Назад
Company hidden
5 дней назад

GRC Lead (Aerospace)

150 000 - 190 000$
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
GRC Lead (CMMC/FedRAMP/SOC 2/ITAR): Owning compliance, risk management, and audit readiness for a space communications infrastructure company with an accent on overlapping regulatory frameworks, CUI handling, and technical control validation. Focus on building evidence programs, coordinating C3PAO and 3PAO assessments, managing enterprise risk, and translating security engineering implementations into defensible compliance documentation.

Location: Torrance, CA, United States. U.S. citizenship or lawful permanent resident status is required for ITAR compliance, and the role requires obtaining and maintaining a Top Secret Security Clearance.

Salary: $150,000–$190,000 per year, plus equity, discretionary performance bonuses, and benefits.

Company

hirify.global is a space infrastructure company building a global network of phased-array ground stations for real-time satellite communications supporting national security, global connectivity, and disaster response.

What you will do

  • Own compliance programs across CMMC Level 2, FedRAMP, SOC 2 Type II, and ITAR, including control mapping, gap assessment, remediation tracking, and audit preparation.
  • Maintain the System Security Plan, POA&M, policy library, control mappings, and continuous evidence collection program.
  • Coordinate C3PAO, FedRAMP 3PAO, and SOC 2 assessments as the primary assessor liaison.
  • Build the enterprise risk management program, including risk registers, risk scoring, executive reporting, risk acceptance, and exception workflows.
  • Manage CUI classification, handling procedures, marking standards, employee training, and ITAR technology control documentation.
  • Partner with security engineering, network, product, and operations teams to validate technical controls across on-premises infrastructure, AWS GovCloud, Microsoft GCC, and corporate systems.

Requirements

  • 5+ years of experience in governance, risk, and compliance in a regulated environment.
  • Deep working knowledge of CMMC Level 2 and NIST SP 800-171, including SSP development, POA&M management, and C3PAO preparation.
  • Experience with FedRAMP authorization, SOC 2 Type II audits, ITAR compliance, CUI programs, risk assessments, and enterprise risk registers.
  • Strong technical fluency and ability to translate security controls into compliance documentation and audit evidence.
  • Ability to obtain and maintain a Top Secret Security Clearance is required.
  • U.S. citizenship or lawful permanent resident status is required to conform with ITAR regulations.

Nice to have

  • Active TS clearance or higher and Defense Industrial Base experience.
  • Experience with eMASS, GRC platforms, AWS GovCloud, Microsoft GCC, DFARS, DIBCAC, or DCSA processes.
  • CISSP, CISM, CISA, CCSK, CMMC Registered Practitioner, or Certified Professional credentials.
  • Experience developing security awareness and CUI handling training programs.

Culture & Benefits

  • Equity, long-term incentives, and discretionary performance bonuses.
  • Comprehensive medical, vision, and dental coverage, including flexible spending accounts.
  • Flexible time off, 10 or more paid holidays per year, and retirement savings plans.
  • Opportunities for professional development.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →