Director of Governance, Risk & Compliance
Accountabilities: Own and mature the internal GRC program and lead the operational delivery of Managed GRC services, establishing standardized methodologies, processes, templates, evidence requirements, and quality controls.
Lead risk assessments, control assessments, compliance readiness activities, policy governance, managed audits, managed security questionnaires, and other GRC engagements while managing client commitments, priorities, capacity, quality, and service performance.
Lead federal compliance activities, including the development and maintenance of System Security Plans, control implementation statements, supporting evidence, POA&Ms, remediation plans, milestones, and responses to government, assessor, and auditor findings.
Coordinate with engineers, security teams, control owners, and clients to validate how security controls are implemented and ensure documented controls accurately reflect the operating environment.
Support requirements related to NIST SP 800-53, NIST SP 800-171, FISMA, CMMC, FedRAMP concepts, and agency-specific federal security requirements, including continuous monitoring, assessments, and authorization activities.
Manage cybersecurity risk and compliance programs covering risk registers, control gaps, treatment plans, exceptions, remediation tracking, SOC 2, NIST, CIS, ISO 27001, PCI DSS, HIPAA, CMMC, and Microsoft security benchmarks.
Oversee managed audit and security questionnaire methodologies, including audit readiness, evidence management, auditor coordination, findings, remediation, and reusable response and evidence libraries.
Partner with senior security leadership to operate and strengthen internal compliance initiatives, including SOC 2 Type 2, policy and control governance, third-party risk, customer security reviews, audit coordination, and evidence management.
Act as a senior GRC advisor to client security, IT, risk, compliance, and executive leaders, translating regulatory requirements into actionable technical and operational security improvements.
Collaborate with Security Operations, cloud, Microsoft 365, and engineering teams to map compliance requirements to technical implementations, with working knowledge of Azure, Entra ID, Defender, Sentinel, Intune, Purview, and Azure Policy.
Support vCISO engagements where governance, risk, audit, and compliance expertise is required, while partnering with Sales and Client Success on service scoping, statements of work, pricing, and complex opportunities.
Lead, mentor, and develop GRC Analysts and Consultants while managing workload, capacity, priorities, quality assurance, escalations, and scalable processes that enable the practice to operate effectively without relying on the Director for every engagement.
Identify opportunities to use automation and AI to improve GRC delivery, increase consistency, and scale services efficiently.
Establish measurable progress through early workflow assessments and prioritized improvements, with long-term ownership of the GRC function, SOC 2 Type 2 program, Managed GRC delivery, federal SSP activities, team development, process maturity, and automation.
Requirements
8+ years of experience in cybersecurity, Governance, Risk & Compliance, security assessment, audit, or a related field, with demonstrated experience leading GRC programs or teams.
Hands-on experience with NIST SP 800-53, System Security Plans, POA&Ms, control implementation statements, and federal security requirements.
Proven experience managing audits, evidence programs, risk assessments, control gaps, policies, remediation initiatives, and compliance activities.
Ability to translate regulatory and compliance requirements into practical technical and operational security controls.
Strong understanding of frameworks and standards such as SOC 2, NIST, CIS, ISO 27001, PCI DSS, HIPAA, CMMC, and Microsoft security benchmarks.
Strong client-facing, executive communication, facilitation, and stakeholder management skills, with the ability to communicate effectively with both senior leaders and technical practitioners.
Ability to work directly with engineers and control owners to understand, validate, and document security control implementations.
Experience in an MSSP, MSP, consulting, professional services, federal program, or government contractor environment is preferred.
Experience with Microsoft Azure and Microsoft 365 security technologies is strongly preferred.
Familiarity with Azure, Entra ID, Defender, Sentinel, Intune, Purview, and Azure Policy is an advantage.
Relevant certifications such as CISSP, CISM, CRISC, CISA, CGEIT, or similar are valued.
Demonstrated leadership qualities including low-ego collaboration, initiative, accountability, empathy, situational awareness, and a bias toward practical problem-solving.
Ability to operate strategically with executives while remaining comfortable engaging deeply with technical details, compliance evidence, assessments, and remediation activities.
Benefits
Competitive salary based on experience and skills.
Performance-based compensation with bonus potential in addition to base salary.
401(k) plan with a 100% employer match on employee contributions up to 4% of salary.
100% employer-paid health, vision, and dental insurance premiums for employees.
Company-paid life, AD&D, short-term disability, and long-term disability insurance.
Three weeks of paid time off that can be used for vacation, personal time, or sick leave.
11 paid holidays each year.
Paid community service leave for volunteering with organizations that are meaningful to you.
Employee recognition and reward programs celebrating strong performance and contributions.
Full-time remote work from anywhere in the United States, with the option to work from a local U.S. office when available.
An opportunity to lead a strategic GRC function, develop a team, work on complex federal compliance programs, and build scalable processes and automation.
How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1