Startups

Sr Project Manager, GRC (Governance Risk and Compliance)

The Coterie · Remote (United States) · Remote

← All jobs
About The Coterie

Who we are: Through a partnership-based approach, Coterie helps insurance professionals unlock untapped revenue in the small commercial space. Backed by a16z.

About the role

Coterie's GRC team is hiring a Senior Project Manager to own remediation projects tied to SOC 2, ITGC, and regulatory compliance requirements, including emerging regulations in privacy, AI governance, and security. The role also supports recurring compliance programs, such as the annual risk assessment cycle, from a scheduling and tracking standpoint, maintaining visibility into risk treatment plan status.

What they're looking for

  • 6+ years of project management experience, including leading complex, cross-functional projects, 2+ years running remediation projects tied to security, compliance, or regulatory findings strongly preferred
  • Experience translating Compliance & Security requirements into technical work and managing requirements traceability through delivery
  • Demonstrated experience building leadership-facing reporting and dashboards to track project, remediation, or risk status
  • Familiarity with frameworks such as SOC 2, ITGC, or similar regulatory and compliance standards, and how audit findings and risk treatment plans translate into scoped remediation work
  • Working technical fluency: comfortable discussing cloud infrastructure, APIs, the software development lifecycle, and core security concepts with engineering and security stakeholders
  • Proven experience managing multiple concurrent projects with competing deadlines and stakeholders
More about this role

Coterie's GRC team is hiring a Senior Project Manager to own remediation projects tied to SOC 2, ITGC, and regulatory compliance requirements, including emerging regulations in privacy, AI governance, and security. The role also supports recurring compliance programs, such as the annual risk assessment cycle, from a scheduling and tracking standpoint, maintaining visibility into risk treatment plan status. While the role reports through GRC, projects may span security, legal, compliance, finance, and other functions depending on business need. The ideal candidate combines strong project management discipline with enough technical fluency to work credibly with engineers and security practitioners including translating security and compliance requirements into work technical teams can execute, along with the ability to build the reporting and dashboards leadership needs to track progress.

Remediation Project Management

  • Own end-to-end delivery of remediation projects tied to SOC 2, ITGC, and regulatory compliance requirements, translating audit findings, control gaps, and new regulatory obligations (privacy, AI governance, security) into scoped plans, milestones, and assigned...

Read the full posting on The Coterie's site ↗

Finance/Security/People Operations

Build your edge while you search

Free tools for founders and investors, plus VC Unfiltered, our take on startups, venture and the people who build them.