Manager, Governance, Risk & Compliance
A
ACM Global LaboratoriesInformation Security
United StatesFull-TimeManager
Salary115,000 - 140,000 USD per year
Apply NowOpens the employer's application page
Job Details
- Experience
- Minimum of 5 years
- Required Skills
- HIPAARisk Management
Requirements
- Minimum of 5 years of experience leading GRC programs.
- Proficiency in ISO 27001 framework.
- Experience with SOC 2, NIST CSF, and HIPAA regulations.
- Experience with third-party/vendor risk management processes.
- Experience working with sales teams on RFPs and security questionnaires.
- Ability to analyze risk data and translate regulations into actionable controls.
- Strong understanding of policy management, risk assessment, and IT audits.
- Bachelor’s degree in IT, cybersecurity, business, or law preferred.
- GRC certifications such as CGRC or CRISC are preferred.
Responsibilities
- Lead GRC program activities including third-party risk, security internal audit, security compliance, and ISMS program management.
- Develop, document, and implement internal policies and procedures to ensure compliance with industry standards.
- Facilitate regular risk assessments against frameworks such as SOC 2, ISO 27001, and PCI-DSS.
- Manage security responses to client questions, RFPs, RFIs, and annual risk reviews.
- Manage and update business continuity and disaster recovery documentation, including BIAs and annual exercises.
- Build and manage a security metrics (KPIs) program.
- Develop relationships with cross-functional teams to drive risk-informed decision-making.
View Full Description & ApplyYou'll be redirected to the employer's site