Senior Security GRC Program Manager at Bumble, overseeing PCI, SOX, ITGC, and GDPR compliance programs. Driving audit excellence and automation maturity across products and infrastructure.
Responsibilities
Own Bumble’s Core Compliance Programs:
Lead end-to-end management of PCI, SOX, ITGC, and GDPR frameworks — from annual audit planning through evidence collection, remediation, and executive reporting.
Drive Audit Efficiency & Automation:
Partner with Security Engineering, Finance IT, and Product teams to automate evidence workflows, control attestations, and testing pipelines via tools such as Drata, Vanta, or ServiceNow GRC.
Lead SOX & ITGC Program Delivery:
Co-own SOX ITGC compliance with Finance IT, directly manage external audit partners, and maintain strong control hygiene across identity, change management, and infrastructure layers.
Oversee PCI Compliance Operations:
Maintain Bumble’s PCI program scope, manage annual assessments, and coordinate with payments and infrastructure teams to ensure ongoing adherence and minimal audit fatigue.
Steward GDPR Alignment:
Partner with Legal, Privacy, and Data Engineering to operationalize GDPR requirements, ensuring data protection principles and privacy-by-design controls are consistently validated.
Report Risk & Remediation Metrics:
Build dashboards and KPI reports that provide visibility into audit readiness, control performance, and remediation progress for executive stakeholders.
Requirements
6+ years of experience in Security GRC, audit, or compliance within a cloud-native or technology-driven environment.
Proven ownership of PCI, SOX, ITGC, and GDPR compliance programs — from planning through audit closure.
Demonstrated success driving measurable improvements in audit efficiency, control maturity, or automation adoption.
Strong working knowledge of cloud architectures (AWS, GCP) and common ITGC control areas — including access management, change management, and incident response.
Experience integrating GRC tools with engineering systems (e.g., CI/CD pipelines, Jira, Slack, or identity platforms like Okta).
Ability to design or refine control automation workflows and collaborate with engineers on technical control implementation.
Practical understanding of data flow mapping and system-of-record validation to support GDPR evidence and privacy controls.
Track record of leading multi-stakeholder audits (Finance, Legal, Engineering, Privacy) and aligning diverse teams on deadlines and deliverables.
Skilled at presenting complex audit or risk topics to executive leadership using concise, data-driven insights.
Capable of drafting clear, audit-ready documentation and control narratives without excessive bureaucracy.
Automation-first: Seeks opportunities to replace manual audit processes with system-driven controls.
Business-aligned: Understands how to balance compliance requirements with engineering velocity.
Outcome-driven: Measures success through reduced audit fatigue, improved evidence hygiene, and faster remediation cycles.
Collaborative: Builds trust with auditors and internal stakeholders through transparency and consistency.
Benefits
Maven Fertility
We offer a $10,000 lifetime benefit opportunity to all employees and their partners around the world. This benefit can be used to support your reproductive journey - from abortion care and related travel costs to fertility treatment, egg-freezing, adoption, surrogacy, and more.
Family & compassionate paid leave
Family leave to support you and your loved ones when needed (including victims of domestic abuse or violent crime).
26 weeks parental leave
26 weeks paid leave for the primary caregiver following the birth, adoption, surrogacy or foster care of a child. The secondary caregiver will also receive 26 weeks paid leave after 1 year of employment.
Unlimited paid time off
Take the time you need when you need it.
Company-wide week off
Once a year, we have a company-wide week off (it’s essential for some teams to continue working and they will be offered alternative time off instead).
Focus Fridays
Every Friday we try to have a no meeting, no deadline, no email and no Slack rule on a Friday so you can focus without distraction.
Program Manager for Remote Patient Monitoring responsible for operational, financial, and clinical oversight at Essen Health Care. Leading a team to improve patient outcomes and efficiency.
Program Manager, Marketing at Baseten overseeing operational execution of marketing initiatives. Driving campaign execution and cross - functional alignment in a rapidly growing AI company.
Program Manager III at CrowdStrike overseeing large - scale infrastructure initiatives in cybersecurity. Collaborating with engineering teams to ensure timely execution and communication across global teams.
Program Manager driving geographic expansion strategies within MedTech surgery. Leading project execution while maintaining collaboration across diverse teams and stakeholders.
Program Manager driving healthcare technology innovations as a core member of the systems PMO team. Focused on design, usability, and safety validation of robotic systems with team collaboration and Agile methodology.
Senior Program Manager for DLA spares portfolio at Boeing ensuring USAF platform readiness. Leading execution of transactional spares and Performance - Based Logistics programs.
Solutions Programme Manager responsible for managing GIS tooling solutions and driving customer outcomes at Computacenter. Collaborating with stakeholders and supporting pre - sales engagements in a hybrid environment.
Principal Program Manager overseeing strategic delivery and project implementation at PointClickCare, a health tech leader. Responsible for managing client relationships and project alignment with transformation objectives.
Clinical Program Director overseeing treatment of clients in AMFM Healthcare’s programs. Leading therapeutic programming and clinical supervision while ensuring compliance with regulations and best practices.
Mobile WorkSource Services Analyst providing workforce services directly to underserved communities in Oregon. Driving a Mobile Job Center and offering high - quality employment services and outreach initiatives.