Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

GRC Lead

$95k - $120k

NextgenID

Location: Onsite – Fairfax, VA · U.S. Citizen Required (FedRAMP / Federal Customer) Type: Full Time NextgenID is hiring a GRC Lead to own our governance, risk, and compliance program end-to-end. We verify and credential identity at the highest assurance level (IAL3) for federal agencies and enterprises, which means our authorizations — FedRAMP, Kantara, UK digital identity (DIATF/DVS), and the security assurances our customers depend on — are core to the business. You own the compliance calendar, the risk register, the audit and assessment relationships, and the evidence that proves our posture. You lead a GRC Analyst and report to the CTO & EVP. This is a working leadership role: you set the program, and you also do the senior, judgment-heavy work yourself. Salary Range: $95,000–$120,000 Role Fit & Non-Negotiables Onsite at our Fairfax, VA headquarters. This is a hands-on leadership role, not remote. U.S. citizen, required for FedRAMP and federal-customer obligations. Five or more years in governance, risk, and compliance, including ownership of a formal authorization or audit program. Direct experience with FedRAMP, FISMA, or an equivalent federal framework, and with third-party (3PAO) assessments. Able to make and defend risk decisions and to sign off on evidence that goes to assessors and customers. What You Will Own (90 to 180 Day Outcomes) A single, authoritative compliance calendar and program plan across FedRAMP, Kantara, UK DVS, SOC 2, and customer questionnaires. The FedRAMP 20x authorization effort carried toward submission, including the 3PAO relationship, Trust Center publication, and machine-readable (OSCAL) control package. A current, governed risk register and monthly POA&M process, with documented risk decisions and compensating controls. Kantara 800-63A (IAL3) certification maintained, with a planned path from Rev 3 to Rev 4. A functioning GRC tooling and evidence pipeline (Vanta) that keeps documentation and submissions current with less manual effort. A GRC Analyst onboarded, directed, and delivering, with the departing analyst’s and intern’s workstreams fully absorbed. Core Responsibilities Compliance Program Leadership — own the program, the calendar, and the standard. Own the compliance calendar and program plan across FedRAMP, FISMA, Kantara/NIST 800-63, UK DIATF/DVS, SOC 2, and ADA. Set GRC policy, standards, and process, and keep them current and version-controlled. Report compliance status, risk posture, and audit readiness to the CTO and leadership. Authorizations & External Assessments — lead audits, 3PAOs, and certification bodies. Lead FedRAMP 20x authorization: 3PAO selection and relationship, ATO timeline, Trust Center publication, and the OSCAL submission strategy. Own the Kantara certification program (800-63A, IAL3) and the Rev 3 to Rev 4 transition strategy. Own the UK DVS / DIATF certification, including scoping and gap-assessment leadership. Risk Management — own the risk register and the decisions that carry risk. Maintain the enterprise and vendor risk register and govern the monthly POA&M process. Make and document risk decisions, risk adjustments, and compensating controls, including vendor vulnerabilities. Set vulnerability remediation priorities and pentest readiness with the engineering and DevSecOps leads. Vendor & Customer Assurance — prove our posture to third parties without slowing the business. Own third-party and vendor risk assessments across our tooling and supply chain. Own the security-questionnaire program (final review and sign-off) and represent our posture to customers and prospects. Partner with Growth and Legal on assurance commitments and trust-center content. Team & Tooling — deliver the program through the analyst and the toolchain. Lead, mentor, and prioritize the work of the GRC Analyst and absorb the departing intern’s workstreams. Own GRC tooling strategy and the evidence pipeline (Vanta, Qualys, OSCAL). Coordinate engineering, DevSecOps, operations, and legal contributors to compliance deliverables. What You Must Have Already Done Owned a federal authorization or audit program (FedRAMP, FISMA, StateRAMP, or equivalent) through a 3PAO or independent assessment. Built and maintained a risk register and a POA&M process, and defended risk decisions to an assessor or customer. Interpreted a control framework (NIST 800-53, 800-63, or ISO 27001) and translated it into policy, procedure, and evidence. Managed an external assessor or certification-body relationship end to end. Led or mentored analysts and coordinated cross-functional contributors to a compliance deadline. Required Qualifications Five or more years in governance, risk, and compliance, security compliance, or audit, with program ownership. Direct experience with FedRAMP and/or FISMA, including continuous monitoring (ConMon) and 3PAO assessment. Working command of NIST SP 800-53 and NIST SP 800-63 (identity assurance), and of risk-assessment methodology. Experience owning a risk register, a POA&M process, and a vendor-risk program. Experience managing external assessors, auditors, or certification bodies. Experience with GRC or compliance-automation tooling (Vanta or similar) and vulnerability tools (Qualys or Nessus). Ability to make, document, and defend risk decisions. Excellent written and verbal communication for assessors, customers, and executives. Must be able to work onsite in Fairfax, VA; U.S. citizen (FedRAMP / federal customer). Preferred Qualifications CISA, CRISC, CISSP, or CISM certification. Experience with Kantara / NIST 800-63 identity assurance (IAL2 / IAL3) certification. Experience with international identity frameworks (UK DIATF / DVS) or ISO 27001 certification. Experience with OSCAL or machine-readable control packages for FedRAMP 20x. Background in a federal-contractor or IDaaS / identity-security environment. Familiarity with SOC 2 and ADA / Section 508 accessibility assessments. You own the calendar in your head: you know what is due, to whom, and what evidence proves it. You make risk calls and defend them with documented reasoning, not hand-waving. You turn a framework into a short list of what has to be done, and get it done. You keep assessors and customers confident because your evidence is clean and current. You lead through other teams, coordinating engineering and operations without owning their headcount. What Success Looks Like FedRAMP 20x reaches submission on schedule, with a published Trust Center and a machine-readable control package. Kantara IAL3 certification stays current, with a credible Rev 4 transition plan. A single risk register and monthly POA&M process run on cadence, with documented risk decisions. Customer questionnaires and external assessments are answered accurately and on time, with no material findings from poor evidence. The GRC Analyst is productive and the departing analyst’s and intern’s workstreams continue without gaps. Why NextgenID NextgenID builds the compliance-grade identity infrastructure that federal agencies and enterprises rely on to verify and credential identity at IAL3. Compliance is not overhead here — it is the product’s license to operate. As GRC Lead, you own the authorizations and the evidence that let us sell and deliver, and you will see your work directly in every certification we hold and every customer we win. For the right person, this is the path to a GRC Manager or Director role as the program grows. NextgenID focuses on improving the efficiency and speed of mission critical, high assurance identity enrollment and credentialing operations that are essential to hundreds of millions of users worldwide. Our technologies are engineered to dramatically reduce the time and cost of capturing accurate data when creating a digital identity. Our industry-neutral solutions revolve around "Supervised Remote-Identity Proofing" to automatically, securely and "remotely" perform all proofing, enrollment and credentialing processes and workflows for our customers. The industry is taking notice as we are now working with some of the largest agencies in the US Defense, intelligence, Civil, State and Local government markets, as well as other national governments and commercial organizations throughout the world. #J-18808-Ljbffr NextgenID

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the GRC Lead in Brooklyn, NY vacancy
  • Litehouse is seeking a Security & Compliance Lead to own the compliance program across SOC 2 and GDPR. You will verify security controls...  ...controls meet requirements. Ideal candidates have 4+ years in GRC, relevant certifications, and hands-on IaC review experience. This... 
    Suggested
    Remote work

    Litehouse

    Brooklyn, NY
    1 day ago
  • Thinking Machines Lab Inc. is seeking a GRC Lead based in San Francisco to drive certifications (SOC 2, ISO 27001, FedRAMP) from scoping to close. You will manage audits, controls, and risk assessments, and shape the roadmap for the GRC function while interfacing directly... 
    Suggested

    Thinking Machines Lab Inc.

    Brooklyn, NY
    3 days ago
  • $158k - $184k

    Washington, D.C. Backed by leading Silicon Valley investors, Peregrine helps public safety organizations, state and local and governments...  ...Certifications 10+ years of experience in information security, GRC, security assurance, or cybersecurity risk management, including... 
    Suggested
    Contract work
    For contractors
    For subcontractor
    Work at office
    Local area
    Relocation
    Visa sponsorship

    Peregrine Technologies, Inc.

    Brooklyn, NY
    5 days ago
  • Peregrine Technologies, Inc. in Washington, DC, is seeking a senior Governance, Risk, and Compliance leader to own FedRAMP High and establish security foundations for DoD IL4-IL6 deployments. This role requires translating federal requirements into implementable controls...
    Suggested

    Peregrine Technologies, Inc.

    Brooklyn, NY
    5 days ago
  • $121k - $173k

     ...with Mitsubishi UFJ Financial Group (MUFG), one of the world’s leading financial groups. Across the globe, we’re 150,000 colleagues, striving...  ...Control Monitoring (CCM) program within the Cybersecurity GRC organization. This role will design and implement automated control... 
    Suggested
    Full time
    Work at office
    Local area
    Remote work

    MUFG

    Jersey City, NJ
    3 days ago
  •  ...Technologies, Inc. is hiring a Public Sector Compliance Manager to lead the company’s compliance program for government contracting in...  ...contracts, coordinating with Legal, People Ops, Finance, Contracts, and GRC. The role requires organizational discipline, strong project... 

    Peregrine Technologies, Inc.

    Brooklyn, NY
    4 days ago
  • $95.6k - $162.4k

     ...partners, we serve the world's most sophisticated clients using leading technology and exceptional service. Senior Lead, Technology Risk...  ...SOC 2. Experience leveraging governance, risk, and compliance (GRC) platforms and workflow tools such as Archer, ServiceNow, AuditBoard... 
    H1b
    Worldwide
    Flexible hours

    Koitecc Solutions

    Brooklyn, NY
    4 days ago
  •  ...conversations that involve security or compliance. Qualifications Required Experience and Capabilities 4+ years in security and compliance (GRC), including direct, hands‑on ownership of a compliance program. Relevant certification: CISSP, CIPP with CIPPE/E for EU GDPR, CISA,... 
    Contract work
    For contractors
    For subcontractor
    Work at office
    Remote work
    Flexible hours

    Litehouse

    Brooklyn, NY
    1 day ago
  • $100k - $125k

     ...redefining how businesses connect their world. The Compliance Team Lead is an individual contributor role positioned at the emerging lead...  ...& Experience 3-5 years of experience in information security, GRC, compliance, privacy, or audit functions Hands-on experience... 
    Remote work

    Celigo, Inc.

    Brooklyn, NY
    2 days ago
  • SHINE Technologies, LLC is seeking a Senior Manager, Information Security to lead SHINE’s enterprise information security program, focusing on governance, risk management, and compliance. This role oversees day-to-day security operations, policy ownership, and the risk... 

    SHINE Technologies, LLC

    Brooklyn, NY
    1 day ago
  •  ...and LLM orchestration. What you’ll do As the sole dedicated ERM Lead for Stripe MALPB, you will own the enterprise risk program end-to...  ...records, automatically flagging anomalies or control deficiencies. GRC System Engineering: Partner with technical teams to optimize and... 
    Remote job

    Nubeero Limited

    Brooklyn, NY
    5 days ago
  • $17 - $27.75 per hour

     ...deliver an exceptional customer experience * Serves as a Brand Ambassador embodying of Coach values and increasing brand awareness * Leads implementation of Company initiatives and support full operation of the business * Maintain a growth mindset for business and... 
    Minimum wage
    Shift work

    Tapestry

    Flushing, NY
    2 days ago
  • $20 per hour

     ...Job Description Job Description   We are hiring immediately for a part time FOH LEAD SUPERVISOR position. Location : BAC 525 - 525 Washington Boulevard Jersey City, NJ 07310 Note: online applications accepted only. Schedule : Part time schedule; Tuesday... 
    Hourly pay
    Full time
    Part time
    Local area
    Immediate start
    Remote work
    Worldwide
    Flexible hours

    Eurest

    Jersey City, NJ
    10 days ago
  •  ...a Head of Cybersecurity, Risk & Compliance in Long Beach, CA to lead governing, risk, and compliance programs. The role reports to the...  ...architecture and incident response. With 8+ years in cybersecurity/GRC and 3+ in leadership, you will manage security engineering, third... 

    MyGeeksGuide Ltd

    Brooklyn, NY
    1 day ago
  • Celigo, Inc. is seeking a Compliance Team Lead to own day-to-day security compliance and risk operations, coordinating SOC 2 audits, policy...  ..., IT, Legal, and Finance, and requires 3-5 years in information security, GRC, privacy, or audit #J-18808-Ljbffr Celigo, Inc.
    Remote job

    Celigo, Inc.

    Brooklyn, NY
    5 days ago
  • Sims Metal (Sims) is seeking a Maintenance Foreman to supervise and coordinate the loading, unloading, sorting, processing, and storage of recyclable materials at our outdoor facility. You will manage equipment, enforce safety policies, train staff, and ensure productivity...

    Fall Creek Farm & Nursery

    Jersey City, NJ
    22 hours ago
  • Chukchansi Gold Resort & Casino in California is seeking an Environmental Services Supervisor (EVS) to lead the housekeeping team on shift, ensuring policy compliance, cleanliness, safety, and exceptional guest service. You will supervise EVS staff, schedule, train, and... 
    Shift work

    Chukchansi Gold

    Brooklyn, NY
    5 days ago
  • Panelmatic, Inc. in Houston seeks an Integration Supervisor to lead the day-to-day operations of the integration team. You will supervise personnel, coordinate production activities, and ensure high-quality control panels and automation systems. The ideal candidate will... 

    Panelmatic

    Brooklyn, NY
    3 days ago
  • Allied Benefit Systems, LLC in Chicago, IL seeks a Supervisor, Stop Loss to assist the Manager with overseeing the department, auditing stop loss filings, reimbursements, and related cash advance claims. Collaboration with the Stop Loss Data Specialist and Reimbursement...
    Remote job

    Allied Benefit Systems, LLC

    Brooklyn, NY
    1 day ago
  • Patient First in Kentucky seeks a certified Radiologic Technologist to supervise X-ray staff, coordinate department operations, and ensure compliant imaging procedures. You will process images using DR and archive via PACS, while addressing physician requests with prompt...
    Local area

    Patient First

    Brooklyn, NY
    3 days ago
  • R+L Carriers is seeking an Outbound Router Supervisor in Kearny, NJ. You will manage driver and freight-handler operations, coordinate dock activities, and ensure timely dispatch of LTL loads at our Kearny Service Center. The role requires proven leadership, strong organizational...

    R+L Carriers

    Kearny, NJ
    4 days ago
  • Vistra's Luminant Generation Company LLC is seeking a Protection and Control Supervisor to lead a team of P&C technicians across fossil generation. You will drive compliance, troubleshoot relays and metering, and oversee upgrades and capital projects to improve plant reliability... 

    TXU Energy

    Brooklyn, NY
    2 days ago
  • Sentara Therapy Center - Cancer Rehab at Brock Cancer Center in Norfolk, VA is seeking a Cancer Rehab Supervisor to lead daily operations of our oncology rehabilitation services. You will supervise clinical staff and coordinate multidisciplinary care to maintain high-quality... 

    Sentara Health Plans

    Brooklyn, NY
    5 days ago
  • Prime Controls, L.P. in Colorado seeks an Instrumentation and Controls Supervisor to lead a team of technicians in set-up, commissioning, and testing of instrumentation and control systems. This role requires coordinating with electrical contractors, troubleshooting issues... 
    For contractors

    Prime Controls Lp

    Brooklyn, NY
    1 day ago
  • Sinai Post Acute in Newark, NJ is seeking a Dietary Supervisor to oversee the food service department, ensure the delivery of high-quality nutrition, supervise dietary staff, and maintain compliance with dietary plans and sanitary regulations. This full-time role includes...
    Full time

    Sinaipostacutecare

    Brooklyn, NY
    4 days ago
  • Three D Metals, Inc. is seeking a Production Supervisor for their Liverpool Production facility in Kentucky. The role involves overseeing daily operations, supervising machine operators, and ensuring efficient production schedules. Candidates should have at least 7 years...

    Three D Metals, Inc.

    Brooklyn, NY
    2 days ago
  • Topgolf International in Chesterfield, MO seeks a Front of House Supervisor to lead and coach a diverse team, ensuring top-quality service and smooth operations. You will monitor performance, address guest concerns, and collaborate across departments to maintain safety... 

    Topgolf International

    Brooklyn, NY
    4 days ago
  • California State University Long Beach is seeking an Assistant Grounds Manager to support the Grounds Manager in daily operations, supervision, and policy enforcement. This role focuses on leadership of crews, adherence to campus standards, and contributing to sustainable...

    The California State University

    Brooklyn, NY
    4 days ago
  • Ensemble Health Partners is seeking a Patient Access Supervisor Champion to organize and coordinate patient access staff at the Breese location. You will ensure registration duties are performed daily, train staff, monitor productivity, and report on key metrics while maintaining...

    Ensemble Health Partners

    Brooklyn, NY
    5 days ago
  •  ...our Facilities team to maintain a safe, functional, and well‑kept environment for residents, guests, visitors, and staff. The role leads the landscaping team, ensures safety compliance, and coordinates maintenance of grounds, irrigation, and seasonal projects. Responsibilities... 
    Seasonal work
    Monday to Friday
    Shift work

    Mabee Village-The Marbridge

    Brooklyn, NY
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to GRC Lead. Be the first to apply!