Note: For our technical positions, we love to get you started in person! You may be required to travel to Medford for your initial onboarding. Don't worry about the logistics - once you're hired, we handle all travel arrangements and expenses for you.
Role Description and Mission:
The Senior Manager, Governance, Risk, and Compliance (GRC) is a strategic leadership position accountable for the architectural integrity of the organization's cybersecurity policies, risk governance frameworks, and contractual compliance standards. Reporting directly to the Chief Information Security Officer (CISO), this role oversees the end-to-end audit lifecycle, external security certifications, and client trust assessments across the enterprise B2B2C platform. The Senior Manager partners across Security, Engineering, and Legal to engineer security exhibits, manage the third-party vendor risk ecosystem, and drive the modernization of GRC operations through automated compliance tooling and generative AI applications. This position ensures that the organization’s security and privacy controls scale alongside evolving regulatory environments while maintaining the rigorous security posture expected by major automotive, insurance, and fleet enterprise partners.
Key Outcomes:
- Audit Lifecycle & Client Trust Leadership: Command the end-to-end response strategy for annual client security assessments; direct the preparation and multi-day presentation of complex technical evidence to sophisticated enterprise partners.
- External Framework Certification: Own the successful execution, maintenance, and scope validation of core compliance frameworks, including PCI-DSS, ISO 27001, SOC2 Type II, and TISAX.
- Contractual Security Engineering: Partner with the Legal and Strategic Procurement teams to draft, review, and negotiate security exhibits within client and vendor contracts, ensuring committed promises align directly with technical capabilities.
- Policy Architecture & Governance: Develop, implement, and enforce a comprehensive library of corporate security policies that satisfy global standards while remaining functional and frictionless for a software-driven enterprise.
- Regulatory Compliance & Privacy Design: Monitor global regulatory environments (e.g., CCPA/CPRA, GDPR, and emerging automotive cybersecurity mandates); collaborate with Privacy Owners to design underlying cyber strategies, documentation, and procedures.
- GRC Automation & Technology Innovation: Direct the modernization of the GRC infrastructure by maximizing the ROI of continuous monitoring platforms and deploying/tuning Generative AI tools to automate high-volume compliance workflows.
- Cross-Functional Security Integration: Serve as a core member of the Cybersecurity leadership team, collaborating with Product and Engineering leads to ensure security and legal requirements are embedded natively into the product development lifecycle.
- Team Leadership & Development: Directly manage, mentor, and evaluate the performance of GRC team professionals, aligning resource allocation with the organization's audit pipeline and strategic deadlines.
Skills, Education and Experience:
Education: Bachelor's degree in Computer Science, Information Security, Information Technology, or a related technical field is required. Active CISSP or CISM certification is required.
Experience: 8+ years of progressive experience in Cybersecurity, GRC, or IT Audit. A minimum of 2 years of direct people management or leadership experience. Proven track record managing complex frameworks (SOC2, PCI, ISO, TISAX), translating technical controls into contractual language, and implementing automated GRC workflows. Privacy, cloud-architecture, or specialized IT audit certifications are highly preferred.
Knowledge, Skills & Abilities:
- Audit Command & Framework Expertise: Capable of leading enterprise-level certification lifecycles (SOC2, PCI, ISO, TISAX) and orchestrating complex evidence presentations for sophisticated, tier-one client stakeholders.
- Contractual Literacy & Legal Alignment: Can collaborate with Legal Counsel to interpret, draft, and negotiate complex security exhibits, ensuring technical parameters are accurately reflected in commercial and vendor agreements.
- GRC Automation & Technical Innovation: Proficient in leveraging compliance automation platforms and utilizing Generative AI/LLM tools to scale evidence collection and automate security questionnaire responses.
- Regulatory Synthesis & Privacy Design: Capable of translating shifting global privacy laws and government cybersecurity mandates into actionable corporate strategies, operational procedures, and policy requirements.
- Executive & Adaptable Communication: Can shift communication style fluidly between a "deep dive" technical review with Software Engineers and an executive "risk briefing" with General Counsel or client C-suites.
- Policy Architecture & Systems Thinking: Capable of designing a comprehensive security policy framework that scales to satisfy rigorous enterprise auditing while supporting a developer-friendly, agile technology ecosystem.
- Strategic Problem Solving & Risk Remediation: Approaches control deficiencies and compliance gaps with a proactive mindset; capable of conducting root-cause analyses and designing scalable, risk-adjusted remediation strategies to protect the organization's security posture.
- Strategic Relationship Management & Influencing: Capable of serving as a cybersecurity evangelist to cultivate deep, trust-based partnerships across enterprise leadership; utilizes strategic diplomacy to align cross-functional goals and successfully drive complex security initiatives without relying on direct authority.
Hiring In:
United States: Arizona, California, Florida, Georgia, Illinois, Massachusetts, Michigan, New Hampshire, New York State, New Mexico, North Carolina, Tennessee, Virginia
WORKING RELATIONSHIPS: This position reports directly to the Chief Information Security Officer (CISO) and manages a direct report. The Senior Manager maintains deep collaborative partnerships with the Legal Team (including Privacy Owners), Engineering and Product Leadership, and the Strategic Procurement Team. Externally, this role interfaces with executive auditors, third-party vendor risk assessment teams, and security leaders at partner enterprise organizations.
ADDITIONAL REQUIREMENTS: Position location and hybrid/remote status are determined by corporate policy. Periodic availability outside of standard working hours may be required to accommodate time-sensitive client audits, regulatory submission deadlines, or critical security reviews.
THIS DESCRIPTION IS NOT INTENDED TO BE A COMPLETE STATEMENT OF JOB CONTENT, RATHER TO ACT AS A GUIDE TO THE ESSENTIAL FUNCTIONS PERFORMED. MANAGEMENT RETAINS THE DISCRETION TO ADD TO OR CHANGE THE DUTIES OF THE POSITION AT ANY TIME.
The anticipated closing date to submit applications for this role is July 1st, 2026. Join our Greenhouse Candidate Portal to track your application status and receive instant alerts for future openings.
The base salary range presented represents the anticipated low and high end salary range for new hires in this position. Your final base salary will be determined based on factors such as work location, experience, job related skills, and relevant training and education. The range listed is just one component of the total compensation package provided by Agero to employees.
Life at Agero:
At Agero, you'll find a workplace where your unique perspective is not just welcomed, it's celebrated. We believe that our differences make us stronger, and we're committed to creating an environment where every employee feels a sense of belonging. If you're looking for a company that values your individuality, provides opportunities for growth, and champions open communication, Agero is the place for you. Join our team and help us drive the future of driver assistance, while experiencing a workplace where you can truly thrive.
Benefits Built for Well-being:
Agero’s innovation is driven by a workforce where all associates feel like they can truly thrive. Agero offers a wide range of benefits to promote well-being, encourage personal development, and ensure financial stability. Our benefits include:
- Health and Wellness: Healthcare, dental, vision, disability, life insurance, and mental health benefits for associates and their families.
- Financial Security: 401(k) plan with company match and tuition assistance to support your future goals.
- Work-Life Balance: Flexible time off, paid sick leave, and ten paid holidays annually.
- For Contact Center Roles: Accrual of up to 3 weeks Paid Time Off per year, paid sick leave, and ten paid holidays annually.
- Family Support: Parental planning benefits to assist associates through life’s milestones.
- Bonus/Incentive Programs
Join Agero and experience a workplace that invests in your success both personally and professionally.
*Applicants must be currently authorized to work in the United States on a full‑time basis. This position is not eligible for employer visa sponsorship now or in the future.
*It is unlawful in Massachusetts to required or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
Skills Required
- Bachelor's degree in Computer Science, Information Security, or related field
- Active CISSP or CISM certification
- 8+ years in Cybersecurity, GRC, or IT Audit
- 2+ years of direct people management experience
- Experience managing SOC2, PCI, ISO, TISAX frameworks
What We Do
Agero is a leading provider of driver assistance, accident management, consumer affairs support and connected vehicle services for stakeholders across the automotive industry, including the world’s largest automakers, auto retailers, insurers, rideshare providers and other brands. As the driving force behind mobility support throughout all points in the vehicle ownership journey - from purchase to maintenance and breakdown to resell or trade in - we deliver a suite of powerful, innovative services and technology solutions that enable our 100+ clients to provide their drivers with enhanced communication, safety, and convenience for whatever their vehicle need.
Why Work With Us
At Agero, our solutions help drivers when they need it most. Our work directly impacts the lives of over 12 million people each year, providing safety and peace of mind. We offer a unique career environment that combines the spirited energy of a fast-paced team with the stability of an established leader. Here you transform the road ahead and shap
Gallery
Agero Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.
Balancing work and life is a priority and productivity looks different for everyone. Our hybrid policy allows employees to work however they work best



.jpeg)
%20(1).png)











.jpeg)
%20(1).png)








