Cybersecurity GRC Program Lead
$112.5k - $163.57kEcho Global Logistics
Echo is seeking a Cybersecurity GRC Program Lead to build the operating system for security governance, risk, controls, evidence, and exceptions across the enterprise. This is a hands-on leadership role for someone who can select and drive adoption of a primary cybersecurity framework, build the control ownership model, build & improve evidence operations, accelerate questionnaire throughput, and create practical governance mechanisms that work with real engineering and business teams. This role is not limited to policy writing or audit coordination. It is intended to make security governance real and measurable across the enterprise by building practical operating mechanisms around risk, controls, evidence, exceptions, and stakeholder accountability. In the staffing plan, this role is explicitly intended to select and operationalize the primary framework, likely starting with NIST CSF 2.0 while mapping outward to ISO 27001 and other requirements for customer, audit, and international needs. What you will do Lead selection, adoption, and operationalization of Echo’s primary cybersecurity framework and related standards structure, with NIST CSF 2.0 as the likely management layer Build and maintain a control ownership model across Technology, Engineering, Platform, Network, EUC, Asset, Data, Integrations, and Security Translate existing policies into measurable operating practices, control expectations, evidence requirements, review cadences, and exception workflows Partner with security architecture, engineering, and operations teams to ensure that governance expectations are practical, technically grounded, and enforceable Drive enterprise risk and control assessments, including facilitating discussions on control design, effectiveness, and remediation priorities Build an evidence library structure while defining repeatable collection, review, reuse, and freshness cadences Improve security questionnaire workflows through standardized responses, evidence reuse, service-level expectations, and clearer ownership Coordinate third-party security intake and help define tiering, minimum security requirements, documentation expectations, and escalation paths Partner with Internal Audit and business stakeholders on readiness efforts, compliance reviews, and operational audit support Track policy exceptions, control gaps, remediation commitments, and overdue actions through closure, including clear owners and time bounds Provide security governance input on supplier security requirements, contractual obligations, and ongoing review expectations Produce reporting for leadership on framework maturity, control ownership, policy currency, evidence readiness, exception status, and risk trends Lead the evolution to and support of continuous compliance capabilities to improve control visibility, evidence freshness, and audit readiness Manage and evolve the organization’s trust center, including published security documentation, customer-facing assurance materials, and the processes that keep content current and supportable What success looks like In the first 60 to 90 days, this role is expected to produce a framework decision package, define the control ownership model, stand up an evidence library structure, improve questionnaire operations, and establish practical workflows for exceptions and third-party intake. Over 12 months, success means framework adoption becomes measurable, control ownership is visible, evidence is reusable, customer and audit due diligence become less reactive, and policy exceptions and control gaps are actively managed. What you bring 7+ years in cybersecurity GRC, security risk, audit readiness, compliance operations, or related functions, with clear experience building or maturing governance operating models Strong experience operationalizing NIST CSF and translating controls across frameworks such as ISO 27001, SOX, SOC 2, or similar frameworks Experience building or maturing security governance programs in complex enterprise environments with multiple technical stakeholders Experience with risk assessments, control design reviews, exception management, and remediation tracking Strong understanding of third-party risk, supplier security reviews, security questionnaires, and governance workflows that scale beyond one-off reviews Experience partnering with technical teams to influence architecture, engineering, and operations outcomes in a practical, technically credible way Ability to turn policy and framework language into concrete operating practices, ownership expectations, and measurable evidence Strong writing, stakeholder management, and executive communication skills Preferred qualifications Experience supporting SOC 2, ISO 27001, CTPAT, SOX or similar audit/readiness efforts Experience with evidence management, control testing, internal audit coordination, or related assurance processes Experience with continuous compliance platforms, including evidence automation, control monitoring, and audit readiness workflows Experience managing a trust center or similar customer assurance portal and keeping security documentation current and reusable Familiarity with enterprise technology environments spanning cloud, identity, endpoint, network, and application security domains Echo Global Logistics is a leading provider of technology-enabled transportation management services. As a third-party logistics provider, we simplify transportation management for our clients and carriers, handling crucial tasks so they can focus on what they do best. From coast to coast, dock to dock, and across all major transportation modes, Echo connects businesses that need to ship their products with carriers who transport goods quickly, securely, and cost-effectively. Why this role matters Echo already has a policy foundation, including formal expectations for information security governance, access control, supplier security, and compliance review. What is needed now is a leader who can turn those policies into a durable governance operating system with clear ownership, evidence discipline, exception management, and measurable accountability. Work environment/physical demands summary: This job operates in an office environment and uses a computer, telephone and other office equipment as needed to perform duties. The noise level in the work environment is typical of that of an office with an open seating floor plan. The employee may encounter frequent interruptions throughout the work day. The employee is regularly required to sit, talk, or hear. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, status as a qualified individual with a disability, or Vietnam era or other protected veteran. #LI-SG1 #Remote Benefits For more information about our benefit offerings, please visit our careers page at Compensation $112,498.00-163,571.00 per year This role is eligible for a bonus that is based on a combination of personal and business performance. Echo Global Logistics is a leading provider of technology-enabled transportation management services. As a third-party logistics provider, we at Echo Global Logistics, we’re in the business of simplifying transportation management. We didn’t become a Fortune 1000 company by chance. We got here because of our team members, who are unwavering in their pursuit to solve complex problems, provide exceptional service, and make an impact every day. Come join Echo and accelerate your career! Your recruiter will keep you informed on what that will look like for the role you are being considered for. During the recruiting process, our recruiting team will continue connecting with qualified candidates in a virtual setting and will have the option of in-office interviews depending on location and the role. For those who are joining the Echo family, your onboarding experience will also be conducted virtually until further notice.
- ...driven people make the impossible possible together. We are seeking an experienced Cybersecurity Governance, Risk and Compliance (GRC) Manager to build and lead the enterprise GRC program. This role will assist in the build‑out of the GRC program from early stages to...SuggestedFlexible hours
- The State of Maryland is seeking a GRC Project Manager to oversee cybersecurity and privacy policy initiatives. This contractual... ...role involves managing comprehensive programs, ensuring alignment with strategic goals, and leading cross-functional teams. Key responsibilities...Suggested
- ...A leading defense technology firm in Fort Worth, TX is seeking a Cybersecurity Compliance Program Manager to oversee compliance initiatives with CMMC, ISO 27001, and PCI DSS. The role requires managing audits, developing policies, and mitigating risks across the organization...Suggested
- ...A cybersecurity firm in the U.S. seeks a Security Program Manager to lead technical programs and manage a team of Security Analysts. Responsibilities include ensuring compliance with cybersecurity frameworks, managing delivery teams, and improving customer retention. Candidates...SuggestedRemote work
$83.1k - $141.3k
...most sophisticated clients using leading technology and exceptional service... ...Overview This role sits in the Cybersecurity Governance, Risk and Compliance (GRC) team within Northern Trust’s Technology... ...benefits. A discretionary bonus program may be included. Reasonable...SuggestedVisa sponsorshipWork visa- ...A leading tech consulting firm in Secaucus, New Jersey is seeking an experienced Archer GRC Program Manager to oversee the implementation and management of the Archer Governance, Risk, and Compliance platform. This pivotal role involves developing program strategies and...
$155k
...Job Posting Title: Cybersecurity GRC Team Lead ---- Hiring Department: Information Security Office ---- Position Open To:... ...central to building a mature, risk-informed, and agile GRC program that aligns with the university's research mission and enterprise...Full timeFor contractorsWork at officeImmediate startRemote workFlexible hours- ...A leading consulting firm in the United States is seeking a Manager for its Cyber Security & Data Privacy group. The role involves leading client engagements to implement cybersecurity programs aligned with major compliance frameworks. Candidates should have over 5 years...
- ...A cybersecurity consulting firm in the United States is seeking an experienced compliance consultant to lead assessments and advise clients on various regulatory frameworks. Candidates should have a Bachelor's degree and over six years of experience in professional services...Flexible hours
$155k
...Cybersecurity GRC Team Lead This is a remote-eligible opportunity offering flexible work arrangements, competitive benefits, and the chance... ...central to building a mature, risk-informed, and agile GRC program that aligns with the university's research mission and enterprise...Full timeWork at officeRemote workFlexible hours- A leading technology firm in Boston is seeking a GRC Program Manager to oversee FedRAMP authorization and broader compliance initiatives. The role requires managing complex audits, coordinating across teams, and enhancing GRC processes. Ideal candidates have 5+ years in...
$155k
Cybersecurity GRC Team Lead Location: Austin, TX Salary Range: $155,000 + depending on qualifications. Responsibilities Lead and manage a team of... ...responsible for supporting the Controlled Research Program and ensuring alignment with CUI‑related frameworks (e.g.,...$196.9k - $295.3k
Stripe is hiring a Security Analyst / Program Manager in San Francisco to build and scale security foundations for its fintech innovation... ...as it scales. Applicants should have 8+ years in security GRC, ideally within startups, and possess a startup mindset. The annual...- Cybersecurity Governance, Risk & Compliance (GRC) Lead page is loaded## Cybersecurity Governance, Risk & Compliance (GRC) Leadlocations: Pleasanton, CA - USAtime... ...continuously improve the company’s cybersecurity program, with a focus on driving risk informed decision...Contract workWork at officeWork from homeFlexible hours
$125k - $175k
Savant Wealth Management is seeking a GRC Lead in Chicago. This role offers the opportunity to design and own the governance, risk, and compliance program from the ground up. You will implement governance strategies, manage vendor risks, and lead regulatory audits. Ideal...Remote jobFlexible hours$162k - $310k
Slope in Washington, DC is hiring a GRC Program Manager to lead the ATO process for FedRAMP and ensure compliance with regulatory frameworks. The role requires at least 5 years of experience in compliance and strong understanding of US government security standards. You...- Prudent Technologies and Consulting, Inc. is looking for an IT Program Manager based in Santa Clara, California. This role involves leading end-to-end program management for GRC initiatives and ensuring compliance with risk management frameworks. Candidates must have over...
- ...Specialist - Governance, Risk, and Compliance (GRC) Lead In this role as a IT Specialist -... ...Developing, implementing, maintaining cybersecurity governance, risk, and compliance... ...technology usage for the cybersecurity GRC program; Transforming existing manual...
- ...Cyber Governance, Risk & Compliance (GRC) Manager in Scottsdale, Arizona. The... ...candidate will have a strong background in cybersecurity, with at least three years in... ...experience. This role requires designing and leading a robust GRC program aligning with business priorities....Work at office
- ...Riverton Siding, Utah, is looking for a Sr. Manager, Governance, Risk & Compliance (GRC) – Cybersecurity. This role will lead the company's cybersecurity governance and compliance programs, ensuring effective risk management aligned with regulatory and business needs....
- ...Olympus Corporation of the Americas is seeking a Senior IT Security GRC Analyst to oversee governance structures for IT Security,... ...hybrid position is based in Pennsylvania and requires expertise in cybersecurity frameworks. The ideal candidate should possess at least 8 years...
- ...A prominent energy solutions company is seeking a Cybersecurity Manager to lead the organization's cybersecurity strategy. This role involves managing cybersecurity programs, ensuring compliance with NERC CIP requirements, and driving continuous improvement in the cybersecurity...
$141.3k - $211.9k
...Job Summary As a SOX Governance Program Lead, Cybersecurity, you will play a vital role in supporting a cross‑functional team focused on building and maintaining effective governance processes. This team collaborates across Security, SOX PMO, and Contractor groups to ensure...For contractorsLocal area$140k
...validation. Summary We are seeking a highly experienced Senior Program Manager to lead the execution and delivery of complex IT and cyber... ...degree (or higher) in Information Technology Management, Cybersecurity, Computer Science, or a related discipline. 10+ years of diverse...Contract workFor subcontractorLocal area- ...Empower AI is seeking a Senior Program/Project Lead at Fort Huachuca. This role emphasizes leadership in IT and cybersecurity operations while ensuring systems remain secure and mission-ready. Ideal candidates possess extensive experience in IT operations and a strong...
- ...for a manager to supervise the DoD Cyber Crime Center's Voluntary Disclosure Program. The candidate will be responsible for strategic planning, program direction, and developing cybersecurity initiatives while ensuring compliance with federal standards. The ideal candidate...
- ...A leading cybersecurity firm in Sunnyvale, CA, is seeking a Security Program Manager to drive execution of key initiatives across the organization. This role will coordinate work among security, engineering, and product teams while defining measurable outcomes. The ideal...
- ...Hewlett Packard Enterprise in Spring, Texas, is seeking a Senior Program Manager for Cybersecurity Risk Management. This role involves leading crucial cybersecurity programs within the enterprise, focusing on operations across the global supply chain. The ideal candidate...
- ...Evolver Federal is seeking a Lead Project/Program Manager in Washington, DC to oversee a comprehensive cybersecurity program for a federal client. This role requires leadership in SOC services, incident response, and compliance with federal standards like NIST. Key responsibilities...
- ...Lynk is seeking a Senior Cybersecurity Compliance Officer (ISSO) to oversee compliance programs aligned with CMMC Level 2, NIST SP 800‑171, and more. This remote position requires 3–6 years in cybersecurity, with a strong focus on governance, risk, and compliance. The...Remote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cybersecurity GRC Program Lead. Be the first to apply!
- cyber security United States
- cyber security intern United States
- work from home cyber security United States
- cyber security sales United States
- no experience cyber security United States
- cyber security incident responder United States
- senior cybersecurity engineer United States
- cyber security architect United States
- cyber security technician United States
- cybersecurity software engineer United States

