Quest is an award-winning IT management software provider offering a broad selection of solutions that solve some of the most common and most challenging IT problems. Quest strives to be the best of the very best in everything we do. We are fanatically customer-focused and are proud to support the most complex customers who have the highest IT demands in the world. It’s exciting, it’s rewarding, it’s hard work, and offers career and personal growth.
At Quest Software, we build technology that simplifies IT management and strengthens cybersecurity resilience for organizations around the world. Our people are central to our success, and we are committed to delivering an HR experience that reflects our global footprint, growth mindset, and employee-first culture.
The Senior Manager, Global IT Governance, Risk, Compliance (GRC), and Privacy will lead Quest’s IT GRC and privacy function for a global software organization. This leader will own enterprise risk governance, audit readiness, privacy control alignment, and compliance operations across complex regulatory, customer, and certification environments. The role requires an experienced, hands-on leader who can guide strategy, improve control maturity, influence senior stakeholders, and manage a team of two direct reports while reporting to the Head of Cybersecurity and Privacy.
This role is intended for candidates with demonstrated success leading mature GRC, privacy, audit, and risk management programs in global software, SaaS, technology, or similarly regulated environments. The successful candidate will be comfortable operating at both strategic and execution levels, setting expectations with senior stakeholders, driving accountability across distributed teams, and maintaining a high standard of follow-through in a fast-moving business.
Governance Management
-Lead the creation, maintenance, implementation, communication, and enforcement of IT policies, standards, and procedures across the global organization.
-Drive adoption of IT policies, standards, and procedures by partnering with stakeholders to clarify expectations, monitor compliance, and address implementation barriers.
-Lead and mature the global security awareness program, including program strategy, communications, training content, metrics, and continuous improvement.
Risk Management
-Own and mature the enterprise IT risk register, including risk identification, scoring, treatment planning, executive-level reporting, and timely follow-up with accountable risk owners.
-Lead and continuously improve third-party risk assessment processes, including assessment intake, risk analysis, stakeholder follow-up, reporting, and process maturity.
-Assist Security Engineering with development and management of insider threat risk mitigation controls
-Partner with Legal, Security Engineering, and other internal teams on legal hold, eDiscovery, and data security investigations that require GRC, privacy, or control expertise.
-Identify recurring problems and risks and recommend proactive measures to mitigate
Compliance Management
-Orchestrate annual maintenance, readiness, evidence collection, and external audit support for NIST Cybersecurity Framework, ISO 27001, ISO 27017, ISO 27018, ISO 27701, ISO 42001, SOC, and other applicable customer, regulatory, and certification requirements across the organization.
-Lead the documentation, assessment, testing, and measurement of control design and operating effectiveness consistent with NIST, ISO, SOC, privacy, and customer assurance requirements.
-Maintain awareness of laws, rules, and regulations governing IT risk, compliance, audit, privacy, and security in the Quest environment for the markets in which Quest operates.
-Lead the evaluation, selection, implementation, configuration, adoption, and continuous improvement of GRC tools, workflows, reporting, and automation capabilities.
-Identify, assess, and prepare Quest for emerging audit, assurance, regulatory, and governance requirements, including SOX readiness, AI governance, privacy obligations, and customer-driven compliance expectations.
Additional Activities
-Develop, maintain, and execute a multi-year GRC and privacy roadmap that aligns with business priorities, customer commitments, regulatory obligations, audit requirements, and security strategy.
-Use market research, stakeholder feedback, and analytic data to understand business needs and identify new requirements.
-Lead, coach, and hold accountable a small team of GRC and privacy professionals, setting clear priorities, developing talent, reviewing work quality, and ensuring timely delivery of commitments.
Qualifications
-12+ years of progressive experience in IT GRC, information security, privacy, technology risk, internal audit, or external audit
-Hands-on experience with assessing, selecting, implementing and administering GRC tools/software including workflow design
-Deep working knowledge of NIST CSF, ISO27001, 27017, 27018, 27701, 42001, GDPR and SOC2 frameworks
-Proven ability to communicate complex risk, compliance, privacy, and audit topics clearly to executives, technical teams, legal partners, auditors, customers, and non-technical stakeholders.
-Demonstrated record of sustained ownership, professional judgment, accountability, and follow-through in roles requiring confidential information handling, audit deadlines, cross-functional dependency management, and high-quality deliverables.
-Active professional certification(s) related to information security or information risk management (i.e. CISA, CRISC, CIPP/US/EU, CISSP, CISM)
Company Overview
Quest Software builds the foundation for enterprise AI with solutions in data governance, cybersecurity, and platform modernization. More than 45,000 companies — including 90% of the Fortune 500 — trust Quest to solve their most critical IT challenges. From securing identities and modernizing platforms to preparing data for AI, we help enterprises unlock their full potential.
Why Quest
At Quest, your work makes an impact. You’ll help organizations get AI-ready while building your career with a global team of innovators. We offer:
Quest is an Equal Opportunity Employer and Prohibits Discrimination and Harassment of Any Kind: Quest is committed to the principle of equal employment opportunity for all employees and to providing employees with a work environment free of discrimination and harassment. All employment decisions at Quest are based on business needs, job requirements and individual qualifications, without regard to race, color, religion or belief, national, social or ethnic origin, sex (including pregnancy), age, physical, mental or sensory disability, HIV Status, sexual orientation, gender identity and/or expression, marital, civil union or domestic partnership status, past or present military service, family medical history or genetic information, family or parental status, or any other status protected by the laws or regulations in the locations where we operate. Quest will not tolerate discrimination or harassment based on any of these characteristics. Quest encourages applicants of all ages.
Come join us. For more information, visit us on the web at Quest Careers | Innovate. Collaborate. Grow.
Job seekers should be aware of fraudulent job offers from online scammers and only apply to roles listed on quest.com/careers using our applicant system. Note: We do not use text messaging or third-party messaging apps like Telegram to communicate with applicants, so please exercise caution if you are approached in this way and only interact with people claiming to be Quest employees if they have an email address ending in @quest.com. You can report job scams to the FTC (ReportFraud.ftc.gov) or your state attorney general. #LI-CJ
Software Powered by ICIMS
www.icims.com