Назад
Company hidden
2 часа назад

Governance, Risk & Compliance (GRC) Manager (Cybersecurity)

165 000 - 165 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Governance, Risk & Compliance (GRC) Manager (Cybersecurity): Leading and maturing cybersecurity governance, risk management, compliance, and audit programs with an accent on CMMC Level 2, SOC audits, and SOX IT General Controls. Focus on conducting risk assessments, closing compliance gaps, managing remediation, and maintaining audit readiness across business and technology stakeholders.

Location: Remote; occasional travel may be required for company meetings, training, project activities, or other business needs.

Salary: $165,000 USD annually (Colorado pay range).

Company

hirify.global is a U.S. construction lifecycle partner providing critical electrical, mechanical, structural, inspection, underground maintenance and installation, soft craft, and fabrication services.

What you will do

  • Lead and mature governance, risk management, compliance, and audit programs.
  • Own cybersecurity compliance initiatives, including CMMC Level 2, SOC audits, and SOX IT General Controls.
  • Align security controls, policies, and compliance activities with regulatory, contractual, and business requirements.
  • Conduct risk assessments, compliance gap analyses, and remediation planning.
  • Partner with business, technology, executive stakeholders, external auditors, assessors, and regulatory stakeholders.
  • Develop and maintain security policies, standards, governance documentation, and audit-readiness materials.

Requirements

  • 10+ years of experience in GRC, information security, risk management, or related cybersecurity functions.
  • 3+ years of leadership, management, or program ownership experience.
  • Direct experience with CMMC Level 2 compliance programs.
  • Hands-on experience managing SOC 1 and/or SOC 2 audits.
  • Experience supporting SOX compliance and ITGC testing and remediation.
  • Strong understanding of NIST SP 800-171, cybersecurity control frameworks, project management, communication, and stakeholder management.

Nice to have

  • CISSP, CISM, CRISC, CISA, CIA, or CGRC certification.
  • Experience in a Defense Industrial Base or other regulated environment.

Culture & Benefits

  • Primarily remote work from a home office with virtual collaboration.
  • Medical, dental, and vision insurance.
  • 401(k) retirement plan with company match.
  • Paid time off, holiday pay, life insurance, and disability insurance.
  • Professional development, training opportunities, and an employee assistance program.
  • Work guided by integrity, teamwork, excellence, urgency, and purpose.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →