Senior GRC Manager

Converge
United States
25 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Working hours
Regular working hours
Job source

Tech stack

Cyber Security Identity and Access Management Information Technology Audit Information Technology

Job description

The Senior Governance, Risk, and Compliance (GRC) Lead is responsible for leading the organization’s security governance program and operational cadence. Reporting to the Director of Information Security, this role oversees risk management, policy lifecycle management, control validation, audit readiness, evidence quality, and executive reporting across multiple compliance frameworks, including SOC 2, PCI, ISO, and CMMC-aligned environments. The ideal candidate combines strong governance expertise, audit readiness experience, and stakeholder leadership capabilities to drive risk-informed decision-making, maintain compliance objectives, and promote a culture of accountability, evidence quality, and continuous improvement., * Lead and manage the governance calendar and recurring GRC operating cadence, including risk committee activities, policy publication schedules, audit milestones, and control validation programs.

  • Oversee audit readiness and evidence management activities across applicable compliance frameworks, ensuring evidence is complete, timely, and reusable when appropriate.
  • Administer and continuously improve the enterprise risk management program, including risk identification, risk register maintenance, ownership tracking, risk reviews, and executive reporting.
  • Manage the full policy lifecycle, including drafting coordination, review processes, publication, communication, and exception management alignment.
  • Lead control effectiveness validation efforts, including control design reviews, operational effectiveness testing, evidence standards development, sampling methodologies, and remediation follow-up activities.
  • Oversee access governance programs from a compliance and risk perspective, ensuring reviews are completed, documented, and aligned with exception management processes.
  • Support governance initiatives related to AI governance, customer assurance activities, architecture reviews, and security review processes.
  • Track and manage audit findings, risk remediation efforts, customer diligence requests, and program assessment results, escalating significant risks and obstacles as appropriate.
  • Maintain customer-facing security assurance materials, evidence packages, and trust documentation supporting customer and sales engagements.
  • Prepare leadership-level reporting on governance decisions, risk posture, compliance status, and remediation progress.
  • Collaborate with Security, Internal IT, Legal, Privacy, Compliance, and business stakeholders to support evidence collection, testing, remediation planning, and validation activities.
  • Promote a culture of evidence quality, repeatable governance processes, accountability, and continuous improvement across the organization.

Requirements

  • Strong knowledge of governance, risk management, compliance programs, policy management, and control validation methodologies.
  • Extensive understanding of multi-framework compliance environments, including SOC 2, PCI, ISO 27001, CMMC, and NIST-aligned standards.
  • Expertise in risk management practices, including risk identification, risk register administration, ownership tracking, risk assessments, and executive reporting.
  • Strong policy development, procedure documentation, and executive-level writing skills with the ability to translate control requirements into scalable operational processes.
  • Experience conducting control effectiveness reviews, operating effectiveness testing, evidence validation, remediation oversight, and audit support activities.
  • Knowledge of governance operating models, committee facilitation, calendar management, and follow-through on governance decisions and remediation actions.
  • Strong executive communication, presentation, and reporting skills that translate technical and compliance activities into actionable business insights.
  • Familiarity with access governance oversight, exception management, customer assurance programs, and cross-framework control mapping.
  • Knowledge of emerging governance disciplines, including AI governance, third-party risk management, and privacy governance.
  • Strong stakeholder management, relationship-building, accountability, and issue escalation skills.
  • Ability to establish priorities, manage multiple initiatives simultaneously, and meet deadlines in a fast-paced environment.
  • Demonstrated competencies in Governance Program Management, Risk Management, Policy Lifecycle Management, Control Effectiveness Validation, Audit Readiness, Multi-Framework Compliance, Executive Reporting, Customer Assurance, and Stakeholder Management., * Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Business Administration, Risk Management, or a related field; or an equivalent combination of education and relevant professional experience.
  • Minimum of seven (7) years of experience in Governance, Risk and Compliance (GRC), Security Compliance, IT Audit, Enterprise Risk Management, or Security Program Management.
  • Experience managing audit readiness programs, evidence collection processes, control testing activities, and compliance initiatives across multiple security and regulatory frameworks.
  • Experience maintaining governance, risk, and compliance technology platforms and supporting evidence-management workflows is preferred.
  • Familiarity with customer-facing assurance programs, due diligence support, vendor security reviews, and security trust programs is preferred.
  • Experience supporting risk committees, governance forums, executive reporting, and enterprise-wide policy management processes.
  • Relevant certifications such as CISSP, CISA, CRISC, ISO Lead Auditor, ISO Lead Implementer, PCI QSA, or equivalent industry credentials are preferred.
  • Experience working in highly regulated, client-assurance-focused, or defense-adjacent environments is preferred.

Physical Requirements:

  • Prolonged periods of sitting at a desk and working on a computer.
  • Must be able to lift up to 15 pounds at times.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:14 min

Establishing legal admissibility through immutable blockchain attestations

Frederik Gregaard Frederik Gregaard +1 · World Congress 2026 Europe

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

42 sec

Energy forecasts and resource demands of information technology

Marjolein Pordon · LIVE

2:08 min

Managing complex structures and corporate guidelines

Alexandra Petri · World Congress 2023

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · World Congress 2026 Europe

Videos

See all

Related articles

See all