Senior GRC Manager
Posted 1ds ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Senior GRC Manager leading security governance, risk management, and multi-framework compliance for a United States organization. Driving audit readiness, control validation, policy lifecycle management, and executive risk reporting.
Responsibilities:
- Lead and manage the governance calendar and recurring GRC operating cadence, including risk committee activities, policy publication schedules, audit milestones, and control validation programs
- Oversee audit readiness and evidence management across applicable compliance frameworks
- Administer and continuously improve the enterprise risk management program, including risk identification, risk register maintenance, ownership tracking, risk reviews, and executive reporting
- Manage the full policy lifecycle, including drafting coordination, review, publication, communication, and exception management alignment
- Lead control effectiveness validation, including control design reviews, operational effectiveness testing, evidence standards, sampling methodologies, and remediation follow-up
- Oversee access governance programs from a compliance and risk perspective
- Support AI governance, customer assurance, architecture reviews, and security review processes
- Track audit findings, risk remediation, customer diligence requests, and program assessment results, escalating significant risks and obstacles
- Maintain customer-facing security assurance materials, evidence packages, and trust documentation
- Prepare leadership-level reporting on governance decisions, risk posture, compliance status, and remediation progress
- Collaborate with Security, Internal IT, Legal, Privacy, Compliance, and business stakeholders on evidence collection, testing, remediation planning, and validation
- Promote evidence quality, repeatable governance processes, accountability, and continuous improvement
Requirements:
- Strong knowledge of governance, risk management, compliance programs, policy management, and control validation methodologies
- Extensive understanding of SOC 2, PCI, ISO 27001, CMMC, and NIST-aligned standards
- Expertise in risk identification, risk register administration, ownership tracking, risk assessments, and executive reporting
- Strong policy development, procedure documentation, and executive-level writing skills
- Experience conducting control effectiveness reviews, operating effectiveness testing, evidence validation, remediation oversight, and audit support
- Knowledge of governance operating models, committee facilitation, calendar management, and follow-through on governance decisions and remediation
- Strong executive communication, presentation, and reporting skills
- Familiarity with access governance, exception management, customer assurance programs, and cross-framework control mapping
- Knowledge of AI governance, third-party risk management, and privacy governance
- Strong stakeholder management, relationship-building, accountability, and issue escalation skills
- Ability to prioritize, manage multiple initiatives, and meet deadlines in a fast-paced environment
- Bachelor's degree in a relevant field or equivalent combination of education and relevant professional experience
- Minimum of seven (7) years of experience in GRC, Security Compliance, IT Audit, Enterprise Risk Management, or Security Program Management
- Experience managing audit readiness, evidence collection, control testing, and compliance initiatives across multiple frameworks
- Experience supporting risk committees, governance forums, executive reporting, and enterprise-wide policy management
- Preferred: experience with GRC technology platforms and evidence-management workflows
- Preferred: customer-facing assurance programs, due diligence, vendor security reviews, and security trust programs
- Preferred: CISSP, CISA, CRISC, ISO Lead Auditor, ISO Lead Implementer, PCI QSA, or equivalent credentials
- Preferred: experience in highly regulated, client-assurance-focused, or defense-adjacent environments
- Prolonged periods of sitting at a desk and working on a computer
- Must be able to lift up to 15 pounds at times




















