GRC Program Manager
Astra
full-remoteseniorpermanentproduct-managementother Full remote 74 days ago via WTTJ
See how well this job matches your profile
Sign up to get an AI match score and generate a tailored application in seconds.
Get your match scoreTags
SOC 1SOC 2PCI DSSISO 27001NIST CSFGRCAudit ManagementRisk AssessmentVendor Risk ManagementISMS
About the role
Role overview
Join Astra as the first dedicated GRC Program Manager, building the company’s governance, risk, and compliance (GRC) foundation to support rapid growth while meeting regulatory expectations.
Key missions / responsibilities
- Own daily audit execution for SOC 1, SOC 2, PCI DSS, and ISO 27001, including:
- Defining audit scope and control testing approach
- Collecting evidence and supporting audit workpapers
- Coordinating with auditors
- Tracking and driving remediation
- Develop and maintain GRC artifacts, including:
- Policies, procedures, and risk assessments
- Control narratives and supporting documentation that evolve with the business
- Partner with engineering & infrastructure to translate security/compliance requirements into practical technical controls across:
- Cloud infrastructure, SDLC, access management
- Logging, monitoring, and incident response
Requirements
- Strong ability to build and maintain high-quality documentation, evidence, and audit artifacts
- Cross-functional collaboration with engineering/product/operations in technical environments
- Comfortable operating in fast-moving, ambiguous settings
- Hands-on experience supporting or leading SOC 1 and/or SOC 2 audits; PCI DSS and ISO 27001 are strongly preferred
- Ability to build from 0 to 1: frameworks, templates, and playbooks that scale
- Working knowledge of compliance frameworks and how controls operate in practice: SOC, ISO 27001, NIST CSF, PCI DSS
- 3–6+ years of experience in GRC, risk, compliance, audit, or information security
- Experience aligning with Product, Sales, and Engineering to drive outcomes
- Bachelor’s degree in a related field (or equivalent practical experience)
- Fintech/payments experience in regulated environments (preferred): payments, banking partners, PCI, or financial audits
- ISO 27001 experience supporting certification or operating within an ISO-aligned ISMS
Nice-to-haves
- Experience implementing compliance tooling, evidence automation, or GRC platforms
- Vendor risk management (third-party risk workflows)
- Startup environment experience scaling compliance programs
- Structured system/vendor/operational risk assessments
- Audit operations skills: scoping, walkthroughs, evidence management, remediation tracking, auditor coordination
- Technical fluency across cloud, IAM, logging/monitoring, SDLC, and security tooling
About Astra
Astra is building trusted financial infrastructure and provides a platform that supports rapid growth in regulated environments. The role focuses on establishing the company’s governance, risk, and compliance foundation, partnering closely with engineering and infrastructure teams.
Scraped 5/12/2026