bluedoor data·Job Postings API·bluedoor.sh ↗

HomeCompaniesAstraGRC Program Manager

GRC Program Manager

Astra · Remote - US Only · Remote · Active · Ashby

Job facts

FieldValue
CompanyAstra
TitleGRC Program Manager
Normalized title-
Department / teamOperations / Operations, Compliance
LocationUnited States
Work modelRemote / Remote
Employment typeFull Time
Salary-
Statusactive
ATS providerAshby
Posted / first seen / 2026-05-29
Changed / last seen2026-05-29 / 2026-06-19

Related slices

PageWhat it containsOpen
Company jobsActive postings from Astra.Open
Company breakdownsRole, location, ATS, and work model facets for this company.Open
ATS provider jobsActive postings observed through Ashby.Open
Provider filtered searchThe same provider as a filtered job collection.Open
Department jobsActive postings in Operations.Open
Work model jobsActive Remote postings.Open
Lifecycle eventsOpen, update, close, and reopen events for this posting.Open
Original postingCanonical source or apply URL captured from the ATS.Open

Linked records

CompanyAstra
Sourcef50f4a32-48bf-466a-a4de-8137e89fb87d
ATS providerAshby

Description

About Astra Astra is building mission-critical infrastructure for moving money at scale. Our platform processes billions in annual transaction volume with 99.9%+ uptime, powering real-time transfers, bank debits, card disbursements, and complex financial compliance systems. We provide APIs and automation tools that enable businesses to move money programmatically while maintaining strict regulatory requirements. The Role As Astra’s first dedicated GRC Program Manager, you will be at the center of how we build trust, scale responsibly, and operate with regulatory excellence. This is more than a traditional compliance role – it’s an opportunity to design the governance, risk, and compliance foundation that enables Astra to grow quickly while meeting the expectations of banks, enterprise customers, auditors, and regulators. You’ll own the full spectrum of Astra's audit execution: driving SOC 1, SOC 2, PCI DSS, and ISO 27001 programs end-to-end, translating regulatory requirements into practical technical controls, building high-quality documentation and evidence, and helping teams embed security and compliance into everyday operations. You’ll partner closely with engineering and infrastructure teams to ensure controls are real, automated where possible, and aligned with how the platform actually runs. Because this is an early hire on the compliance team, you’ll have direct input into how Astra structures its audit programs, risk management processes, vendor due diligence workflows, and compliance tooling. You’ll collaborate with leaders across engineering, product, operations, and leadership to build scalable systems that reduce friction while increasing assurance and visibility. This role is perfect for someone who enjoys rolling up their sleeves to execute today while also designing durable systems for tomorrow – someone who sees compliance not as a checkbox exercise, but as a strategic advantage for building trusted financial infrastructure. What You’ll Do Audit Execution & Readiness: Own day-to-day execution of SOC 1, SOC 2, PCI DSS, and ISO 27001 readiness and audit cycles – including scoping, control testing, evidence collection, auditor coordination, and remediation tracking. Control Design & Documentation: Develop and maintain policies, procedures, risk assessments, control narratives, and supporting documentation that meet auditor expectations and scale with the business. Cross-Framework Mapping: Map controls across SOC, ISO, PCI, and NIST frameworks to identify overlap, gaps, automation opportunities, and control maturity improvements. Risk Management: Facilitate risk assessments for systems, vendors, products, and business initiatives. Maintain risk registers, mitigation plans, and executive reporting on residual risk. Engineering Partnership: Partner with engineering and infrastructure teams to translate security requirements into practical technical controls across cloud infrastructure, SDLC, access management, logging, monitoring, and incident response. Vendor Risk Management: Manage vendor security reviews, questionnaires, evidence validation, risk scoring, and ongoing monitoring for critical third parties and partners. Customer Trust & Due Diligence: Support customer security reviews, security questionnaires, and trust documentation that enable enterprise sales and bank partnerships. Continuous Compliance: Help build scalable compliance workflows, tooling, and automation to reduce manual effort and improve evidence quality as Astra grows. Metrics & Reporting: Maintain dashboards and reporting on audit status, control health, remediation progress, and risk posture for leadership. What We’re Looking For Required Experience 3–6+ years of experience in governance, risk, compliance, audit, or information security rolls. Hands-on experience supporting or leading SOC 1 and/or SOC 2 audits ; experience with PCI DSS and ISO 27001 is strongly preferred. Strong working knowledge of compliance frameworks (SOC, ISO 27001, NIST CSF, PCI DSS) and how controls operate in practice. Experience working cross-functionally with engineering, product, and operations teams in a technical environment. Proven ability to build and maintain high-quality documentation, evidence, and audit artifacts. Comfort operating in fast-moving environments where priorities evolve and ambiguity is common. Ambition to structure and systems 0 to 1, and comfort in creating frameworks, templates, and playbooks that scale. Experience collaborating with Product, Sales, and Engineering teams to align on priorities and drive outcomes. Education Bachelor’s degree in Information Systems, Computer Science, Business, Risk Management, or related field (or equivalent practical experience). Preferred Experience Fintech / Payments: Experience operating in regulated environments involving payments, banking partners, PCI, or financial audits. ISO 27001: Experience supporting certification or operating within an ISO-aligned ISMS. Automation & Tooling: Experience implementing compliance tooling, evidence automation, or GRC platforms. Vendor Risk Programs: Hands-on ownership of third-party risk management workflows. Startup Environment: Experience building or scaling compliance programs in high-growth companies. Key Skills Audit Operations: Scoping, walkthroughs, evidence management, remediation tracking, auditor coordination. Control Design: Ability to translate regulatory requirements into clear, testable, and scalable controls. Risk Assessment: Experience performing system, vendor, and operational risk assessments with structured methodologies. Technical Fluency: Working understanding of cloud infrastructure, identity and access management, logging, monitoring, SDLC, and security tooling. Documentation & Writing: Strong ability to produce clear policies, procedures, narratives, and evidence artifacts. Project Management: Ability to manage multiple parallel audits, initiatives, and stakeholders while maintaining quality and deadlines. Communication: Ability to explain complex compliance concepts clearly to engineers, auditors, leadership, and external partners. Operational Rigor: Highly organized with strong attention to detail and follow-through. Why This Role Matters Trust is foundational to everything Astra builds. Our customers, bank partners, and regulators depend on the strength of our control environment, operational discipline, and risk management practices. As a GRC Program Manager, your work will directly: Enable Astra to scale responsibly while maintaining strong audit outcomes and regulatory credibility. Reduce friction for engineering and product teams by building clear, pragmatic compliance processes. Support enterprise sales and partnerships by strengthening customer trust and security posture. Improve operational maturity through automation, documentation quality, and continuous improvement. This role is not just about passing audits – it’s about building durable infrastructure that allows Astra to grow faster and more confidently. What We Offer Competitive compensation with equity in a growing fintech company. Remote-first culture with flexible working arrangements Small team, big impact — your work directly supports Astra’s ability to scale responsibly Professional growth opportunities in compliance and risk management Mission-driven — build infrastructure that powers financial innovation while meeting the highest regulatory standards Remote Work and Culture Astra is a remote-first company hiring only within the U.S. We value thoughtful collaboration, clarity, and initiative. We’re proud to be an equal opportunity employer and are committed to building a diverse and inclusive team. How to Apply If you thrive on building structure, improving systems, and enabling teams to move fast while managing risk, we’d love to hear from you. Please submit: Resume highlighting relevant audit, compliance, and risk program management experience. Brief cover letter (300 words max) answering: “Describe a compliance, audit, or risk initiative you owned end-to-end. What problem were you solving, and what impact did it have?” Optional: Sample documentation (control narrative, audit artifact, or process design) demonstrating clarity and rigor.

Full job record

Job ID41dd9b5334991ae849df7f4259ce98fe42847d42
Org IDc3b821b8-426d-4f43-860b-0521ea8c7dd5
Source IDf50f4a32-48bf-466a-a4de-8137e89fb87d
Board IDf50f4a32-48bf-466a-a4de-8137e89fb87d
Providerashby
Provider Job Keye35fb02e-d868-4b4d-acf3-2af734237406
TitleGRC Program Manager
Normalized Title
Statusactive
Activeyes
Location TextRemote - US Only
DepartmentOperations
TeamOperations, Compliance
Employment Typefull_time
Workplace Typeremote
Remote Policyremote
CountryUnited States
Region
City
Salary Raw
Salary Min
Salary Max
Salary Currency
Salary Period
Source URLhttps://jobs.ashbyhq.com/astra/e35fb02e-d868-4b4d-acf3-2af734237406
Apply URLhttps://jobs.ashbyhq.com/astra/e35fb02e-d868-4b4d-acf3-2af734237406/application
First Seen At2026-05-29 07:07:05Z
Last Seen At2026-06-19 09:49:23Z
Last Checked At2026-06-19 09:49:23Z
Last Changed At2026-05-29 07:07:05Z
Inactive At
Source Posted At
Source Updated At
Raw Payload Uris3://job-postings-prod-raw-590183727216/raw/provider=ashby/board=astra/date=2026-06-19/2026-06-19T09-49-21-426Z-33291071e8a6ccaa661e642fa538408239397cb85ef9f60437ce25e6ea446d8f.json
Event Fields
{
  "content_hash": "7972ea14d05b35b991951af4c511b6781d2ae363cda60772eff05b6cbe80fb31",
  "source_hash": "332562d1cb53ef295e9fdae3636d0e9030e857869ecb065ef568275ec4737e67",
  "last_changed_at": "2026-05-29T07:07:05.142Z",
  "active_status": "active"
}
Parsed Structured
{
  "language": "en",
  "location": {
    "raw": "Remote - US Only",
    "city": null,
    "region": null,
    "country": "United States",
    "is_remote": true,
    "confidence": 0.95
  },
  "salary_max": null,
  "salary_min": null,
  "inferred_at": "2026-06-19T09:49:23.986Z",
  "launch_scope": {
    "reason": "english_us_canada",
    "included": true,
    "language": "en",
    "location": {
      "raw": "Remote - US Only",
      "city": null,
      "region": null,
      "country": "United States",
      "is_remote": true,
      "confidence": 0.95
    },
    "countries": [
      "United States"
    ]
  },
  "remote_policy": "remote",
  "salary_period": null,
  "workplace_type": "remote",
  "salary_currency": null
}
Extensions
{}
Native Structured
{
  "id": "e35fb02e-d868-4b4d-acf3-2af734237406",
  "team": "Operations, Compliance",
  "title": "GRC Program Manager",
  "jobUrl": "https://jobs.ashbyhq.com/astra/e35fb02e-d868-4b4d-acf3-2af734237406",
  "address": null,
  "applyUrl": "https://jobs.ashbyhq.com/astra/e35fb02e-d868-4b4d-acf3-2af734237406/application",
  "isListed": true,
  "isRemote": true,
  "location": "Remote - US Only",
  "updatedAt": null,
  "apiVersion": "ashby-non-user-graphql-v1",
  "department": "Operations",
  "publishedAt": null,
  "workplaceType": "Remote",
  "employmentType": "FullTime",
  "secondaryLocations": []
}
Get this page with API

Rendered from the bluedoor Job Postings API. Reproduce it:

GET https://api.bluedoor.sh/job-postings/v1/jobs/41dd9b5334991ae849df7f4259ce98fe42847d42?include=descriptionJSON
GET https://api.bluedoor.sh/job-postings/v1/orgs/c3b821b8-426d-4f43-860b-0521ea8c7dd5JSON
GET https://api.bluedoor.sh/job-postings/v1/sources/f50f4a32-48bf-466a-a4de-8137e89fb87dJSON
GET https://api.bluedoor.sh/job-postings/v1/jobs/41dd9b5334991ae849df7f4259ce98fe42847d42/eventsJSON