Sr. Governance, Risk, and Compliance Lead

1 Month ago • 5 Years + • Risk Management • $136,250 PA - $175,000 PA

Job Summary

Job Description

Upwork is seeking a Sr. Lead, Governance, Risk, and Compliance (GRC) to enhance its Information Security program by managing audit readiness and compliance across global frameworks and vendor requirements. This role involves influencing security strategy and collaborating across departments to ensure Upwork adheres to high standards of data security and privacy, safeguarding the platform for millions of users. The Lead will manage audits for ISO 27001 and SOC 2 Type 2, maintain the Information Security Management System (ISMS), and track enterprise risks and compliance metrics.
Must have:
  • 5+ years experience in GRC, Information Security, or Compliance
  • Expertise with ISO 27001, SOC 2, and Microsoft SSPA
  • Managed end-to-end audit processes
  • Strong project management, communication, and analytical skills
  • Cross-functional compliance initiative experience
Good to have:
  • Experience in a technology or cloud-first environment
  • Certifications like CISA, CRISC, or ISO 27001 Lead Auditor/Implementer
Perks:
  • Comprehensive medical coverage
  • Unlimited PTO
  • 401(k) plan with matching
  • 12 weeks paid parental leave
  • Employee Stock Purchase Plan

Job Details

Upwork ($UPWK) is the world’s largest work marketplace, connecting businesses with highly skilled professionals worldwide. From entrepreneurs to Fortune 100 enterprises, companies trust Upwork’s platform to access expert talent, leverage AI-powered work solutions, and drive meaningful business outcomes.

Upwork’s AI-powered platform has facilitated over $20 billion in economic opportunity for professionals worldwide. With professionals spanning 10,000+ skills, including AI and machine learning, software development, sales and marketing, customer support, finance and accounting, and more, Upwork empowers businesses of all sizes to scale, innovate, and build agile teams.


We are looking for a Sr. Lead, GRC (Governance, Risk, and Compliance) to strengthen Upwork’s Information Security program by leading audit readiness and compliance operations across global frameworks and vendor requirements. This is an exciting opportunity to influence security strategy and work cross-functionally to ensure that Upwork meets the highest standards in data security and privacy. Join us in safeguarding our platform and enabling trust at scale for millions of users around the world.

As part of the Information Security team, you'll guide audit processes for ISO 27001, SOC 2 Type 2, and Microsoft SSPA, ensure that our ISMS and internal controls are up to date, and provide strategic insights into risk and compliance operations. Your work will support core business functions and help advance our enterprise-grade security posture.

Responsibilities

  • Lead and manage internal and external audits for ISO 27001 and SOC 2 Type 2, including evidence collection, readiness assessments, and remediation tracking

  • Own Upwork’s compliance with Microsoft Supplier Security and Privacy Assurance (SSPA), including completing the annual DPR and attestation

  • Maintain and evolve the Information Security Management System (ISMS) and associated documentation to reflect Upwork’s growing business and risk landscape

  • Collaborate with Engineering, IT, Legal, and Privacy teams to implement controls and address identified gaps efficiently and effectively

  • Monitor and report on the enterprise risk register, audit findings, and key compliance metrics to drive transparency and accountability

  • Act as the primary point of contact for auditors, assessors, and external stakeholders during audits and customer due diligence activities

  • Track and interpret changes in regulatory and compliance frameworks to guide proactive adaptation and policy updates

What it takes to catch our eye

  • 5+ years of experience in GRC, Information Security, or Compliance, ideally in a technology or cloud-first environment

  • Proven expertise with ISO 27001, SOC 2, and third-party compliance programs like Microsoft SSPA

  • Demonstrated success managing end-to-end audit processes and cross-functional compliance initiatives

  • Strong project management, communication, and analytical skills with a track record of influencing cross-functional stakeholders

  • Relevant certifications such as CISA, CRISC, or ISO 27001 Lead Auditor/Implementer are a plus


Come change how the world works.

At Upwork, you’ll shape the future of work for a global, remote-first workforce, creating economic opportunities for professionals worldwide. While we have a physical office in Palo Alto, we currently hire full-time employees in 21 U.S. states, making it easier than ever to join our mission from wherever you call home.

Our culture is built on trust, risk-taking, customer focus, and excellence, all in service of our core mission: to create economic opportunities so people have better lives. We embrace authenticity and inclusion, encouraging everyone to bring their whole selves to work. Personal and professional growth is a priority here, supported through development programs, mentorship, and our Upwork Belonging Communities.

We’re proud to offer benefits that go beyond the basics, including comprehensive medical coverage for you and your family, unlimited PTO, a 401(k) plan with matching, 12 weeks of paid parental leave, and an Employee Stock Purchase Plan. Visit our Life at Upwork page to learn more about our values, working principles, and the overall employee experience.

Ready to help shape the future of work? Check out our Careers page and follow us on LinkedIn, Facebook, Instagram, TikTok, and X. to learn more about life at Upwork.

Upwork is an Equal Opportunity Employer committed to recruiting and retaining a diverse and inclusive workforce. We do not discriminate based on race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, or other legally protected characteristics under federal, state, or local law.

Please note that a criminal background check may be required once a conditional job offer is made. Qualified applicants with arrest or conviction records will be considered in accordance with applicable law, including the California Fair Chance Act and local Fair Chance ordinances.

 

The annual base salary range for this position  is displayed below. The range displayed reflects the minimum and maximum salary for this position, and individual base pay will depend on your skills, qualifications, experience, and location. Additionally, this position is eligible for the annual bonus plan or sales incentive plan and eligibility to participate in our long term equity incentive program.

Annual Base Compensation

$136,250 - $175,000 USD

To learn more about how Upwork processes and protects your personal information as part of the application process, please review our Global Job Applicant Privacy Notice

Similar Jobs

dun bradstreet - Senior Product Manager, Go-To-Market

dun bradstreet

London, England, United Kingdom (Hybrid)
1 Month ago
Moloco - Senior Data Scientist, Growth Analytics

Moloco

Tel Aviv-Yafo, Tel Aviv District, Israel (On-Site)
2 Months ago
P99 soft - Lead Java Developer

P99 soft

Hyderabad, Telangana, India (On-Site)
3 Months ago
Trend Micro - (Sr.) Software Engineer in Windows Agent

Trend Micro

Taipei City, Taiwan (On-Site)
1 Month ago
Armada - Senior Software Engineer

Armada

Thiruvananthapuram, Kerala, India (On-Site)
9 Months ago
Ion - Senior Risk Analyst, Italy

Ion

Collecchio, Emilia-Romagna, Italy (On-Site)
9 Months ago
PwC - Risk Assurance Information Technology Trainee

PwC

Makati City, Metro Manila, Philippines (On-Site)
10 Months ago
OKX - Head of Risk, EEA

OKX

Sliema, Malta (On-Site)
3 Weeks ago
Aledade - Senior Director, Risk Performance

Aledade

Bethesda, Maryland, United States (Remote)
1 Month ago
Monzo - Risk & Control Manager

Monzo

Dublin, County Dublin, Ireland (On-Site)
2 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Sword Health - AP Staff Accountant

Sword Health

Porto, Porto District, Portugal (Hybrid)
1 Month ago
Ethos Life - Head of Product Design, Consumer

Ethos Life

United States (Remote)
3 Months ago
Crowd Strick - Services Partner Manager, APJ

Crowd Strick

Singapore (Remote)
1 Year ago
Axon - Director of Operations

Axon

Ho Chi Minh City, Vietnam (Hybrid)
3 Weeks ago
Salesforce - Partner Business Manager

Salesforce

Singapore (Hybrid)
1 Month ago
CommerceIQ - Software Development Engineer II - UI

CommerceIQ

Bengaluru, Karnataka, India (On-Site)
1 Month ago
Accenture - AI / ML Engineer

Accenture

Pune, Maharashtra, India (On-Site)
2 Weeks ago
Sailpoint - Senior Staff DevOps Engineer

Sailpoint

Austin, Texas, United States (On-Site)
2 Months ago
PayPal - Compliance Manager

PayPal

Scottsdale, Arizona, United States (Hybrid)
2 Weeks ago
Monzo - Financial Reporting Analyst

Monzo

Dublin, County Dublin, Ireland (On-Site)
3 Weeks ago

Get notifed when new similar jobs are uploaded

Jobs in United States

Naughty Dog - Producer

Naughty Dog

Santa Monica, California, United States (On-Site)
2 Months ago
Plaid  - Engineering Manager - Money Movement & Partnerships

Plaid

San Francisco, California, United States (On-Site)
4 Months ago
Luma - Account Executive – Brands

Luma

Palo Alto, California, United States (Hybrid)
3 Weeks ago
Marvell - Hardware & Silicon Validation Senior Staff Engineer

Marvell

Santa Clara, California, United States (On-Site)
2 Weeks ago
Niantic - Software Engineer, Server

Niantic

Sunnyvale, California, United States (Hybrid)
3 Weeks ago
Alpha Sense - Senior Software Engineer

Alpha Sense

United States (Remote)
2 Months ago
Interface AI - Staff Backend Engineer - Data

Interface AI

San Francisco, California, United States (On-Site)
1 Month ago
Discord - Workplace Operations Specialist, Analytics

Discord

San Francisco, California, United States (On-Site)
2 Months ago
rivos - Senior Power-Management Architect

rivos

Santa Clara, California, United States (Hybrid)
7 Months ago
Trailer park group - Strategist - RPG Social

Trailer park group

Los Angeles, California, United States (Remote)
3 Months ago

Get notifed when new similar jobs are uploaded

Risk Management Jobs

logifuture - Junior Risk and Payments Analyst

logifuture

Bucharest, Romania (Hybrid)
2 Weeks ago
Aledade - Senior Director, Impact Analytics - Risk Adjustment

Aledade

United States (Remote)
4 Weeks ago
Yodlee - Information Security Risk Management Director

Yodlee

Berwyn, Pennsylvania, United States (Hybrid)
4 Months ago
Visa - Head of Risk Consulting, Visa Consulting & Analytics, CISSEE

Visa

Almaty, Almaty Region, Kazakhstan (On-Site)
9 Months ago
bytedance - Payment Risk Strategy Expert

bytedance

Singapore (On-Site)
5 Months ago
PwC - Risk Assurance-IT Senior Associate

PwC

Makati City, Metro Manila, Philippines (On-Site)
10 Months ago
bytedance - Risk Control Business Partner

bytedance

Singapore (On-Site)
3 Months ago
Gree - Group Risk Management/Subsidiary Management (Manager Candidate)

Gree

Tokyo, Japan (On-Site)
2 Months ago
luxsoft - Murex Credit Risk Consultant (report development)

luxsoft

Singapore (On-Site)
2 Months ago
Zscaler - Sr Staff, Security Third Party Risk Management

Zscaler

Costa Rica (Remote)
2 Months ago

Get notifed when new similar jobs are uploaded