GRC Leader
Gabriel
Chavez
Senior Manager, GRC
Transforming GRC from cost center to strategic business enabler at scale.
About
Architect of Enterprise GRC Transformation Programs
After pivoting from retail and nonprofit operations to complete an accountancy degree at San Diego State, Gabriel launched his career in Big Four IT risk advisory, building deep technical audit expertise across nine industries before moving in-house.
At Procore, he transformed fragmented compliance activity into a platform-driven, automation-first GRC program — owning 350+ controls, leading acquisition integrations, and aligning certification strategy directly to revenue and executive priorities.
9+
Years in GRC & IT Risk
350+
Controls Governed
12+
Frameworks Managed
6
Acquisition Integrations Led
Experience
2021 — Present
Procore Technologies, Inc.
Senior Manager, GRC
- —Architected unified Procore Control Framework spanning SOC 1, SOC 2, ISO 27001, and SOX across 350+ controls.
- —Drove GRC platform strategy across three generations, increasing automated evidence collection by 480% YoY.
- —Consolidated three siloed audits into one integrated engagement, eliminating 52% of redundant evidence requests.
- —Led compliance integration for six acquisitions, establishing the M&A compliance assessment process enterprise-wide.
- —Directed team restructuring consolidating compliance, risk, and governance into a unified GRC function with optimized headcount.
2018 — 2022
Ernst & Young, LLP – Risk Advisory
Technology Risk Consultant - Senior
- —Led external and internal IT audits for public and private companies across SOX, ITGC, and application controls.
- —Managed engagement economics including budgets, hours tracking, and overrun justifications to senior management.
- —Directed onshore and offshore teams across multiple simultaneous annual audit engagements.
- —Audited enterprise IAM and MFA environment for a major media conglomerate during 100,000-employee furlough.
- —Built an information security risk register in Jira with automated Power BI executive reporting.
2016 — 2018
Ernst & Young, LLP – Risk Advisory
Technology Risk Consultant - Staff
- —Executed SOX ITGC testing across Windows, Active Directory, Linux, SQL, and Oracle environments.
- —Performed SDLC control testing spanning requirements approval through go-live authorization workflows.
- —Coordinated planning, fieldwork, and reporting as liaison between IT process owners and external auditors.
2010 — 2013
Macy's, Inc.
Administrative Support Team Associate
- —Co-led region-wide rollout of CRM analytics tool for customer satisfaction monitoring; received service award.
- —Managed data across PeopleSoft HR, Taleo recruiting, and inventory control systems.
2007 — 2010
Muscular Dystrophy Association
Administrative Assistant
- —Managed donor relationships and vendor partnerships for fundraising events across the region.
- —Established Access and Excel reporting as a regional standard, presenting the methodology to leadership.
Skills
Select a face on the crystal to explore a skill domain.
Projects & Initiatives
Compliance Automation & Expansion Program
Originated, defended, and scaled a standing L1 compliance program with a multi-quarter roadmap, driving 500+ automated artifacts and 60% automation coverage for technical controls.
Unified Control Framework Architecture
Designed and implemented the Procore Control Framework as a single source of truth mapping SOC 1, SOC 2, ISO 27001, SOX, FedRAMP, and HIPAA — enabling cross-audit reuse and eliminating operational silos.
M&A Compliance Integration Program
Led compliance integration for six acquisitions, establishing standardized assessment processes, onboarding entities onto unified control baselines, and surfacing material risk before audit exposure.
Examples of Work Products
No examples uploaded yet.
Files will appear here once added.
Contact
Let's connect.
Open to speaking engagements, consulting, advisory roles, and connecting with other GRC professionals.
© 2026 Gabriel Chavez
nomoreresume