for 80% of the world’s workforce: hourly workers. These are the dedicated employees who keep our world running – from baristas to nurses, cleaners to delivery drivers, florists to factory workers. Despite their vital role in society, most workplace technology has focused on those workers who sit behind a desk, but at Deputy, we transform the frontline. When businesses use Deputy, their workplaces thrive – the business is more profitable, compliant, and productive, while the workers are more engaged and happier at work. We're becoming an AI-native company, a commitment that means you'll be empowered (and expected) to use AI tools and thinking in your day-to-day work. You'll have the training, support, and freedom to use AI responsibly and creatively to spark ideas, solve problems faster, and unlock new ways of working. If you’re passionate about creating solutions that put people first and helping businesses and their teams thrive, join us at Deputy and make an impact where it matters most! The Role As the GRC Program Manager, you will be empowered with AI to be the sole custodian and operator of Deputy’s integrated governance program. This is a highly impactful, "hands-on" role that requires a unique blend of strategic framework design and tactical, daily execution. Reporting to the Senior Director of Security, you will be a true GRC Swiss Army Knife—responsible for building, running, and maintaining our comprehensive programs across Security, Privacy, AI Governance, and Data Governance, while simultaneously executing core security certifications
Applying for this GRC Program Manager role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Lever
- Lever uses a streamlined one-page form — apply in under 5 minutes.
- LinkedIn import works well; review parsed data before submitting.
- The cover letter field is optional but visible to reviewers — use it to differentiate.
- Referral codes from employees can significantly boost visibility of your application.
ANONYMOUS · UNFILTERED
What do employees actually say about Deputy?
Real rants from real employees. Read before you apply.