Director of Governance, Risk & Compliance
New
A
AtmoseraCybersecurity GRC
Remote - USFull-TimeDirector
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Experience
- 8+ years of cybersecurity, GRC, security assessment, audit, or related experience.
- Required Skills
- Microsoft Azure
Requirements
- 8+ years of cybersecurity, GRC, security assessment, audit, or related experience.
- Demonstrated experience leading GRC programs or teams.
- Hands-on experience with NIST SP 800-53, System Security Plans, POA&Ms, control implementation statements, and federal security requirements.
- Experience managing audits, evidence, risk assessments, control gaps, policies, and remediation programs.
- Ability to translate regulatory requirements into technical and operational security controls.
- Experience supporting frameworks such as SOC 2, NIST, CIS, ISO 27001, PCI DSS, HIPAA, CMMC, or Microsoft security benchmarks.
- Microsoft Azure and Microsoft 365 security experience preferred.
- Experience in an MSSP, MSP, consulting, professional services, federal program, or government contractor environment preferred.
- CISSP, CISM, CRISC, CISA, CGEIT, or similar certification preferred.
Responsibilities
- Own Atmosera’s internal GRC program and operational delivery of Managed GRC services.
- Establish standardized GRC methodologies, processes, templates, evidence requirements, and quality controls.
- Lead risk assessments, control assessments, compliance readiness, policy governance, Managed Audit, and Managed Questionnaires.
- Manage client commitments, priorities, capacity, deliverable quality, and service performance.
- Lead and maintain System Security Plans for federal clients, including control implementation statements and supporting evidence.
- Manage POA&Ms, control deficiencies, remediation activities, milestones, and dependencies.
- Coordinate responses to government, assessor, and auditor findings and requests.
- Partner with client and internal technical teams to validate controls and map requirements to technical implementations.
- Lead, mentor, and develop GRC Analysts and Consultants; manage workload, quality assurance, and escalations.
- Identify opportunities to use automation and AI to improve GRC delivery and scalability.
View Full Description & ApplyYou'll be redirected to the employer's site