Quest Software
Senior Manager, Global GRC and Privacy

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Overview
Quest is an award-winning IT management software provider offering a broad selection of solutions that solve some of the most common and most challenging IT problems. Quest strives to be the best of the very best in everything we do. We are fanatically customer-focused and are proud to support the most complex customers who have the highest IT demands in the world. It’s exciting, it’s rewarding, it’s hard work, and offers career and personal growth.
At Quest Software, we build technology that simplifies IT management and strengthens cybersecurity resilience for organizations around the world. Our people are central to our success, and we are committed to delivering an HR experience that reflects our global footprint, growth mindset, and employee-first culture.
About the Role
The Senior Manager, Global IT Governance, Risk, Compliance (GRC), and Privacy will lead Quest’s IT GRC and privacy function for a global software organization. This leader will own enterprise risk governance, audit readiness, privacy control alignment, and compliance operations across complex regulatory, customer, and certification environments. The role requires an experienced, hands-on leader who can guide strategy, improve control maturity, influence senior stakeholders, and manage a team of two direct reports while reporting to the Head of Cybersecurity and Privacy.
This role is intended for candidates with demonstrated success leading mature GRC, privacy, audit, and risk management programs in global software, SaaS, technology, or similarly regulated environments. The successful candidate will be comfortable operating at both strategic and execution levels, setting expectations with senior stakeholders, driving accountability across distributed teams, and maintaining a high standard of follow-through in a fast-moving business.
Responsibilities
Governance Management
- Lead the creation, maintenance, implementation, communication, and enforcement of IT policies, standards, and procedures across the global organization.
- Drive adoption of IT policies, standards, and procedures by partnering with stakeholders to clarify expectations, monitor compliance, and address implementation barriers.
- Lead and mature the global security awareness program, including program strategy, communications, training content, metrics, and continuous improvement.
Risk Management
- Own and mature the enterprise IT risk register, including risk identification, scoring, treatment planning, executive-level reporting, and timely follow-up with accountable risk owners.
- Lead and continuously improve third-party risk assessment processes, including assessment intake, risk analysis, stakeholder follow-up, reporting, and process maturity.
- Assist Security Engineering with development and management of insider threat risk mitigation controls.
- Partner with Legal, Security Engineering, and other internal teams on legal hold, eDiscovery, and data security investigations that require GRC, privacy, or control expertise.
- Identify recurring problems and risks and recommend proactive measures to mitigate.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Compliance Management
- Orchestrate annual maintenance, readiness, evidence collection, and external audit support for NIST Cybersecurity Framework, ISO 27001, ISO 27017, ISO 27018, ISO 27701, ISO 42001, SOC, and other applicable customer, regulatory, and certification requirements across the organization.
- Lead the documentation, assessment, testing, and measurement of control design and operating effectiveness consistent with NIST, ISO, SOC, privacy, and customer assurance requirements.
- Maintain awareness of laws, rules, and regulations governing IT risk, compliance, audit, privacy, and security in the Quest environment for the markets in which Quest operates.
- Lead the evaluation, selection, implementation, configuration, adoption, and continuous improvement of GRC tools, workflows, reporting, and automation capabilities.
- Identify, assess, and prepare Quest for emerging audit, assurance, regulatory, and governance requirements, including SOX readiness, AI governance, privacy obligations, and customer-driven compliance expectations.
Additional Activities
- Develop, maintain, and execute a multi-year GRC and privacy roadmap that aligns with business priorities, customer commitments, regulatory obligations, audit requirements, and security strategy.
- Use market research, stakeholder feedback, and analytic data to understand business needs and identify new requirements.
- Lead, coach, and hold accountable a small team of GRC and privacy professionals, setting clear priorities, developing talent, reviewing work quality, and ensuring timely delivery of commitments.
Qualifications
- 12+ years of progressive experience in IT GRC, information security, privacy, technology risk, internal audit, or external audit.
- Hands-on experience with assessing, selecting, implementing, and administering GRC tools/software including workflow design.
- Deep working knowledge of NIST CSF, ISO27001, 27017, 27018, 27701, 42001, GDPR, and SOC2 frameworks.
- Proven ability to communicate complex risk, compliance, privacy, and audit topics clearly to executives, technical teams, legal partners, auditors, customers, and non-technical stakeholders.
- Demonstrated record of sustained ownership, professional judgment, accountability, and follow-through in roles requiring confidential information handling, audit deadlines, cross-functional dependency management, and high-quality deliverables.
- Active professional certification(s) related to information security or information risk management (i.e. CISA, CRISC, CIPP/US/EU, CISSP, CISM).


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Company Overview
Quest Software builds the foundation for enterprise AI with solutions in data governance, cybersecurity, and platform modernization. More than 45,000 companies — including 90% of the Fortune 500 — trust Quest to solve their most critical IT challenges. From securing identities and modernizing platforms to preparing data for AI, we help enterprises unlock their full potential.
Why Quest
At Quest, your work makes an impact. You’ll help organizations get AI-ready while building your career with a global team of innovators. We offer:
- Competitive pay, annual bonuses, and top-performer recognition.
- Comprehensive health, family, and retirement benefits.
- Flexible work options, generous PTO, and wellness programs.
- Professional growth through learning platforms, mentorship, and leadership programs.
- Inclusive teams that reflect the world we serve, supported by Employee Resource Groups and our Equality & Inclusion Council.
Equal Opportunity Employer
Quest is an Equal Opportunity Employer and Prohibits Discrimination and Harassment of Any Kind: Quest is committed to the principle of equal employment opportunity for all employees and to providing employees with a work environment free of discrimination and harassment. All employment decisions at Quest are based on business needs, job requirements, and individual qualifications, without regard to race, color, religion or belief, national, social or ethnic origin, sex (including pregnancy), age, physical, mental or sensory disability, HIV Status, sexual orientation, gender identity and/or expression, marital, civil union or domestic partnership status, past or present military service, family medical history or genetic information, family or parental status, or any other status protected by the laws or regulations in the locations where we operate. Quest will not tolerate discrimination or harassment based on any of these characteristics. Quest encourages applicants of all ages.
Come Join Us
For more information, visit us on the web at Quest Careers | Innovate. Collaborate. Grow.
Job seekers should be aware of fraudulent job offers from online scammers and only apply to roles listed on quest.com/careers using our applicant system. Note: We do not use text messaging or third-party messaging apps like Telegram to communicate with applicants, so please exercise caution if you are approached in this way and only interact with people claiming to be Quest employees if they have an email address ending in @quest.com. You can report job scams to the FTC (ReportFraud.ftc.gov) or your state attorney general.
#LI-CJ
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills