
Senior GRC Manager
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in United States.
• Lead and manage the governance calendar along with the ongoing GRC operating cadence, which includes risk committee activities, policy publication timelines, audit milestones, and control validation programs.
• Supervise audit readiness and evidence management across relevant compliance frameworks.
• Administer and enhance the enterprise risk management program, focusing on risk identification, maintaining the risk register, tracking ownership, conducting risk reviews, and preparing executive reports.
• Oversee the entire policy lifecycle, encompassing drafting coordination, review processes, publication, communication, and alignment on exception management.
• Direct control effectiveness validation, which includes reviewing control designs, testing operational effectiveness, establishing evidence standards, utilizing sampling methodologies, and ensuring follow-up on remediation efforts.
• Manage access governance programs from a compliance and risk viewpoint.
• Support AI governance, customer assurance, architecture reviews, and security review procedures.
• Monitor audit findings, risk remediation activities, customer diligence requests, and program assessments, while escalating significant risks and barriers.
• Maintain customer-facing security assurance materials, evidence packages, and trust documentation.
• Prepare reports for leadership that detail governance decisions, risk posture, compliance status, and remediation progress.
• Collaborate with Security, Internal IT, Legal, Privacy, Compliance, and business stakeholders on evidence collection, testing, remediation planning, and validation.
• Foster evidence quality, establish repeatable governance processes, ensure accountability, and promote continuous improvement.
• Strong understanding of governance, risk management, compliance programs, policy management, and control validation methodologies.
• Extensive knowledge of SOC 2, PCI, ISO 27001, CMMC, and NIST-aligned standards.
• Expertise in risk identification, administration of risk registers, tracking ownership, conducting risk assessments, and executive reporting.
• Proficient in policy development, procedure documentation, and writing for executive-level audiences.
• Experience in conducting control effectiveness reviews, operational effectiveness testing, evidence validation, remediation oversight, and audit support.
• Familiarity with governance operating models, committee facilitation, calendar management, and following through on governance decisions and remediation actions.
• Strong skills in executive communication, presentations, and reporting.
• Knowledge of access governance, exception management, customer assurance initiatives, and cross-framework control mapping.
• Understanding of AI governance, third-party risk management, and privacy governance.
• Proven stakeholder management, relationship-building, accountability, and issue escalation abilities.
• Capacity to prioritize and manage multiple initiatives while meeting deadlines in a fast-paced environment.
• Bachelor’s degree in a relevant field or an equivalent combination of education and professional experience.
• At least seven (7) years of experience in GRC, Security Compliance, IT Audit, Enterprise Risk Management, or Security Program Management.
• Experience in managing audit readiness, evidence collection, control testing, and compliance initiatives across various frameworks.
• Experience in supporting risk committees, governance forums, executive reporting, and enterprise-wide policy management.
• Preferred: experience with GRC technology platforms and evidence-management workflows.
• Preferred: involvement in customer-facing assurance programs, due diligence, vendor security assessments, and security trust initiatives.
• Preferred: credentials such as CISSP, CISA, CRISC, ISO Lead Auditor, ISO Lead Implementer, PCI QSA, or similar qualifications.
• Preferred: experience in highly regulated environments, client-assurance-focused sectors, or defense-adjacent fields.
• Ability to sit at a desk and work on a computer for extended periods.
• Must be capable of lifting up to 15 pounds on occasion.
• Comprehensive health, dental, and vision insurance.
• Competitive salary with performance-based bonuses.
• Opportunities for professional development and training.
• Flexible work hours and remote work options.
• Employee wellness programs and resources.
ICON plc
US Anesthesia Partners
MultiplyMii
Paychex
Get handpicked remote jobs straight to your inbox weekly.