Head of Cybersecurity Governance, Risk...

CRC Insurance Services Inc
Charlotte, NC, United States
19 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Cyber Security Data Security Disaster Recovery Phishing Cyber Threat Analysis RSA Archer Platform Servicenow

Job description

This role is for the Head of Cybersecurity Governance, Risk & Compliance (GRC) function within a nationally recognized insurance wholesale brokerage organization. The Cyber GRC program was built from the ground up and is now moving into a more mature, business-as-usual operating model, delivered by a hybrid team of full-time employees and strategic contract support spanning regulatory compliance, IT and cyber risk, third-party risk, AI governance, education and awareness, policy and standards, and disaster recovery governance.

As Head of Cyber GRC, this leader will carry the program forward, owning critical governance across Cyber risk, IT risk, regulatory compliance, Third-Party Vendor risk, AI governance, and disaster recovery governance. The role ensures cybersecurity, technology, and regulatory risks are identified, documented, escalated, remediated, and communicated effectively across the enterprise, and is central to translating complex risk and compliance topics into clear, business-ready language for senior leadership.

The position offers broad ownership and enterprise visibility, with high-trust partnership across the CISO, CIO, Legal, Privacy, Compliance, Enterprise Risk, Supplier Risk, Internal Audit, IT, Cybersecurity, and business leaders. It also provides exposure to a unique Cybersecurity regulatory environment, including Committee on Foreign Investment in the United States (CFIUS)-related obligations, NYDFS cybersecurity compliance, and insurance-sector governance requirements.

Key Responsibilities

  • Hands-On GRC Leadership : Serve as a hands-on, working leader who personally performs and owns key GRC deliverables - risk assessments, control reviews, regulatory analysis, and reporting - while leading the function across regulatory compliance, technology risk, cyber risk, third-party risk, AI governance, awareness, and policy and standards

  • Regulatory Obligations (CFIUS): Manage key regulatory obligations tied to CFIUS, including national security agreement and data security plan commitments

  • NYDFS Cybersecurity Compliance: Support NYDFS cybersecurity compliance in partnership with internal subject matter experts and broader risk and compliance stakeholders

  • IT & Cyber Risk Management: Oversee IT and cyber risk registers, risk assessments, remediation tracking, findings management, and governance reporting through Optro (formerly AuditBoard)

  • Third-Party Cyber Risk: Lead third-party cyber risk management, including vendor due diligence, supplier risk partnership, SOC/SIG review, and cyber-related audit response

  • AI Governance: Govern the AI risk management framework, including policy, standards, council activity, risk review, and governance maturity

  • Control Library & NIST Alignment: Manage and maintain a technology control library to support clear ownership and accountability and to report on the effectiveness of NIST-aligned controls across the organization

  • Education & Awareness: Oversee cybersecurity education, awareness, communications, phishing simulations, testing, metrics, and reporting

  • Disaster Recovery Governance: Provide governance oversight for disaster recovery, including plan readiness, testing expectations, and accountability tracking

  • Cross-Functional Partnership: Partner across Legal, Privacy, Compliance, Enterprise Risk, Internal Audit, IT, Cybersecurity, Supplier Risk, and business leadership to drive practical risk management

Requirements

The requirements listed below are representative of the knowledge, skill and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

  • Senior cybersecurity GRC, technology risk, cyber risk, information security governance, or regulatory compliance leadership experience

  • Background in insurance, financial services, banking, brokerage, or another highly regulated enterprise environment

  • Prior experience working directly with a CISO, CIO, or senior information security executive

  • Strong understanding of cyber governance, IT and cyber risk registers, regulatory compliance, control environments, audit readiness, and remediation tracking

  • Experience with third-party cyber risk, vendor due diligence, supplier risk partnership, and customer/carrier audit response

  • Experience with GRC platforms such as AuditBoard/Optro, Archer, ServiceNow IRM/GRC, MetricStream, LogicGate, OneTrust, or similar tools

Certifications, Licenses, Registrations

  • Certifications such as CISM, CISSP, CRISC, CISA, GSLC, or similar are preferred

Functional Skills

  • Strong executive communication skills, with the ability to simplify complex cyber, technology, regulatory, and operational risk topics for senior leadership

  • Ability to lead emerging technology governance, particularly AI governance, policy, standards, risk review, and control development

  • Ability to manage executive stakeholders while providing the team clear direction, prioritization, and support

  • Proven ability to ensure cybersecurity, technology, and regulatory risks are identified, documented, escalated, remediated, and communicated across the enterprise

Preferred Attributes

  • NYDFS cybersecurity experience is strongly preferred

  • CFIUS experience is highly valuable, We seek passionate individuals who thrive in a fast-paced, collaborative environment. If you value integrity and are driven to succeed, CRC Group is the place for you.

Benefits & conditions

General Description of Available Benefits for Eligible Employees of CRC Group: At CRC Group, we’re committed to supporting every aspect of teammates’ well-being - physical, emotional, financial, social, and professional. Our best-in-class benefits program is designed to care for the whole you, offering a wide range of coverage and support. Eligible full-time teammates enjoy access to medical, dental, vision, life, disability, and AD&D insurance; tax-advantaged savings accounts; and a 401(k) plan with company match. CRC Group also offers generous paid time off programs, including company holidays, vacation and sick days, new parent leave, and more. Eligible positions may also qualify for restricted stock units and/or a deferred compensation plan.

CRC Group supports a diverse workforce and is an Equal Opportunity Employer that does not discriminate against individuals on the basis of race, gender, color, religion, citizenship or national origin, age, sexual orientation, gender identity, disability, veteran status or other classification protected by law. CRC Group is a Drug Free Workplace.

EEO is the Law (https://www.eeoc.gov/sites/default/files/2022-10/EEOC_KnowYourRights_screen_reader_10_20.pdf) Pay Transparency Nondiscrimination Provision E-Verify (https://www.e-verify.gov/employees/employee-rights-and-responsibilities)

Join CRC Group, a leader in specialty wholesale insurance, and take your career to new heights. We’re a dynamic team dedicated to innovation, collaboration, and excellence.

Why CRC Group?

  • Growth: Advance your career with our learning and leadership development programs.

  • Innovation: Work in a forward-thinking environment that values new ideas.

  • Community: Be part of a supportive team that celebrates success together.

  • Benefits: Enjoy competitive compensation, health benefits, and retirement plans.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.juju.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:04 min

Embedding data security and applied ethics into developer education

Daniel Tao +3 · WWC 2024

56 sec

Integrating automated approval workflows into the portal

Markus Eisele Markus Eisele · WWC 2025

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · WWC Europe 2026

41 sec

Massive client data loss and bio-digital storage

Chris Heilmann +1 · LIVE

2:27 min

Establishing a simulated technical environment for the workflow demo

Tobias Dunn-Krahn · LIVE

Videos

See all

Related articles

See all