Chief Governance, Risk & Compliance Officer (CGRCO)

$280,000 – $420,000K/Yr
Remote
Posted 6 days ago

Job Description

The Chief Governance, Risk & Compliance Officer (CGRCO) is a C-level executive responsible for establishing and leading the organization’s enterprise Governance, Risk Management, Compliance, Cybersecurity Governance, Privacy, Internal Controls, and Digital Risk strategy.

The CGRCO partners closely with the CEO, CIO, CISO, Legal, Internal Audit, and the Board of Directors to ensure the organization maintains strong governance practices while meeting regulatory obligations and reducing enterprise-wide risk. This executive drives business resilience, strengthens organizational trust, and enables secure digital transformation through effective governance frameworks.


Key Responsibilities

Enterprise Governance

  • Develop and execute the enterprise Governance, Risk & Compliance (GRC) strategy.
  • Establish governance policies, standards, and corporate controls.
  • Lead governance committees and executive steering meetings.
  • Present governance updates to executive leadership and the Board.

Enterprise Risk Management

  • Define enterprise risk appetite and risk tolerance.
  • Identify strategic, operational, financial, cyber, and technology risks.
  • Maintain enterprise risk registers and dashboards.
  • Monitor Key Risk Indicators (KRIs) and risk trends.

Regulatory Compliance

  • Ensure compliance with applicable regulations and standards, including:
    • NIST Cybersecurity Framework (CSF)
    • ISO/IEC 27001
    • SOC 2
    • PCI DSS
    • HIPAA
    • GDPR
    • CCPA
    • SOX
    • FedRAMP
  • Lead regulatory examinations and external audits.

Cybersecurity Governance

  • Partner with the CISO to oversee cybersecurity governance.
  • Approve enterprise security policies and risk treatment plans.
  • Monitor cyber resilience and incident response readiness.
  • Support cloud security governance initiatives.

Internal Controls & Audit

  • Oversee enterprise internal control frameworks.
  • Ensure effective remediation of audit findings.
  • Coordinate with Internal Audit and external auditors.
  • Monitor compliance metrics and reporting.

Third-Party Risk Management

  • Establish vendor risk governance programs.
  • Approve supplier risk assessments.
  • Review critical third-party security controls.
  • Oversee contract compliance and due diligence.

AI & Digital Governance

  • Develop governance for Artificial Intelligence (AI) and Generative AI.
  • Implement responsible AI policies and model governance.
  • Oversee AI risk management and regulatory compliance.
  • Ensure ethical and transparent AI deployment.

Leadership

  • Lead cross-functional GRC, Privacy, Audit, and Risk teams.
  • Mentor senior directors and managers.
  • Manage enterprise GRC budgets.
  • Drive a culture of ethics, compliance, and accountability.

Required Qualifications

  • Bachelor’s degree in Cybersecurity, Information Technology, Business Administration, Finance, or a related field.
  • Master’s degree (MBA, MIS, or Cybersecurity) preferred.
  • 15+ years of experience in Governance, Risk & Compliance, Cybersecurity, Enterprise Risk, or Internal Audit.
  • 8+ years in executive or senior leadership roles.
  • Experience presenting to executive leadership and Boards of Directors.
  • Strong knowledge of enterprise GRC frameworks and regulatory requirements.

Preferred Certifications

  • Certified Information Systems Security Professional (CISSP)
  • Certified Information Security Manager (CISM)
  • Certified in Risk and Information Systems Control (CRISC)
  • Certified Information Systems Auditor (CISA)
  • Certified in Governance of Enterprise IT (CGEIT)
  • Project Management Professional (PMP)
  • ISO/IEC 27001 Lead Implementer or Lead Auditor

Technical Skills

  • ServiceNow GRC
  • RSA Archer
  • MetricStream
  • LogicGate
  • AuditBoard
  • OneTrust
  • Microsoft Purview
  • Splunk
  • Microsoft Sentinel
  • Power BI
  • Azure
  • AWS
  • Google Cloud Platform (GCP)
  • Microsoft Defender

Core Competencies

  • Executive Leadership
  • Corporate Governance
  • Enterprise Risk Management (ERM)
  • Regulatory Compliance
  • Cyber Risk Management
  • Business Continuity & Resilience
  • Digital Transformation
  • AI Governance
  • Board-Level Communication
  • Strategic Planning
  • Vendor Risk Management
  • Crisis Management
  • Policy Development
  • Cross-Functional Leadership

Job Features

Job CategoryGRC

Apply For This Job