Source Job

20 jobs similar to Cybersecurity Governance and Risk Management (GRC) Lead

Jobs ranked by similarity.

$70,000–$77,000/yr
US

  • Perform enterprise risk assessments using NIST CSF, SOC 2, and CIS frameworks.
  • Develop and execute security awareness programs including training and phishing simulations.
  • Support governance and control management by maintaining policies and control libraries.

Protective helps protect customers against life's uncertainties by providing insurance and peace of mind. The company offers a collaborative environment with a focus on employee wellbeing and work-life balance.

US

  • Lead the design and governance of control frameworks and risk workflows within the GRC platform, ensuring alignment with compliance requirements like HIPAA, HITRUST, and NIST.
  • Oversee risk assessments, control testing, and vendor evaluations to identify and mitigate security risks.
  • Manage policy lifecycle, audit coordination, and reporting on control effectiveness and risk indicators.

USAP is a healthcare organization focused on providing anesthesia services and patient safety. It is a growing company with a culture of security, compliance, and collaboration.

$150,000–$170,000/yr
US Unlimited PTO

  • Lead the governance, risk, and compliance function across security policies, standards, risk management, audits, and third-party risk.
  • Own audit readiness and ongoing compliance programs across frameworks such as SOC 2, ISO 27001, GovRAMP, PCI DSS, HIPAA, NIST CSF, and more.
  • Manage third-party and supply chain risk management, including vendor security reviews, due diligence, and remediation tracking.

Accela provides government software solutions to improve efficiency, increase citizen engagement, and enable thriving communities. They have been an industry leader for nearly 20 years and are committed to diversity, equity, and inclusion.

US

  • Lead enterprise IT infrastructure and cybersecurity operations for a government contracting company.
  • Ensure compliance with CMMC 2.0, NIST, and DFARS regulations across all systems.
  • Manage risk, business continuity, and enterprise systems governance including DAR and COOP planning.

Lynker Corporation is a leading provider of innovative solutions in weather and climate science. As an employee-owned business, Lynker combines scientific expertise with mature, results-driven processes to serve government clients and employs a team of 500-1000 staff.

$180,000–$230,000/yr
US

  • Lead day-to-day management of cybersecurity and information security programs, including schedules, milestones, and performance metrics.
  • Serve as the primary liaison between executives, cybersecurity teams, and operational stakeholders, facilitating governance forums and executive reviews.
  • Support strategic planning, risk management, and organizational change initiatives to modernize cybersecurity capabilities.

ERP International provides health, science, and technology solutions to government and commercial sectors. Founded in 2006, the company is headquartered in Laurel, MD, with satellite offices nationwide and has been recognized as a Top Workplace for seven consecutive years.

US 3w PTO

  • Lead and advance governance, risk management, compliance, and information security programs to support organizational objectives and regulatory requirements.
  • Manage vulnerability management, third-party risk, security governance, policy development, and AI governance initiatives.
  • Partner with leaders to foster a culture of accountability, risk awareness, and continuous improvement.

Ultimate Medical Academy is a non-profit healthcare educational institution with a national presence, headquartered in Tampa, Florida and founded in 1994. The organization offers online and on-campus programs and fosters a culture of integrity, student success, and team member development.

India

  • Lead GRC activities including risk management framework, security assessments, and continuous monitoring for assigned systems.
  • Collaborate with engineering and security teams to integrate GRC principles into system lifecycles and DevSecOps practices.
  • Develop and maintain security documentation, support ATO processes, and provide risk briefings to leadership.

The partner company helps organizations strengthen cybersecurity programs through modern GRC practices and engineering expertise. It is a fully remote organization with a collaborative culture focused on technical excellence and professional growth.

US

  • Lead end-to-end service delivery operations for cybersecurity and cloud security professional services engagements.
  • Own the delivery lifecycle for FedRAMP advisory, implementation, continuous monitoring, and related security programs.
  • Develop operational strategies and governance models ensuring compliance with NIST 800-53, FedRAMP, and DoD frameworks.

This company specializes in cybersecurity and cloud service delivery for federal agencies, managing mission-critical environments with strict compliance requirements. They are a mid-sized organization focused on scalable operations and measurable outcomes.

$175,000–$265,000/yr
US Unlimited PTO

  • Develop and execute cybersecurity strategy, roadmap, and governance to protect Voyager's information systems and mission-critical environments.
  • Lead security operations, incident response, vulnerability management, and compliance with government regulations like CMMC and NIST.
  • Oversee security architecture, risk management, and team leadership to enable secure innovation in aerospace and defense.

Voyager is an innovative space, defense, and national security technology company delivering transformative, mission-critical solutions. It fosters a culture where innovation thrives, curiosity is rewarded, and impact is real, with a team of doers, thinkers, and builders united by purpose.

US

  • Lead GRC initiatives to protect the business and strengthen technology risk posture.
  • Translate complex risk data into clear insights and action plans for leadership.
  • Build and improve policies, standards, and procedures for governance and compliance.

Herbalife is a global nutrition company focused on developing and distributing dietary supplements and personal care products. The company employs thousands worldwide and fosters a collaborative, fast-paced environment with a culture of accountability and continuous improvement.

US

  • Lead ISSO activities to ensure confidentiality, integrity, availability, and compliance of enterprise applications and information systems.
  • Manage RMF processes including ATO packages, continuous monitoring, risk assessments, and accreditation documentation within eMASS.
  • Implement and maintain compliance with DISA STIGs, NIST 800-53 controls, and federal cybersecurity requirements.

Jobgether is a platform that uses AI-powered matching to connect candidates with job opportunities. The company facilitates the hiring process by sharing top-fitting candidate shortlists with partner companies, focusing on efficiency and objectivity.

$133,109–$239,596/yr
Global Unlimited PTO

  • Act as a trusted advisor to business leaders, bridging security risks and business priorities.
  • Lead security assessments, risk reviews, and remediation planning for new products and enterprise changes.
  • Maintain clear visibility of security risk, control health, metrics, and dashboards, escalating when needed.

Experian is a global data and technology company, powering opportunities for people and businesses around the world. With a team of 25,200 people in 32 countries, they foster an inclusive, purpose-driven culture and have been recognized as a World's Best Workplace in 2025.

US Unlimited PTO

  • Manage and implement complex controls frameworks for large systems consisting of Cloud infrastructure and SaaS services.
  • Design and develop automation solutions for evidence collection across Cloud infrastructure, endpoints, and SaaS services.
  • Conduct risk assessments across business units and processes, identifying risk findings and recommending remediation strategies.

Virtru is a data protection platform that enables secure sharing without sacrificing security or privacy. Backed by top venture capital firms, the company helps Fortune 500 companies and government agencies achieve true data security with freedom to share.

US

  • Serves as a cybersecurity SME for Assessment and Authorization (A&A) of information systems, applying NIST 800-53 security controls and the Risk Management Framework (RMF) process.
  • Possesses five years of relevant RMF, NIST, and A&A experience, including assessing security controls for large, complex organizations like DLA.
  • Briefs senior management on authorization progress and understands cybersecurity in emerging technology areas such as Cloud and Industrial Control Systems.

Horizon Industries Limited is a dynamic IT and Management Consulting firm based in the Washington, DC area, providing full-cycle IT consulting and management support to both private and public sectors. Founded in 1996, the company prides itself on a diverse, employee- and family-centric culture with a focus on professional growth.

Philippines

  • Drive compliance, risk management, and security assurance as a GRC Specialist.
  • Own third-party risk management and maintain security documentation.
  • Support audits, self-assessments, and customer security inquiries.

Avid provides technology and collaboration tools for creators to entertain, inform, educate, and enlighten the world. The company fosters a culture of passion, customer focus, and innovation, with employees who believe in their mission.

$27,000–$29,700/yr
Mexico

  • Operate as a trusted advisor to executive teams, guiding them through complex cybersecurity challenges and building security programs.
  • Develop enterprise security strategies, roadmaps, and governance frameworks, translating technical risks into business impact.
  • Lead risk assessments, incident response planning, and compliance initiatives aligned with NIST, CIS, and ISO frameworks.

DYOPATH simplifies technology for clients while investing deeply in its people. Recognized as a Great Place to Work for five consecutive years, the company prides itself on building exceptional teams to deliver secure solutions.

US

  • Manage and maintain version control of all documentation related to compliance for each standard and track implementation status of security controls.
  • Oversee preparation and execution of external compliance audits, including facilitating security assessments.
  • Support mapping of compliance requirements to security control implementation using agile development processes.

Hypori is a high-growth cybersecurity SaaS company providing a virtual workspace platform for secure mobile access. Backed by $55M in funding, the company is expanding into commercial and regulated markets with a focus on innovation and security.

LATAM

  • Coordinate governance activities for strategic Technology and Cybersecurity programs in LATAM.
  • Support the Vulnerability Management Program and M&A technology integration initiatives.
  • Develop KPIs, dashboards, and executive reports to drive risk-based decision-making.

Experian is a global data and technology company that drives opportunities for people and businesses worldwide. With 25,200 employees in 32 countries, the company is people-centric, inclusive, and recognized as a top workplace.

$115,000–$145,000/yr
Global

  • Serve as a hands-on GRC advisor for customers, guiding them through risk assessments, audit preparation, and control rollouts.
  • Help customers navigate audits like SOC 2, ISO 27001, HIPAA, PCI-DSS, and NIST, translating requirements into practical steps.
  • Spot GRC complexity early and partner with Support and Customer Success to own escalations requiring real GRC expertise.

Compyl is a GRC and automated security compliance platform built by security practitioners. Backed by Venture Guides, Contour Venture Partners, and Armory Square Ventures, it is a high-growth Series A company.

US 3w PTO

  • Lead quality assurance for RMF authorization packages to ensure completeness and readiness for government review.
  • Coordinate with RMF analysts, ISSOs, system owners, and technical stakeholders to validate security documentation and evidence.
  • Mentor team members on documentation standards and best practices while tracking assessment readiness metrics to reduce rework.

True Zero Technologies is a veteran-owned small business that enables people and technology to drive quality outcomes. The company has been named a Best Place to Work multiple times and made the Inc. 5000 list of fastest-growing companies, reflecting its people-first culture and commitment to excellence.