3 дня назад
GRC Lead (Cybersecurity)
140 000 - 185 000$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
GRC Lead (Cybersecurity): Owning and maturing a cybersecurity governance, risk, and compliance program covering CMMC, NIST 800-171, FAR/DFARS, control frameworks, evidence management, and audits with an accent on CMMC readiness and cross-functional compliance execution. Focus on mapping controls, conducting gap assessments, building audit-ready evidence, managing risk treatment, and coordinating with assessors and auditors.
Location: Remote - United States. Travel may be required to company facilities, operational sites, and partner locations. The role may occasionally require work outside normal business hours for security exercises, incident response, or time-sensitive remediation.
Base salary: $140,000–$185,000 USD per year, depending on experience, skills, and location.
Company
develops mission-critical technologies for the space, defense, and national security sectors.
What you will do
- Own the end-to-end governance, risk, and compliance program across CMMC, NIST 800-171, FAR/DFARS, and other applicable requirements.
- Lead CMMC readiness, including scoping, gap assessments, POA&M development, and coordination with C3PAOs through assessment.
- Manage control mapping, ownership assignment, evidence collection, and remediation of compliance gaps.
- Build and maintain an accurate, complete, and audit-ready evidence library.
- Plan and support internal and external audits, assessments, and third-party reviews as the primary auditor contact.
- Maintain the organizational risk register and partner with IT, engineering, legal, and operations to embed compliance into processes, tools, and projects.
Requirements
- Bachelor’s degree in information security or a related field with 8 years of relevant experience, or a master’s degree with 6 years of relevant experience.
- Relevant certification such as CISSP, CISA, CRISC, CISM, or CompTIA Security+.
- Hands-on experience implementing and preparing assessments for CMMC Level 2 or Level 3 or NIST SP 800-171.
- Experience managing control frameworks, drafting security policies and procedures, preparing audit evidence, and coordinating with auditors.
- Ability to work independently, manage multiple workstreams, influence cross-functional stakeholders, and explain technical compliance requirements to non-technical audiences.
- Must be a U.S. Person and eligible to obtain required export authorizations for access to ITAR/EAR-controlled information and government-controlled systems.
Nice to have
- CMMC assessor certification such as CCP, CCA, or LCCA.
- Experience building or maturing an early-stage GRC program.
- Experience coordinating with C3PAOs or DCSA assessors.
Culture & Benefits
- Flexible Time Off supporting work-life balance.
- Medical, dental, and vision coverage for employees and families.
- 401(k) plan with a 50% company match on contributions up to 8%.
- Wellness programs, gym membership options, and additional employee support resources.
- Mission-driven work alongside a highly skilled team focused on space, defense, and national security technology.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
3 дня назад
Lead Security Analyst - GRC (Cybersecurity)
138 000 - 215 625$
3 дня назад
GRC Security Analyst (AI Governance)
114 000 - 139 000$
9 дней назад
Security Analyst, GRC
100 000 - 120 000$
3 дня назад
Senior Security Governance Analyst (Cybersecurity)
110 500 - 157 300$
4 дня назад
CMMC Consultant (Cybersecurity)
Sardine
4 дня назад
Security Compliance Lead (Fintech)
130 000 - 190 000$