Director of Governance, Risk & Compliance
Quick Summary
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Director of Governance, Risk & Compliance based in the United States.
This is a hands-on leadership opportunity to own and evolve an internal Governance, Risk & Compliance (GRC) program while overseeing Managed GRC services for clients. You will shape scalable methodologies, processes, evidence standards, and quality controls while remaining directly involved in complex compliance and security initiatives. The role combines executive-level advisory work with practitioner-level engagement, requiring close collaboration with CISOs, auditors, engineers, control owners, and technical teams. A significant focus will be on federal security programs, including System Security Plans (SSPs), control implementation statements, evidence, POA&Ms, remediation, and responses to government or assessor findings. You will also guide risk assessments, audits, security questionnaires, and compliance programs across frameworks such as NIST, SOC 2, ISO 27001, CMMC, and HIPAA. The position offers the opportunity to lead and develop a growing GRC team while introducing automation and AI-enabled approaches that improve delivery, consistency, and scalability. This is a remote U.S. role with the option to work from home or from a local U.S. office.
- Own and mature the internal GRC program and lead the operational delivery of Managed GRC services, establishing standardized methodologies, processes, templates, evidence requirements, and quality controls.
- Lead risk assessments, control assessments, compliance readiness activities, policy governance, managed audits, managed security questionnaires, and other GRC engagements while managing client commitments, priorities, capacity, quality, and service performance.
- Lead federal compliance activities, including the development and maintenance of System Security Plans, control implementation statements, supporting evidence, POA&Ms, remediation plans, milestones, and responses to government, assessor, and auditor findings.
- Coordinate with engineers, security teams, control owners, and clients to validate how security controls are implemented and ensure documented controls accurately reflect the operating environment.
- Support requirements related to NIST SP 800-53, NIST SP 800-171, FISMA, CMMC, FedRAMP concepts, and agency-specific federal security requirements, including continuous monitoring, assessments, and authorization activities.
- Manage cybersecurity risk and compliance programs covering risk registers, control gaps, treatment plans, exceptions, remediation tracking, SOC 2, NIST, CIS, ISO 27001, PCI DSS, HIPAA, CMMC, and Microsoft security benchmarks.
- Oversee managed audit and security questionnaire methodologies, including audit readiness, evidence management, auditor coordination, findings, remediation, and reusable response and evidence libraries.
- Partner with senior security leadership to operate and strengthen internal compliance initiatives, including SOC 2 Type 2, policy and control governance, third-party risk, customer security reviews, audit coordination, and evidence management.
- Act as a senior GRC advisor to client security, IT, risk, compliance, and executive leaders, translating regulatory requirements into actionable technical and operational security improvements.
- Collaborate with Security Operations, cloud, Microsoft 365, and engineering teams to map compliance requirements to technical implementations, with working knowledge of Azure, Entra ID, Defender, Sentinel, Intune, Purview, and Azure Policy.
- Support vCISO engagements where governance, risk, audit, and compliance expertise is required, while partnering with Sales and Client Success on service scoping, statements of work, pricing, and complex opportunities.
- Lead, mentor, and develop GRC Analysts and Consultants while managing workload, capacity, priorities, quality assurance, escalations, and scalable processes that enable the practice to operate effectively without relying on the Director for every engagement.
- Identify opportunities to use automation and AI to improve GRC delivery, increase consistency, and scale services efficiently.
- Establish measurable progress through early workflow assessments and prioritized improvements, with long-term ownership of the GRC function, SOC 2 Type 2 program, Managed GRC delivery, federal SSP activities, team development, process maturity, and automation.
Requirements
~2 min read- 8+ years of experience in cybersecurity, Governance, Risk & Compliance, security assessment, audit, or a related field, with demonstrated experience leading GRC programs or teams.
- Hands-on experience with NIST SP 800-53, System Security Plans, POA&Ms, control implementation statements, and federal security requirements.
- Proven experience managing audits, evidence programs, risk assessments, control gaps, policies, remediation initiatives, and compliance activities.
- Ability to translate regulatory and compliance requirements into practical technical and operational security controls.
- Strong understanding of frameworks and standards such as SOC 2, NIST, CIS, ISO 27001, PCI DSS, HIPAA, CMMC, and Microsoft security benchmarks.
- Strong client-facing, executive communication, facilitation, and stakeholder management skills, with the ability to communicate effectively with both senior leaders and technical practitioners.
- Ability to work directly with engineers and control owners to understand, validate, and document security control implementations.
- Experience in an MSSP, MSP, consulting, professional services, federal program, or government contractor environment is preferred.
- Experience with Microsoft Azure and Microsoft 365 security technologies is strongly preferred.
- Familiarity with Azure, Entra ID, Defender, Sentinel, Intune, Purview, and Azure Policy is an advantage.
- Relevant certifications such as CISSP, CISM, CRISC, CISA, CGEIT, or similar are valued.
- Demonstrated leadership qualities including low-ego collaboration, initiative, accountability, empathy, situational awareness, and a bias toward practical problem-solving.
- Ability to operate strategically with executives while remaining comfortable engaging deeply with technical details, compliance evidence, assessments, and remediation activities.
What We Offer
~2 min readLocation & Eligibility
Listing Details
- Posted
- October 1, 2026
- First seen
- October 1, 2026
- Last seen
- October 1, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 68%
- Scored at
- October 1, 2026
Signal breakdown
Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.