
Director of Governance, Risk & Compliance
Posted 4 days ago

Posted 4 days ago
This is a fully remote position, open to applicants in United States.
• Oversee Atmosera's internal Governance, Risk, and Compliance (GRC) program and Managed Governance, Risk & Compliance services.
• Develop and implement standardized methodologies, processes, templates, evidence requirements, and quality controls for GRC.
• Conduct risk assessments, control assessments, compliance readiness evaluations, policy governance, Managed Audit, Managed Questionnaires, and other GRC initiatives.
• Manage client commitments, set priorities, oversee capacity, ensure deliverable quality, and monitor service performance.
• Identify opportunities to leverage automation and AI for enhancing GRC delivery and scalability.
• Collaborate with Sales and Client Success teams on service scoping, Statements of Work (SOWs), pricing, and complex opportunities.
• Lead and maintain System Security Plans for federal clients.
• Create and review control implementation statements along with supporting evidence.
• Work with technical control owners to validate the implementation of controls.
• Manage Plans of Action and Milestones (POA&Ms), control deficiencies, remediation activities, milestones, and dependencies.
• Coordinate responses to findings and requests from government bodies, assessors, and auditors.
• Facilitate working sessions on SSP and controls with clients, engineers, security teams, and stakeholders.
• Provide support for continuous monitoring, security assessments, and authorization activities.
• Ensure alignment between documented controls and the actual operating environment.
• Assist with requirements involving NIST SP 800-53, NIST SP 800-171, FISMA, CMMC, FedRAMP concepts, and agency-specific mandates.
• Lead cybersecurity risk assessments, control gap analyses, risk registers, treatment plans, exceptions, and remediation tracking.
• Support frameworks such as SOC 2, NIST, CIS, ISO 27001, PCI DSS, HIPAA, CMMC, and Microsoft security benchmarks.
• Take ownership of the Managed Audit methodology, encompassing audit readiness, evidence management, auditor coordination, findings, and remediation efforts.
• Oversee the delivery of Managed Security Questionnaires and maintain reusable response and evidence libraries.
• Ensure that policies, standards, procedures, and control documentation accurately reflect operational practices.
• Collaborate with the CISO to operate and enhance Atmosera's internal security and compliance program.
• Act as a senior GRC advisor to client security, IT, risk management, compliance, and executive leadership teams.
• Convert regulatory and compliance requirements into actionable security improvements.
• Partner with Security Operations, Managed Azure, Microsoft 365, and engineering teams to align control requirements with technical implementations.
• Maintain a working knowledge of Azure, Entra ID, Defender, Sentinel, Intune, Purview, and Azure Policy.
• Support virtual Chief Information Security Officer (vCISO) engagements that require governance, risk, audit, or compliance expertise.
• Lead, mentor, and develop GRC Analysts and Consultants.
• Manage workload, capacity, priorities, quality assurance, and escalations effectively.
• Establish repeatable processes to enable the GRC practice to scale successfully.
• Complete onboarding, shadow active engagements, and audit current Managed Governance and Risk Compliance (MGRC) workflows within 90 days.
• Independently oversee the GRC function, manage the SOC 2 Type 2 program, lead MGRC delivery, and handle complex federal System Security Plan activities within one year.
• 8+ years of experience in cybersecurity, GRC, security assessment, audit, or related fields.
• Proven track record of leading GRC programs or teams.
• Practical experience with NIST SP 800-53, System Security Plans, POA&Ms, control implementation statements, and federal security mandates.
• Experience in managing audits, evidence, risk assessments, control gaps, policies, and remediation programs.
• Ability to convert regulatory requirements into effective technical and operational security controls.
• Strong client-facing, executive communication, and technical stakeholder management abilities.
• Experience in an MSSP, MSP, consulting, professional services, federal programs, or government contracting environment is preferred.
• Preferred experience with Microsoft Azure and Microsoft 365 security.
• Relevant certifications such as CISSP, CISM, CRISC, CISA, CGEIT, or similar are preferred.
• Competitive salaries based on experience and skills.
• 100% company match on 401(k) contributions up to 4% of salary.
• Performance-based compensation with bonus potential in addition to base salary.
• 100% employer-paid health, vision, and dental insurance for employees.
• Company-paid life, AD&D, short-term disability, and long-term disability insurance.
• Three weeks of paid time off.
• 11 paid holidays.
• Paid community service leave.
• Employee recognition and reward program.
• Flexibility to work from home or from a local US office.
Laboratorios Médicos Colonia del Valle - Olab
Insight IT
White Hat Gaming
TRM Labs
Get handpicked remote jobs straight to your inbox weekly.