Fortress Information Security is seeking a Senior Product Manager - GRC to own and evolve their Governance, Risk, and Compliance (GRC) platform. This role involves leading product management efforts, collaborating with cross-functional teams, and defining a compelling product vision and strategy to drive growth and customer value.
Responsibilities:
- Lead the product vision and roadmap for governance, risk, and compliance (GRC) capabilities, ensuring alignment with organizational goals, operational needs, and evolving regulatory and security priorities
- Convert user insights, field requirements, and program objectives into clear product direction and measurable outcomes
- Partner with engineering, design, and data teams to deliver secure, reliable, and high-quality products optimized for mission use
- Oversee the product lifecycle to ensure ongoing reliability, sustainment, and continuous improvement across mission-critical capabilities
- Define success metrics, analyze performance, and refine product decisions based on data, user feedback, and mission impact
- Stay current on GRC and regulatory trends—including SOC 2, ISO 27001, NIST 800-53/CSF, GDPR, SOX, and industry-specific frameworks—and use these insights to recommend features that strengthen compliance posture and differentiate the platform
Requirements:
- 5+ years of product management experience, including direct ownership of a Governance, Risk, and Compliance (GRC) software platform
- Strong analytical, strategic, and problem-solving skills with a data-driven approach
- Excellent leadership and communication abilities, with experience influencing cross-functional teams
- Technical fluency (APIs, AI/ML, data models, architecture, scaling) and comfort working closely with engineering teams located in India
- Customer-obsessed approach with experience gathering insights through interviews, research, and usability testing, especially with high-stakes user groups
- Familiarity with agile/lean methodologies and modern product development practices
- Bachelor's degree in cybersecurity, information technology, supply chain, business administration or equivalent professional work experience required
- Prior experience building or managing GRC, IRM, or compliance-focused products
- Experience with AI/ML features, data-driven products, or platform ecosystems
- Experience with Jira, Looker, MongoDB, Postgres, Aha!, etc
- Previous startup-scale or high-growth company experience