
GRC Lead
Posted 12 hours ago

Posted 12 hours ago
This is a fully remote position, open to applicants in United States.
• Take ownership of the complete cybersecurity Governance, Risk, and Compliance (GRC) program, which encompasses governance frameworks, risk management processes, and compliance activities.
• Spearhead CMMC readiness initiatives, which involve scoping, conducting gap assessments, developing Plans of Action & Milestones (POA&Ms), and coordinating with the C3PAO throughout the assessment process.
• Oversee the control framework by aligning controls with standards, monitoring ownership, and driving remediation efforts.
• Develop and uphold an evidence library, ensuring that all artifacts are accurate, comprehensive, and prepared for audits.
• Organize and facilitate both internal and external audits, assessments, and third-party evaluations; act as the primary contact for auditors.
• Maintain the organizational risk register, guide risk assessments, and monitor the closure of risk treatment decisions.
• Collaborate with IT, engineering, legal, and operations teams to integrate compliance requirements into various processes, tools, and projects.
• Monitor changes in regulatory and compliance landscapes and provide guidance to leadership.
• Report directly to the Senior Director of Cybersecurity within the IT department.
• Bachelor’s degree in information security or a related discipline with 8 years of experience in GRC, information security compliance, or a related area, or a Master’s degree in information security or a related field with 6 years of experience.
• Relevant certifications such as CISSP, CISA, CRISC, CISM, or CompTIA Security+ are required.
• Direct, practical experience with CMMC Level 2 or Level 3 or preparation for NIST SP 800-171 implementation and assessment is necessary.
• Proven ability to manage a control framework, including control mapping, ownership assignment, evidence collection, and gap remediation.
• Experience in drafting and maintaining information security policies and procedures is essential.
• Demonstrated history of supporting audits or third-party evaluations, including evidence preparation and coordination with auditors.
• Capability to work independently, manage several workstreams concurrently, and engage cross-functional stakeholders without direct authority.
• Strong written and verbal communication skills, including the ability to convey technical compliance requirements to non-technical audiences.
• CMMC assessor certification such as CCP, CCA, or LCCA is preferred.
• Previous experience in building or enhancing a GRC program from an early stage is preferred.
• Background in coordinating with C3PAOs or DCSA assessors is preferred.
• Travel to Voyager facilities, operational sites, and partner locations may be necessary.
• Participation in security exercises, incident response, or urgent remediation outside of regular business hours may be required occasionally.
• Must be a U.S. Person: U.S. citizen, lawful permanent resident of the U.S., or a protected individual as defined by 8 U.S.C. § 1324b(a)(3).
• Must qualify to obtain necessary export authorizations from the U.S. Department of State or Department of Commerce.
• Flexible Time Off (FTO).
• Extensive medical, dental, and vision coverage for employees and their families, with a substantial portion of premiums covered by the company and many benefits available at 100% for employees.
• Flexible and affordable gym memberships with over 12,700 options nationwide, including free on-demand workout videos prior to enrollment.
• 401(k) retirement plan featuring a 50% company match on contributions up to 8%.
• Employee wellness programs that promote both physical and mental health.
• Additional voluntary benefits and employee support resources.
• Opportunity to collaborate with a highly skilled team in an innovative, mission-driven setting.
Jerry
Bomb Party Official
HighlightTA
BeOne Medicines
Get handpicked remote jobs straight to your inbox weekly.