
Manager, Security Governance & Risk
Job description
About the role
You will own the end-to-end security governance, risk, and compliance program for Emburse, shaping the strategy and operating model that underpins how the company identifies, measures, and communicates enterprise security risk. In this people-leadership position, you will guide a team of GRC professionals, overseeing the day-to-day execution of audits and assessments while ensuring the team operates with autonomy and quality. You will be responsible for establishing and maintaining robust governance for AI use across both our AI-enabled products and internal AI applications, ensuring controls keep pace with innovation. A core part of your role will involve translating complex control and risk data into clear, decision-ready reporting for executives and the Board, providing credible insight that drives informed action. You will own the configuration, data integrity, and automation strategy for the GRC platform, setting standards that ensure consistency and reliability as the business scales. This role requires genuine analytical rigor to turn raw risk metrics into actionable intelligence that strengthens Emburse's financial operations and modernized spend ecosystem. You will partner closely with technology, product, and finance leaders to embed security governance into the fabric of the business, making it a strategic enabler rather than a compliance checkpoint. Ultimately, you will mature how Emburse manages security risk, building a program that is transparent, accountable, and trusted by customers, stakeholders, and the Board.
Key facts
What you'll do
Lead the development, execution, and continuous improvement of Emburse's enterprise security governance, risk, and compliance framework, aligning it with industry standards and business objectives.
Define and evolve the GRC operating model, including role clarity, workflows, and escalation paths, to ensure the function operates efficiently and scales with the growth of AI initiatives.
Own the governance of AI use across product and internal environments, establishing controls, policies, and monitoring mechanisms specific to AI-driven services and data.
Establish and maintain configuration standards, data integrity protocols, and automation roadmaps for the GRC platform to reduce manual effort and improve reporting reliability.
Create decision-ready security metrics and risk reporting for executives and the Board, synthesizing complex control outcomes into clear narratives and trend analyses.
Partner with technology and product teams to integrate security governance into the software development lifecycle, ensuring risk considerations are addressed early and often.
Manage the end-to-end audit execution through a team of GRC professionals, providing direction, quality assurance, and professional development to maintain high standards of audit coverage.
Define and implement a risk-based metrics framework that measures the effectiveness of security controls, highlighting areas of strength and opportunities for improvement.
Collaborate with legal, compliance, and internal audit stakeholders to ensure alignment with regulatory requirements and emerging frameworks relevant to AI and financial operations.
Champion the use of process intelligence and analytics to identify inefficiencies in governance workflows and drive targeted improvements across the GRC function.
Act as the primary point of contact for enterprise risk discussions, articulating the security posture and risk trends in a way that is accessible and actionable for non-technical audiences.
Drive the adoption of governance tools and methodologies, coaching stakeholders on their use and ensuring consistent application across teams and initiatives.
Identify gaps in existing control frameworks and propose pragmatic enhancements that balance security rigor with business agility in a fast-moving AI landscape.
Champion a culture of continuous learning and accountability within the GRC team, encouraging curiosity, rigorous analysis, and proactive risk management.
Requirements
Must have a Bachelor's degree in a relevant field or equivalent practical experience, demonstrating foundational knowledge in risk management, security, or a related discipline.
Bring 8+ years of progressive experience in security governance, risk, or compliance roles, with a track record of managing complex GRC programs in a professional services or technology environment.
Possess deep, credible experience in security and enterprise risk management, including the ability to apply risk frameworks, assess control effectiveness, and interpret risk metrics for executive consumption.
Have proven experience owning and maturing GRC functions, including the design of operating models, governance frameworks, and the oversight of internal audit execution.
Demonstrate hands-on expertise with AI governance, including the ability to establish controls, policies, and metrics specific to AI use in product and operational environments.
Show a strong history of creating and maintaining security metrics, risk reports, and governance dashboards that influence decision-making and board-level conversations.
Must have experience configuring and governing GRC platforms, including attention to data integrity, automation opportunities, and standard-setting for controls and evidence.
Have collaborated with technology and product teams to embed security practices into product development, cloud adoption, and digital transformation initiatives.
Nice to have
Experience with modern expense management or financial operations platforms is a plus, given Emburse's focus on intelligent spend solutions.
Familiarity with AI-specific risk frameworks, such as those addressing model risk, data privacy, or regulatory considerations in emerging technologies.
Background working with Board-level or executive stakeholders, translating technical risk concepts into clear, strategic narratives.
Practical notes
This is a full-time role based in Dallas, TX.
Candidates must be eligible to work in the United States without sponsorship at this time.
The role reports to a senior leader within Emburse's growing Security and Risk organization.