
Senior Manager, Governance Risk & Compliance
Posted 4 hours ago

Posted 4 hours ago
This is a fully remote position, open to applicants in United States.
• Directly oversee the implementation of the enterprise information security GRC program, reporting to the CISO.
• Convert the CISO’s cybersecurity strategy and risk appetite into scalable processes, measurable outcomes, and a defensible compliance stance.
• Manage the security risk lifecycle, which includes assessments, tracking, remediation, and escalating significant risks to the CISO.
• Sustain the security policy framework and translate standards (such as NIST CSF, ISO 27001, SOC 2) into actionable control requirements.
• Oversee compliance activities related to security and audits; maintain documentation and ensure remediation is completed.
• Administer the vendor security risk management program, escalating high-risk vendors and systemic concerns.
• Generate concise risk and compliance metrics and dashboards for the CISO and senior leadership team.
• Mentor GRC team members and serve as a trusted advisor to Security, IT, Legal, Privacy, and various business units.
• Collaborate with the CISO and Sr. Manager of Security Operations to refresh the Strategic Information Security Program.
• Bachelor’s degree in Information Security, Cybersecurity, Information Systems, Computer Science, Business Administration, or a related discipline.
• Over 7 years of experience in information security GRC or risk management.
• Comprehensive understanding of the HIPAA Security Rule, NIST CSF, ISO 27001, SOC 2, and security risk methodologies.
• Proficient in conducting risk assessments, audits, and control testing.
• Capability to effectively communicate security risks to senior leadership.
• Demonstrated ability to mentor and develop GRC team members while fostering collaborative relationships across organizations.
• Extensive knowledge of technology and associated security risks.
• Preferred qualifications include CISSP, CISM, CRISC, CISA, or similar certifications.
• Experience working within a CISO-led security organization or in a regulated environment.
• Medical insurance
• Dental insurance
• Vision insurance
• Health care and dependent care flexible spending account
• 401(k) retirement savings plan with a company match
• Paid time off (PTO) accrues immediately upon start date at a rate of 15 days per year, in line with Sound's PTO policy
• Ten company-paid holidays each year
Thermo Fisher Scientific
EHS Support
FHI 360
BambooHR
Get handpicked remote jobs straight to your inbox weekly.