
Senior GRC Manager
1 week ago
Pontera is a fintech company on a mission to help people retire better. Our software platform enables retirement savers to get the help they need managing their 401(k) and other retirement plan accounts as part of a personalized strategy by their trusted financial advisor.
Pontera is used by financial advisors across the nation– from SMB to Fortune 500 RIA firms, independent broker-dealers, plan custodians, and plan advisors.
Backed by leading venture capital firms including ICONIQ Growth and Lightspeed Venture Partners, Pontera is built by talented individuals who share a dedication to helping people retire with greater security.
Our team is fast-growing and driven to become one of the largest fintech companies in the world. Our culture is built on a people-first principle: in a complex and numbers-driven industry, we never lose sight of the people we serve and work alongside. That's where you come in.
We are hiring a
Senior GRC Manager
to sustain, scale, and continuously enhance our Governance, Risk, and Compliance (GRC) program. Reporting directly to the
CISO
, this is a high-impact role focused on maintaining Pontera's robust compliance posture (including
SOC 2 Type II
,
ISO 27001
,
27017
, and
27018
), driving cloud assurance initiatives, and strengthening trust with customers and partners.
The ideal candidate is comfortable working cross-functionally, automating compliance workflows, and serving as a key liaison for external diligence and internal controls.
Responsibilities
- Maintain and mature the GRC program: Own core processes, documentation, and internal controls to support Pontera's security and privacy obligations.
- Align GRC activities with key frameworks, including NIST CSF, CIS Controls, and ISO 27001/27018, to ensure comprehensive control coverage and internal alignment.
- Support certification continuity: Ensure ongoing adherence and audit readiness for SOC 2 Type II, ISO 27001, ISO 27017, and ISO 27018 through continuous monitoring, control validation, and stakeholder coordination.
- Support evolving privacy governance efforts, including ISO 27701 adoption, privacy impact assessments (PIAs), and alignment with standards such as ISO 29134 or NIST Privacy Framework.
- Contribute to vendor and third-party risk management: Support onboarding, reviews, and oversight of vendors handling sensitive data or infrastructure.
- Manage Pontera's customer trust program, including responding to security questionnaires, maintaining compliance artifacts, and owning our public Trust Center (e.g., SafeBase).
- Administer and optimize GRC platforms: Manage tools such as VISO Trust, or Vanta to streamline evidence collection, risk tracking, and control testing. Lead process improvements and automation where possible.
- Maintain the risk management program: Update the enterprise risk register, facilitate periodic risk assessments, and drive mitigation planning across business functions.
- Partner cross-functionally with Legal, IT, Engineering, and Product to embed compliance requirements and align security initiatives with business goals.
Requirements
- 5+ years of experience in GRC, security compliance, or audit within a cloud-native or SaaS environment.
- Proven track record supporting and maintaining certifications such as SOC 2 Type II, ISO 27001, 27017, and 27018.
- Strong understanding of the NIST Cybersecurity Framework and CIS Critical Security Controls as applied in modern SaaS/cloud environments.
- Familiarity with privacy management standards such as ISO 27701, ISO 29134, or equivalent frameworks (e.g., NIST Privacy Framework, GDPR Art. 35 PIAs)
- Hands-on experience with GRC automation tools (e.g., Drata, Vanta, Tugboat Logic, OneTrust).
- Excellent communication skills, particularly for external audit and customer diligence engagements.
- Strong organizational and project management capabilities, with an ability to coordinate across functions and meet deadlines.
Preferred Qualifications
- Experience managing a Trust Center (e.g., SafeBase).
- Certifications such as CISM, CRISC, CCSK, or ISO 27001 Lead Implementer.
- Previous experience in regulated or trust-sensitive industries such as fintech, B2B SaaS, or healthtech industries.
What We Offer
- Opportunity: Have a major impact at a fast-growing startup that is revolutionizing the FinTech industry
- Team Culture: A collegial, collaborative, fun work environment with frequent team events
- Equity: All new hires are eligible for equity grant participation
- Professional Development: Sponsored learning & development program
- Work Flexibility: A hybrid office work model (In-Office Mon/Tues/Weds and WFH Sun//Thurs)
-
Senior Business Development Manager
1 week ago
Herzliya, Tel Aviv, Israel UWORK Full time $90,000 - $120,000 per yearWe're Hiring: B2C Trading Offerings Business Development ManagerA leading global trading company is seeking asenior Business Development Managerto drive the growth of itsB2C trading products, with a strong focus onFutures.In this high-impact role, you will be responsible for leading the full business cycle – from strategy and market expansion to product...
-
Senior Product Manager
1 week ago
Herzliya, Tel Aviv, Israel Upstream Security Full time $90,000 - $120,000 per yearUpstream is developing the next generation of AI-powered quality and cybersecurity platform for the Automotive industry. Upstream products protect millions of vehicles worldwide and help customers leverage their connected vehicle data to improve cyber resilience, safety, customer satisfaction and increase brand loyalty.Upstream is looking for an experienced...
-
Senior Product Manager
1 week ago
Herzliya, Tel Aviv, Israel Upstream Security Full time $90,000 - $120,000 per yearUpstream is developing the next generation of AI-powered quality and cybersecurity platform for the Automotive industry. Upstream products protect millions of vehicles worldwide and help customers leverage their connected vehicle data to improve cyber resilience, safety, customer satisfaction and increase brand loyalty.Upstream is looking for an experienced...
-
Senior Sales Operations Manager
1 week ago
Herzliya, Tel Aviv, Israel Penlink Full time $104,000 - $130,878 per yearAbout us:Penlink is a global leader in digital intelligence solutions. Our advanced technologies simplify complex data, empowering public safety organizations to make informed decisions quickly and effectively. We believe in the power of data-driven intelligence to accelerate clarity in decision-making for global security, strategic operations, and the most...
-
Senior Sales Operations Manager
1 week ago
Herzliya, Tel Aviv, Israel penlink Full time $104,000 - $130,878 per yearAbout us:Penlink is a global leader in digital intelligence solutions. Our advanced technologies simplify complex data, empowering public safety organizations to make informed decisions quickly and effectively. We believe in the power of data-driven intelligence to accelerate clarity in decision-making for global security, strategic operations, and the most...
-
Senior Product Manager
1 week ago
Herzliya, Tel Aviv, Israel CYE Full time $90,000 - $120,000 per yearCYE is seeking a Senior Product Manager with a passion for building and developing cutting-edge cybersecurity and cybersecurity risk quantification products. This role requires a hands-on approach, translating ideas into roadmaps and features, and following product development from start to finish. We are looking for an individual contributor and a product...
-
Senior Data Product Manager
1 week ago
Herzliya, Tel Aviv, Israel CYE Full time $90,000 - $120,000 per yearCYE is on the hunt for a temporary Senior Data Product Manager who thrives on shaping the future of cybersecurity and risk quantification. You'll roll up your sleeves, turn bold ideas into roadmaps and features, and shepherd products from spark to scale. We're after a hands-on leader who lives and breathes data and analytics—and isn't afraid to make magic...
-
Senior Product Manager
1 week ago
Herzliya, Tel Aviv, Israel Microsoft Full time $104,000 - $130,878 per yearSecurity represents the most critical priorities for our customers in a world awash in digital threats, regulatory scrutiny, and estate complexity. Microsoft Security aspires to make the world a safer place for all. We want to reshape security and empower every user, customer, and developer with a security cloud that protects them with end to end, simplified...
-
Senior Product Manager
1 week ago
Herzliya, Tel Aviv, Israel AppsFlyer Full time $104,000 - $130,878 per yearAppsFlyer is the global leader in mobile attribution and marketing analytics, powering the growth of thousands of the world's leading apps and brands. As part of our AI-first transformation, we're investing heavily in new product innovation - turning our unmatched data assets into intelligent tools that help marketers thrive in the AI era. One of our most...
-
Security Compliance Officer
1 week ago
Herzliya, Tel Aviv, Israel entrypoint Full time $104,000 - $130,878 per yearHigh-Tech Company is looking for a motivated Security Compliance Officer to join our team and support the company's compliance, governance, and risk management efforts. This role is ideal for someone who is detail-oriented, organized, and eager to grow in the field of security compliance. You will work closely with Security, IT, Legal, and Operations teams...