Назад
Company hidden
5 дней назад

Director of Governance, Risk & Compliance (Cybersecurity)

Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
director
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Director of Governance, Risk & Compliance (Cybersecurity) (GRC, Federal Compliance): Leading Atmosera’s internal GRC program and Managed GRC services, including federal System Security Plans, risk assessments, audits, remediation, and client advisory with an accent on NIST, SOC 2, CMMC, FedRAMP concepts, and control validation. Focus on managing government and assessor findings, maintaining defensible SSPs, translating requirements into technical controls, and scaling the GRC practice through repeatable processes, team leadership, automation, and AI.

Location: Remote within the United States, with the option to work from a US office if local.

Salary: Competitive salary based on experience and skills; additional performance-based compensation may be available.

Company

hirify.global delivers modern technology, cloud, security, data, AI, DevOps, and Microsoft Azure solutions as a Microsoft Partner.

What you will do

  • Lead hirify.global’s internal Governance, Risk & Compliance program and Managed GRC services.
  • Establish standardized GRC methodologies, processes, templates, evidence requirements, and quality controls.
  • Manage federal security programs, including System Security Plans, control implementation statements, evidence, POA&Ms, remediation, and responses to government and assessor findings.
  • Lead risk assessments, control assessments, audit readiness, managed audits, security questionnaires, and compliance engagements.
  • Advise client executives, CISOs, auditors, engineers, and control owners on translating regulatory requirements into implemented security controls.
  • Lead, mentor, and develop GRC analysts and consultants while improving service scalability through automation and AI.

Requirements

  • 8+ years of experience in cybersecurity, GRC, security assessment, audit, or a related field.
  • Experience leading GRC programs or teams and managing audits, evidence, risk assessments, control gaps, policies, and remediation.
  • Hands-on experience with NIST SP 800-53, System Security Plans, POA&Ms, control implementation statements, and federal security requirements.
  • Ability to translate regulatory requirements into technical and operational security controls.
  • Strong client-facing, executive communication, and technical stakeholder management skills.
  • Must be based in the United States; remote work or work from a local US office is available.

Nice to have

  • Experience in an MSSP, MSP, consulting, professional services, federal program, or government contractor environment.
  • Microsoft Azure and Microsoft 365 security experience.
  • CISSP, CISM, CRISC, CISA, CGEIT, or a similar certification.

Culture & Benefits

  • Full-time employment with work-from-home flexibility within the United States.
  • Employer-paid health, vision, dental, life, and disability insurance.
  • 401(k) plan with a 100% company match on contributions up to 4% of salary.
  • Three weeks of PTO, 11 paid holidays, and paid community service leave.
  • Employee recognition and performance-based compensation programs.

Hiring process

  • 30-minute talent screen.
  • 60-minute Impact & Attributes Assessment with the CISO, followed by a collaborator loop with peers.
  • Final alignment with the executive team; a presentation or work sample and an additional step may be required.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →