
Global Security Governance, Risk & Compliance Manager
Posted Sep 18

Posted Sep 18
This is a fully remote position, open to applicants in United States.
• Drive and maintain governance, risk, and compliance across engineering, manufacturing, and corporate settings.
• Report directly to the CISO and lead a team of Governance, Risk, and Compliance (GRC) professionals.
• Oversee enterprise-wide IT implementation of CMMC and other compliance program lifecycles.
• Define the scope, System Security Plan (SSP)/Plan of Action and Milestones (POA&M), evidence quality and refresh cadence, assessor coordination, corrective-action closure, and site-level readiness.
• Coordinate control owners through a global matrix model.
• Convert policies and strategic goals into standardized processes across manufacturing plants, engineering teams, and corporate functions.
• Drive remediation initiatives and provide transparency regarding readiness, progress, and risk.
• Mentor team members, prioritize workloads, develop capabilities, and encourage global collaboration.
• Take ownership of preparation for and participation in customer and third-party audits and security questionnaires.
• Utilize AI technologies to minimize manual GRC efforts.
• Maintain a business-impact perspective on risk, track remediation commitments, and escalate gaps to leadership.
• Coordinate evidence, close findings, and create sustainable corrective-action plans.
• Advocate for a global security culture while promoting accountability and risk ownership.
• Translate regulatory topics into clear expectations for employees.
• Collaborate with HR and stakeholders to provide targeted training, awareness, and role-based education.
• Manage the complete vendor security risk lifecycle, including assessments, treatment, remediation, and monitoring.
• Operate supplier security expectations with key stakeholders and escalate systemic vendor-risk trends.
• Govern data protection for intellectual property, manufacturing processes, export-controlled data, and cloud workloads.
• Validate classification, Data Loss Prevention (DLP), access control, and retention standards.
• Oversee security and compliance aspects of business continuity and disaster recovery readiness.
• Define resilience control requirements and validate recovery playbooks, exercises, and evidence.
• Partner with technology and business service owners to address identified gaps.
• A minimum of 7 years of experience in IT GRC, information security, or regulated compliance.
• At least 2 years of experience managing a geographically diverse team is preferred.
• Proven ability to use generative AI and automation responsibly to enhance analysis, evidence operations, knowledge management, and workflow efficiency.
• Experience in evaluating AI risk and governance is preferred.
• Defense experience is strongly preferred.
• Demonstrated experience with CMMC, NIST SP 800-171, and/or DFARS readiness and audit execution.
• Strong oral and written communication skills.
• Ability to lead cultural transformations, influence individuals, and provide technical strategic direction.
• Proven problem-solving and organizational skills.
• Capability to manage multiple programs simultaneously.
• Bachelor’s degree from an accredited college or university or equivalent experience.
• Preferred certifications include CISSP, CISM, CRISC, CGEIT, GRCP, CGRC, GSLC, PMP, or other relevant credentials.
• Must comply with applicable U.S. export-control regulations; access to controlled information may require U.S. Person status or an export-control license.
• Reasonable accommodations provided for applicants with disabilities.
• Full-time remote work arrangement.
LabConnect
Ripple Effect
Binance
biBerk Business Insurance
Get handpicked remote jobs straight to your inbox weekly.