Manager, IT Governance, Risk & Compliance; Remote - West Coast
Walnut Creek, Contra Costa County, California, 94598, USA
Listed on 2026-03-04
-
IT/Tech
Cybersecurity, IT Consultant -
Finance & Banking
With a company culture rooted in collaboration, expertise and innovation, we aim to promote progress and inspire our clients, employees, investors and communities to achieve their greatest potential. Our work is the catalyst that helps others achieve their goals. In short, We Enable Possibility℠.
Job SummaryThe Manager, IT Governance, Risk & Compliance (GRC) supports the Arch Global Mortgage business by executing governance, risk, and compliance activities related to technology, security, and regulatory obligations. This role serves as a primary execution and coordination point between Arch Global Mortgage stakeholders, Arch technology and security teams, customers, and regulators. The position focuses on intake, analysis, coordination, and drafting of Arch Global Mortgage‑related materials, working in close partnership with the VP, Chief Information Security Officer.
WorkArrangement
This is a fully remote U.S.
-based role. Candidates located on the U.S. West Coast are strongly preferred, as the position requires regular overlap with both U.S. stakeholders and the Arch Global Mortgage team in Sydney, Australia.
- Serve as a primary point of contact for Arch Global Mortgage originating requests related to technology risk, security controls, customer audits, and regulatory inquiries.
- Interface with international Arch Global Mortgage stakeholders to understand regulatory, customer, and business drivers.
- Triage incoming requests, identify appropriate subject‑matter experts, coordinate inputs, and track responses to completion.
- Draft and prepare regulatory responses, customer communications, and supporting materials for review, refinement, and approval by the CISO.
- Develop background analysis, control narratives, and documentation used to support external responses.
- Create and maintain regulatory‑to‑control mappings demonstrating alignment between Arch Global Mortgage requirements and Arch technology and security controls.
- Interpret Arch policies, standards, and control frameworks for Arch Global Mortgage‑specific use cases and elevate gaps or ambiguities.
- All external regulatory or customer responses are routed through senior leadership rather than independently positioned, particularly during the first 18–24 months.
- Support relevant SOC 2 engagements and other audit activities by coordinating evidence collection, drafting control descriptions and response inputs, and managing requests from auditors and internal teams.
- This role contributes to execution and preparation but does not independently own audit positioning or conclusions.
- Maintain working familiarity with business continuity and disaster recovery (BC/DR) concepts relevant to Arch Global Mortgage.
- Support BC/DR governance activities, documentation updates, testing preparation, and related audit, customer, or regulatory requests.
- Partner with the CISO to establish and maintain a calendar of recurring Arch Global Mortgage governance, compliance, and reporting activities.
- Draft metrics, summaries, and artifacts used for senior leadership discussions and board or committee materials.
- Surface risks, control gaps, and areas of uncertainty clearly and promptly to support prioritization decisions.
- Experience in IT governance, risk, compliance, or security risk management within financial services or insurance.
- Experience working with global or non‑U.S. regulated businesses strongly preferred.
- Experience supporting customer audits and third‑party risk management (TPRM) programs, particularly with banks or large financial institutions.
- Prior technical background sufficient to understand, assess, and question technology and security controls.
- Strong written communication skills, with experience drafting materials intended for external review.
- Familiarity with SOC 2 and BC/DR concepts required (ownership experience not required).
- Ability to work across time zones; U.S. West Coast preferred but negotiable, with willingness to overlap with…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).