GRC Program Manager

$150K/Yr - $180K/Yr
Remote
Posted 2 weeks ago

Job Description

We are seeking an experienced and strategic Governance, Risk, and Compliance (GRC) Program Manager to lead and enhance our enterprise-wide GRC initiatives. This leadership role is responsible for developing, implementing, and managing governance frameworks, enterprise risk management strategies, cybersecurity compliance programs, and regulatory initiatives that support business objectives while reducing organizational risk.

As a GRC Program Manager, you will collaborate with executive leadership, cybersecurity, legal, internal audit, privacy, IT operations, cloud engineering, and business stakeholders to ensure compliance with applicable regulations, industry standards, and corporate policies. You will oversee enterprise risk assessments, regulatory audits, policy management, third-party risk programs, security control implementation, and continuous compliance monitoring.

The ideal candidate possesses deep knowledge of cybersecurity governance, risk management, compliance frameworks, and regulatory requirements while demonstrating strong leadership, communication, and program management skills. Experience leading enterprise GRC programs in highly regulated industries such as finance, healthcare, technology, or government is highly desirable.


Key Responsibilities

Governance & Program Management

  • Develop and manage the organization’s Governance, Risk, and Compliance (GRC) strategy.
  • Lead enterprise-wide GRC initiatives aligned with business objectives.
  • Establish governance frameworks, policies, standards, and procedures.
  • Drive continuous improvement of governance processes and compliance programs.
  • Define GRC program goals, KPIs, and success metrics.
  • Report program performance and risk posture to executive leadership and governance committees.

Risk Management

  • Lead enterprise risk assessments across business units and IT environments.
  • Develop and maintain enterprise risk registers.
  • Identify operational, cybersecurity, technology, cloud, and third-party risks.
  • Evaluate business impacts and recommend risk mitigation strategies.
  • Monitor Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs).
  • Coordinate risk treatment and remediation activities.
  • Support Enterprise Risk Management (ERM) initiatives.

Compliance Management

  • Ensure compliance with applicable regulatory and industry requirements.
  • Manage internal and external compliance audits.
  • Coordinate evidence collection for regulatory assessments.
  • Monitor regulatory changes and communicate compliance impacts.
  • Maintain compliance documentation and audit readiness.
  • Track remediation plans for audit findings.

Security Governance

  • Develop and maintain information security policies and standards.
  • Ensure security controls align with organizational objectives.
  • Support cybersecurity governance initiatives.
  • Oversee security awareness and compliance programs.
  • Collaborate with Information Security leadership on strategic initiatives.

Third-Party Risk Management

  • Oversee third-party/vendor risk management programs.
  • Review vendor security assessments and due diligence reports.
  • Evaluate supplier compliance with contractual security requirements.
  • Monitor vendor remediation activities.
  • Support procurement during vendor onboarding.

Audit & Control Management

  • Coordinate internal audits and external regulatory examinations.
  • Perform control assessments and maturity reviews.
  • Monitor control effectiveness.
  • Track corrective action plans.
  • Support SOC 2, ISO, PCI, HIPAA, and SOX audit activities.

Leadership & Collaboration

  • Lead cross-functional GRC initiatives.
  • Mentor GRC analysts, compliance specialists, and junior team members.
  • Present risk and compliance updates to executives and board committees.
  • Partner with Legal, Privacy, Internal Audit, Finance, HR, and Technology teams.
  • Manage relationships with auditors, regulators, and external consultants.

Continuous Improvement

  • Identify opportunities to automate GRC processes.
  • Improve governance workflows using GRC platforms.
  • Implement compliance dashboards and executive reporting.
  • Stay informed about emerging cybersecurity threats, regulations, and industry best practices.
  • Promote a culture of compliance and risk awareness throughout the organization.

Required Qualifications

  • Bachelor’s degree in Cybersecurity, Information Technology, Information Systems, Computer Science, Business Administration, Risk Management, or a related field.
  • Master’s degree preferred.
  • 7+ years of experience in Governance, Risk, Compliance, Cybersecurity, IT Risk, or Information Security.
  • 3+ years of experience managing enterprise GRC programs or leading GRC teams.
  • Strong knowledge of enterprise risk management principles.
  • Experience managing enterprise compliance initiatives.
  • Excellent leadership and stakeholder management skills.
  • Strong analytical and problem-solving abilities.
  • Outstanding written and verbal communication skills.
  • Experience working with executive leadership and board-level reporting.

Required Technical Skills

  • Governance, Risk & Compliance (GRC)
  • Enterprise Risk Management (ERM)
  • IT Risk Management
  • Operational Risk
  • Cyber Risk Management
  • Security Control Frameworks
  • Policy Management
  • Risk Assessments
  • Control Testing
  • Audit Management
  • Compliance Monitoring
  • Vendor Risk Management
  • Business Continuity Planning
  • Disaster Recovery
  • Security Awareness Programs
  • Data Governance
  • Regulatory Compliance
  • KPI & KRI Reporting
  • Executive Reporting
  • Project & Program Management

Regulatory & Compliance Frameworks

Candidates should have experience with one or more of the following:

  • NIST Cybersecurity Framework (CSF)
  • NIST Risk Management Framework (RMF)
  • ISO/IEC 27001
  • ISO/IEC 27002
  • SOC 2
  • PCI DSS
  • HIPAA
  • SOX (Sarbanes-Oxley)
  • GDPR
  • CCPA
  • COBIT
  • CIS Controls
  • FedRAMP (Preferred)
  • HITRUST (Preferred)

GRC Tools

Experience with one or more of the following platforms is preferred:

  • ServiceNow GRC
  • Archer Integrated Risk Management (RSA Archer)
  • MetricStream
  • OneTrust
  • LogicGate
  • AuditBoard
  • Microsoft Purview
  • Microsoft Defender
  • Jira
  • Confluence
  • Power BI
  • Microsoft Excel
  • Microsoft 365
  • Splunk (Preferred)

Cloud Security Knowledge

Experience with cloud governance and compliance in:

  • Amazon Web Services (AWS)
  • Microsoft Azure
  • Google Cloud Platform (GCP)

Knowledge of cloud security frameworks including:

  • AWS Well-Architected Framework
  • Azure Security Benchmark
  • CIS Benchmarks
  • Cloud Security Alliance (CSA) Cloud Controls Matrix

Preferred Certifications

One or more of the following certifications is highly preferred:

  • Certified Information Systems Security Professional (CISSP)
  • Certified Information Security Manager (CISM)
  • Certified in Risk and Information Systems Control (CRISC)
  • Certified Information Systems Auditor (CISA)
  • Certified Third-Party Risk Professional (CTPRP)
  • ISO/IEC 27001 Lead Implementer or Lead Auditor
  • Project Management Professional (PMP)
  • Certified Risk Management Professional (PMI-RMP)
  • Microsoft Certified: Cybersecurity Architect Expert (SC-100)
  • AWS Certified Security – Specialty

Soft Skills

  • Leadership and Team Management
  • Strategic Planning
  • Executive Communication
  • Stakeholder Management
  • Business Consulting
  • Decision-Making
  • Risk Analysis
  • Conflict Resolution
  • Negotiation
  • Critical Thinking
  • Organizational Skills
  • Time Management
  • Cross-Functional Collaboration
  • Problem Solving

Benefits

  • Competitive salary with annual performance bonus
  • Medical, dental, and vision insurance
  • Paid vacation, holidays, and parental leave
  • Flexible remote and hybrid work options
  • Professional certification reimbursement
  • Learning and development programs
  • Employee Assistance Program (EAP)
  • Wellness initiatives
  • Career advancement opportunities

Job Features

Job CategoryGRC

Apply For This Job

A valid phone number is required.