Source Job

  • Build and lead the Cyber GRC function, including policy, NIST/CIS/ISO frameworks, and regulatory compliance.
  • Manage vendor risk and security assessments across the vendor lifecycle.
  • Drive security awareness, AI governance, and quantified cyber risk reporting.

Cybersecurity GRC Vendor Risk Management NIST CSF

17 jobs similar to Director, Cyber GRC

Jobs ranked by similarity.

US

  • Support enterprise cybersecurity governance, compliance, and risk management programs.
  • Conduct security control assessments, audit readiness, and policy development.
  • Coordinate with technical teams and executive leadership to drive cybersecurity modernization.

ERP International is a nationally respected provider of health, science, and technology solutions supporting government and commercial clients. The company has been named a Top Workplace by WTOP News for 7 years and offers a culture of employee recognition, community outreach, and professional development.

US 3w PTO

  • Lead and advance governance, risk management, compliance, and information security programs to support organizational objectives and regulatory requirements.
  • Manage vulnerability management, third-party risk, security governance, policy development, and AI governance initiatives.
  • Partner with leaders to foster a culture of accountability, risk awareness, and continuous improvement.

Ultimate Medical Academy is a non-profit healthcare educational institution with a national presence, headquartered in Tampa, Florida and founded in 1994. The organization offers online and on-campus programs and fosters a culture of integrity, student success, and team member development.

United States Unlimited PTO

  • Own and strengthen the controls environment, ensuring compliance requirements are effectively implemented and maintained.
  • Support and mature the GRC program, including SOC 2 operations and alignment with frameworks such as NIST.
  • Manage vendor risk assessments, regulatory licensing, and security issue lifecycle across jurisdictions.

Mesh enables consumers to pay and be paid with any asset, bridging crypto payments into everyday commerce. Backed by investors like PayPal Ventures and Paradigm, the company is building infrastructure for the global economy with a small, fast-moving team.

US

  • Lead and mature the GRC program across SOC 2, ISO 27001, PCI DSS, and other compliance frameworks, including audit preparation and evidence collection.
  • Own the annual security risk assessment process using NIST SP 800-30 methodology, including stakeholder interviews and risk scoring.
  • Drive security awareness training, AI governance, and Data Loss Prevention program development while collaborating with cross-functional teams.

RainFocus is a rapidly growing software company that provides an industry-disrupting event management platform for Fortune 500 companies like Adobe, Cisco, and IBM. The company is well-funded, growing fast, and building a culture that is challenging, fun, and exciting.

$147,050–$220,800/yr
US

  • Lead IT governance and risk management, including executive reporting and risk register maintenance.
  • Develop KPI and KRI dashboards to translate complex data into actionable insights for senior leadership.
  • Oversee ITSM governance, ServiceNow optimization, and vendor risk management.

Our partner is a global organization operating in a sophisticated Governance, Risk & Compliance environment, connecting technology, cybersecurity, privacy, and operational risk. It fosters a collaborative culture with a focus on work-life balance and professional development.

$230,000–$270,000/yr
US Unlimited PTO 16w maternity 16w paternity

  • Own and manage federal compliance frameworks including FedRAMP, NIST, CMMC, DFARS, and StateRAMP.
  • Translate regulatory controls into automated tests and machine-readable specifications for continuous authorization.
  • Collaborate with Engineering, Product, and Design to shape product capabilities and influence strategy.

Our partner company is a technology organization focused on federal compliance automation, serving organizations from emerging companies to large enterprises. They operate with a remote-first culture and value autonomy, accuracy, and scalability.

$114,000–$139,000/yr
US

  • Monitor and enforce compliance with security frameworks like NIST CSF, ISO 27001, SOC 2, and regulations such as GLBA, CCPA, and GDPR.
  • Conduct comprehensive risk assessments, develop security policies, and lead internal and external security audits with cross-functional teams.
  • Evaluate third-party vendor security posture, maintain compliance records, and define metrics to assess the success of the security program.

Clear Capital is a national real estate analytics, data solutions and valuation technology company with a simple purpose: to build confidence in real estate decisions to strengthen communities and improve lives. The company values integrity, kindness, and grit, and has been committed to excellence since 2001.

India

  • Lead GRC activities including risk management framework, security assessments, and continuous monitoring for assigned systems.
  • Collaborate with engineering and security teams to integrate GRC principles into system lifecycles and DevSecOps practices.
  • Develop and maintain security documentation, support ATO processes, and provide risk briefings to leadership.

The partner company helps organizations strengthen cybersecurity programs through modern GRC practices and engineering expertise. It is a fully remote organization with a collaborative culture focused on technical excellence and professional growth.

Brazil

  • Lead the GRC strategy, shifting from bureaucratic to strategic enabler focused on real business risk.
  • Manage cyber risk quantification, third-party risk, and continuous compliance programs.
  • Oversee information security governance, AI governance, and IAM governance, reporting to the CISO.

Grupo QuintoAndar is the largest real estate ecosystem in Latin America, covering all phases of the housing journey. The company is valued at over USD 5.1 billion, with a culture of innovation, collaboration, and high performance working with top professionals.

US Unlimited PTO 16w maternity 16w paternity

  • Build and own federal compliance frameworks for FedRAMP, NIST, and CMMC.
  • Interpret controls at the mechanics level and author precise technical guidance.
  • Lead Vanta's machine-readable future with OSCAL and FedRAMP 20x.

Vanta helps businesses earn and prove trust by automating security monitoring and compliance. Founded in 2018, the company has a kind and talented team and is used by thousands of companies.

United States Unlimited PTO

  • Partner with the CISO to define and execute Sardine's security strategy and roadmap.
  • Help identify and prioritize the highest-risk areas across the business, including application security, compliance, and incident response.
  • Support customer-facing security conversations and represent Sardine's security program to auditors and stakeholders.

Sardine is the leading agentic risk platform for fighting financial crime, providing an integrated solution to stop fraud and automate fraud operations. The company is a fast-growing startup with a remote-first culture and hubs in the US, Canada, and Brazil.

$180,000–$230,000/yr
US

  • Lead day-to-day management of cybersecurity and information security programs, including schedules, milestones, and performance metrics.
  • Serve as the primary liaison between executives, cybersecurity teams, and operational stakeholders, facilitating governance forums and executive reviews.
  • Support strategic planning, risk management, and organizational change initiatives to modernize cybersecurity capabilities.

ERP International provides health, science, and technology solutions to government and commercial sectors. Founded in 2006, the company is headquartered in Laurel, MD, with satellite offices nationwide and has been recognized as a Top Workplace for seven consecutive years.

$133,109–$239,596/yr
Global Unlimited PTO

  • Act as a trusted advisor to business leaders, bridging security risks and business priorities.
  • Lead security assessments, risk reviews, and remediation planning for new products and enterprise changes.
  • Maintain clear visibility of security risk, control health, metrics, and dashboards, escalating when needed.

Experian is a global data and technology company, powering opportunities for people and businesses around the world. With a team of 25,200 people in 32 countries, they foster an inclusive, purpose-driven culture and have been recognized as a World's Best Workplace in 2025.

$156,500–$195,000/yr
US

  • Develop and execute multi-channel campaigns to drive leads for risk advisory services.
  • Partner with product and BD to align GTM strategy and optimize sales pipeline.
  • Use data and storytelling to increase market awareness and revenue in IT security.

Aprio is a top 20 CPA and advisory firm with more than 3,200 team members across 40 U.S. and international offices. It combines proven expertise and strategic foresight for fast-growing industries, offering a collaborative and progressive culture.

US

  • Lead Enterprise Security Engineering and SecOps, directing a high-performing team while owning operational defense.
  • Architect Zero Trust Architecture transition, implementing micro-segmentation and identity-based controls.
  • Oversee 24/7 MDR/SOC partnerships, incident response, and risk-based vulnerability management.

Virta Health is on a mission to reverse metabolic disease in one billion people through innovations in technology, personalized nutrition, and virtual care delivery. They have raised over $350 million and partner with large health plans, employers, and government organizations, with a values-driven culture emphasizing ownership, transparency, and evidence-based decision-making.

$127,200–$205,100/yr
Global Unlimited PTO

  • Own and continuously improve Camunda's Information Security Management System (ISMS), driving measurable improvements.
  • Drive security audit cycles for ISO 27001, SOC 2, and future frameworks with minimal supervision.
  • Review information security requirements in customer contracts and lead responses to complex security questionnaires.

We are the enterprise platform for agentic orchestration, enabling organizations to coordinate AI agents, people, and systems across complex business processes. We are a fully remote, global team trusted by over 700 organizations, named a GP Bullhound Next Unicorn and Great Place to Work certified.

US Australia 18w maternity 18w paternity

  • Own the full technology and security remit, including enterprise infrastructure, security, identity, applications, and workplace technology.
  • Lead and grow three functions: IT & Security Operations, Cloud Platform Engineering, and GRC.
  • Mature security operations with automation and serve as customer zero for the company's own platform.

UpGuard builds a Cyber Risk Posture Management platform that integrates security ratings, threat intel, and agentic AI to help organizations manage cyber risk. They are a certified Great Place to Work with a lean, high-growth culture and a global remote team.