Director of Governance, Risk & Compliance

Posted 4 days ago

This is a fully remote position, open to applicants in United States.

📋 Description

• Oversee Atmosera's internal Governance, Risk, and Compliance (GRC) program and Managed Governance, Risk & Compliance services.

• Develop and implement standardized methodologies, processes, templates, evidence requirements, and quality controls for GRC.

• Conduct risk assessments, control assessments, compliance readiness evaluations, policy governance, Managed Audit, Managed Questionnaires, and other GRC initiatives.

• Manage client commitments, set priorities, oversee capacity, ensure deliverable quality, and monitor service performance.

• Identify opportunities to leverage automation and AI for enhancing GRC delivery and scalability.

• Collaborate with Sales and Client Success teams on service scoping, Statements of Work (SOWs), pricing, and complex opportunities.

• Lead and maintain System Security Plans for federal clients.

• Create and review control implementation statements along with supporting evidence.

• Work with technical control owners to validate the implementation of controls.

• Manage Plans of Action and Milestones (POA&Ms), control deficiencies, remediation activities, milestones, and dependencies.

• Coordinate responses to findings and requests from government bodies, assessors, and auditors.

• Facilitate working sessions on SSP and controls with clients, engineers, security teams, and stakeholders.

• Provide support for continuous monitoring, security assessments, and authorization activities.

• Ensure alignment between documented controls and the actual operating environment.

• Assist with requirements involving NIST SP 800-53, NIST SP 800-171, FISMA, CMMC, FedRAMP concepts, and agency-specific mandates.

• Lead cybersecurity risk assessments, control gap analyses, risk registers, treatment plans, exceptions, and remediation tracking.

• Support frameworks such as SOC 2, NIST, CIS, ISO 27001, PCI DSS, HIPAA, CMMC, and Microsoft security benchmarks.

• Take ownership of the Managed Audit methodology, encompassing audit readiness, evidence management, auditor coordination, findings, and remediation efforts.

• Oversee the delivery of Managed Security Questionnaires and maintain reusable response and evidence libraries.

• Ensure that policies, standards, procedures, and control documentation accurately reflect operational practices.

• Collaborate with the CISO to operate and enhance Atmosera's internal security and compliance program.

• Act as a senior GRC advisor to client security, IT, risk management, compliance, and executive leadership teams.

• Convert regulatory and compliance requirements into actionable security improvements.

• Partner with Security Operations, Managed Azure, Microsoft 365, and engineering teams to align control requirements with technical implementations.

• Maintain a working knowledge of Azure, Entra ID, Defender, Sentinel, Intune, Purview, and Azure Policy.

• Support virtual Chief Information Security Officer (vCISO) engagements that require governance, risk, audit, or compliance expertise.

• Lead, mentor, and develop GRC Analysts and Consultants.

• Manage workload, capacity, priorities, quality assurance, and escalations effectively.

• Establish repeatable processes to enable the GRC practice to scale successfully.

• Complete onboarding, shadow active engagements, and audit current Managed Governance and Risk Compliance (MGRC) workflows within 90 days.

• Independently oversee the GRC function, manage the SOC 2 Type 2 program, lead MGRC delivery, and handle complex federal System Security Plan activities within one year.


⛳️ Requirements

• 8+ years of experience in cybersecurity, GRC, security assessment, audit, or related fields.

• Proven track record of leading GRC programs or teams.

• Practical experience with NIST SP 800-53, System Security Plans, POA&Ms, control implementation statements, and federal security mandates.

• Experience in managing audits, evidence, risk assessments, control gaps, policies, and remediation programs.

• Ability to convert regulatory requirements into effective technical and operational security controls.

• Strong client-facing, executive communication, and technical stakeholder management abilities.

• Experience in an MSSP, MSP, consulting, professional services, federal programs, or government contracting environment is preferred.

• Preferred experience with Microsoft Azure and Microsoft 365 security.

• Relevant certifications such as CISSP, CISM, CRISC, CISA, CGEIT, or similar are preferred.


🏝️ Benefits

• Competitive salaries based on experience and skills.

• 100% company match on 401(k) contributions up to 4% of salary.

• Performance-based compensation with bonus potential in addition to base salary.

• 100% employer-paid health, vision, and dental insurance for employees.

• Company-paid life, AD&D, short-term disability, and long-term disability insurance.

• Three weeks of paid time off.

• 11 paid holidays.

• Paid community service leave.

• Employee recognition and reward program.

• Flexibility to work from home or from a local US office.

People also viewed

Laboratorios Médicos Colonia del Valle - Olab1 day ago

Associate Regulatory Specialist, Drinking Water

US flagNew York OnlyFull-timeCompliance$57.8k – $86.8k/year
ApplyView job
Insight IT2 days ago

Senior Consultant, Regulatory Audit and Internal Controls

BR flagBrazil OnlyFreelanceCompliance
ApplyView job
White Hat Gaming2 days ago

Compliance Analyst

ZA flagSouth Africa OnlyFull-timeCompliance
ApplyView job
TRM Labs2 days ago

Senior Manager, Contracts & Compliance

US flagUnited States OnlyFull-timeCompliance
ApplyView job
Workstreet2 days ago

Senior GRC Engineer, Bilingual Spanish-English

PA flagPanama OnlyFull-timeCompliance
ApplyView job
LegitScript2 days ago

Manager, Policy and Compliance, Certification

US flagUnited States OnlyFull-timeCompliance
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers