
Manager, Governance, Risk & Compliance
Posted 5 days ago

Posted 5 days ago
This is a fully remote position, open to applicants in United States.
• Lead the governance, risk, and compliance function encompassing security policies, standards, risk management, audits, third-party risk, and control operations.
• Develop, maintain, and implement global security policies, standards, procedures, control documentation, and exception processes.
• Oversee audit readiness and continuous compliance programs across frameworks such as SOC 2, ISO 27001, GovRAMP, PCI DSS, HIPAA, NIST CSF, NIST 800-53, CCPA/GDPR, and other customer or regulatory requirements.
• Direct GovRAMP and PCI DSS readiness initiatives, including control mapping, evidence collection, remediation tracking, stakeholder coordination, audit preparation, and audit support.
• Facilitate the collection of audit evidence, control testing, remediation tracking, auditor communication, and management responses.
• Maintain the security risk register, which includes identification, assessment, ownership, remediation, acceptance, exception tracking, and executive reporting of security risks.
• Collaborate with control owners across Security, IT, Engineering, Legal, HR, Finance, Product, and Operations to ensure control effectiveness and accountability.
• Oversee third-party and supply chain risk management, involving vendor security reviews, due diligence, risk assessments, contract security input, and remediation tracking.
• Assist with customer security reviews, questionnaires, trust center content, security documentation, and customer-facing compliance responses.
• Create metrics and dashboards for audit status, control health, risk posture, vendor risk, policy exceptions, compliance readiness, and remediation progress.
• Aid in incident response and privacy incident processes by ensuring that regulatory, contractual, audit, and customer notification obligations are understood and tracked.
• Collaborate with the CISO to convey security posture, compliance progress, key risks, control gaps, and trade-offs to executives, customers, auditors, and regulators.
• Drive continuous enhancement of the GRC operating model, focusing on automation, evidence reuse, control rationalization, risk prioritization, and policy lifecycle management.
• A minimum of 6 years of experience in security governance, risk management, compliance, audit, third-party risk, or related cybersecurity roles.
• Experience in managing or supporting audits and compliance programs for SOC 2, ISO 27001, GovRAMP, PCI DSS, HIPAA, NIST 800-53, or similar frameworks.
• Strong understanding of security controls, policy management, risk assessment, control testing, evidence collection, and audit readiness practices.
• Proven experience working with auditors, customers, internal stakeholders, and executive leadership.
• Experience in managing third-party risk or vendor security review programs.
• Ability to convert complex compliance obligations into practical business and technical requirements.
• Strong project management capabilities with the ability to handle multiple audits, risks, remediation efforts, and stakeholder workstreams concurrently.
• Excellent written and verbal communication skills.
• Flexible time off
• Comprehensive medical, dental, and vision plans
• Family planning benefits
• 401(k) retirement savings plan with company match
• Health savings account with company contributions
• Flexible spending account
• Life, accident, and disability coverage
• Business travel insurance
• Employee assistance programs
• Additional well-being benefits
Thermo Fisher Scientific
EHS Support
FHI 360
Sound Physicians
Get handpicked remote jobs straight to your inbox weekly.