Director, Cybersecurity GRC
Momentive Software, Inc.
- # Director, Cybersecurity GRCApply: Remote (US Only): Full time: Posted Today: R685# **Job Description****POSITION OVERVIEW**The Director, Cybersecurity GRC manages the people, processes, and technology related to Momentive Software's Cybersecurity GRC group — overseeing governance, risk, and compliance activities including client audit support, RFP response, internal IT audit, and contract review. This role carries out GRC activities in alignment with the Firm's business objectives, regulatory requirements, and strategic goals, with a focus on recognized cybersecurity frameworks and contractual compliance.The Director serves as the process owner for all IS GRC-related projects and activities and assists the CISO in planning, developing, and overseeing the cybersecurity program. The role integrates across Cybersecurity, Information Technology, new business development, the Office of General Counsel, and the professional responsibility function. In addition to ongoing governance and operational oversight, this position supports strategic alignment with the business, cybersecurity outreach, and expert guidance to internal and external stakeholders. As a strategic partner to the business, this role helps Momentive win and retain enterprise clients, support growth and M&A readiness, and position the GRC program as a business enabler — not just a compliance function.**KEY RESPONSIBILITIES****GRC Program Leadership*** Maintain direct responsibility for all aspects of IS GRC, including governance, risk assessment, compliance, and audit support.* Ensure continual improvement of the cybersecurity program through effective application of technology, systems, processes, personnel development, and leadership.* Provide cybersecurity services that meet or exceed the Firm's professional, contractual, regulatory, and certification requirements.* Manage the Firm's IS GRC people, processes, and technology infrastructure, including creation and review of IS GRC standards, guidelines, and operating procedures.* Serve as the business owner for IS GRC toolsets, platforms, and processes.* Manage the IS GRC team budget.* Consult with Legal regarding acceptable contract terms and conditions related to cybersecurity.**ISMS & System Governance*** Lead the System Governance Virtual Team, promoting continual ISMS improvement across the Firm.* Provide direction on risk assessment requirements and assistance evaluating risk treatment plans.* Provide input on the selection and design of IS controls.* Provide input on metrics developed to monitor and test the effectiveness of the Firm's IS controls.* Define documentation requirements to ensure compliance with ISMS requirements.* Advise the team on client contractual requirements and Firm commitments relative to GRC practices.* Assist the team in developing systems and processes that ensure ISMS compliance and continual improvement.* Maintain the Firm's Cybersecurity Management System (ISMS), including the creation and review of policies, standards, and procedures.* Enforce, monitor, and report on compliance with the Firm's ISMS.* Partner with the Director, AI Governance to co-develop and align AI policies, assess AI-related risks, and integrate AI governance practices into the ISMS framework.**Cybersecurity Operations & Engineering Integration*** Work closely with Cybersecurity Operations and Engineering teams to define, develop, and facilitate efficient and effective service delivery.* Oversee integrated vendor and other risk assessment activities in coordination with technical teams.* Liaise with system and business owners to ensure new platforms comply with Firm cybersecurity requirements.* Serve within the Firm's Computer Cybersecurity Incident Response Team (CSIRT).**Compliance & Audit*** Oversee cybersecurity risk assessments and provide audit mechanisms for the cybersecurity process.* Meet published SLAs for the provisioning and support of cybersecurity GRC operations and activities.* Provide evidence and expert support for client audits, RFP responses, and regulatory reviews.* Track compliance with applicable regulatory schemes and monitor changes in legislation and accreditation standards.**Cybersecurity Awareness & Culture*** Manage the cybersecurity awareness program, including phishing simulation and constituent outreach initiatives.* Initiate, facilitate, and promote activities that foster cybersecurity awareness across the organization.* Maintain and contribute to the Firm's cybersecurity-related information repositories.**Leadership & People Management*** Mentor and lead members of the Cybersecurity GRC group through effective performance reviews, development opportunities, and a culture of performance excellence.* Direct reports include TPRM Advisors, who manage third-party risk management activities across the organization; this role carries full people management accountability for that team.* Transform executive priorities into operational GRC initiatives with clear vision, support, and expectation-setting.* Provide status reports and relevant metrics to the CISO.* Serve in a proactive, consultative role to other business units and constituents.* Provide exemplary service to internal and external stakeholders, demonstrating empathy, respect, professionalism, and expertise.**Strategic Planning & Roadmap*** Maintain situational and environmental awareness; implement appropriate tactics and strategies to protect the organization and support roadmap development.* Strike an appropriate balance between strategic leadership and operational contribution, using a hands-on approach to solving problems and meeting deliverables.* Participate in defining the Firm's DR/BCP practices as required.* Provide innovation within the cybersecurity realm.**SKILLS & EXPERIENCE****Required*** 10-12+ years of experience in cybersecurity, with 3-5 years in a leadership or program management role.* Thorough knowledge of professional management practices including supervisory techniques, leadership principles, and employment practices.* Excellent verbal and written communication skills, including public speaking and the ability to convey complex cybersecurity concepts to non-technical stakeholders.* Ability to think and communicate strategically about the role of cybersecurity in a global organization.* Ability to quickly assess an organization's capability-maturity level and apply that knowledge to RFPs, audits, contract reviews, and internal operations.* Proficiency in at least one major EGRC/ITGRC platform (e.g., ServiceNow GRC, Archer, OneTrust, LogicGate).* Comprehensive understanding of major cybersecurity frameworks: NIST CSF, CIS Controls, SOC2T2, and COBIT.* Familiarity with common regulatory schemes including GDPR, PCI-DSS, GLBA, FISMA, HIPAA, and ITAR.* Advanced understanding of technical controls, how they address risk, and how they map to framework and regulatory requirements.* Broad understanding of TCP/IP, DNS, common network services, and foundational infrastructure concepts.* Knowledge of server, workstation, and Active Directory technologies as they relate to cybersecurity controls.* Familiarity with common cybersecurity monitoring technologies: SIEM, IDS, log management, and vulnerability assessment.* Ability to gather and analyze facts, define problems, draw conclusions, and recommend solutions.* Ability to maintain objectivity and composure under pressure.* Ability to set priorities independently given broad executive requirements.* Demonstrated flexibility in response to the ever-changing priorities of a service provider organization.* Rigorous and disciplined approach to operational oversight.**Preferred*** One or more relevant certifications required or preferred: CISSP, CISM, or CRISC. ISO 27001 Lead Implementer or Lead Auditor is a plus.# **About Us**Momentive Software amplifies the impact of over 20,000 purpose-driven organizations in over 30 countries, with over $11 billion raised and 55 million members served to date. Mission-driven nonprofits and associations rely on Momentive’s cloud-based software and services to address their most pressing challenges – from engaging their communities to simplifying operations and growing revenue. Designed to help organizations connect more, manage more, and ultimately expect more, Momentive's solutions are built with reliability at the core and strategically focus on fundraising, learning, events, careers, volunteering, accounting, and association management. Momentive partners with organizations that believe \"good enough\" is never enough – so they can bring on better outcomes for everyone they serve. Learn more at momentivesoftware.com.# **Why Work Here?**At Momentive Software, we’re a team of passionate problem-solvers, innovators, and volunteers who believe in using technology to make a real difference. We dream big, support each other, and take pride in creating solutions that help our customers drive meaningful change. If you’re looking for a place where your work matters and your ideas are valued, you’ll find it here.Medical, Dental & Vision Benefits401(k) Savings Plan with Company MatchFlexible Planned Paid Time OffGenerous Sick LeaveInclusive & Welcoming EnvironmentPurpose-Driven CultureWork-Life BalanceCommitment to Community InvolvementEmployer-Paid Parental LeaveEmployer-Paid Short-Term DisabilityRemote Work Flexibility Momentive Software actively embraces diversity and equal opportunity in a meaningful way. We are committed to building a team that represents a variety of backgrounds, perspectives, and skills. The more inclusive we are, the better our work will be, which is why we do not discriminate based on race, color, religion, marital status, age, national origin, ancestry, physical or mental disability, medical condition, pregnancy, genetic information, gender, sexual orientation, gender identity or expression, veteran status, or any other status protected under federal, state, or local law. All persons hired will be required to verify identity, minimum age of 18, eligibility to work in the United States (without sponsorship), and to complete the required employment eligibility verification form upon hire.
- J-18808-Ljbffr Momentive Software, Inc.
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Director, Cybersecurity GRC in Brooklyn, NY vacancy
- ...and a third day unique to each team or employee).The Impact you will have in this role:Being a member of IT Cybersecurity & Platform Strategy team, the Director, Cyber Resiliency will build, lead, and mature our capability focusing on recovery from destructive events that...SuggestedRemote workFlexible hours
- ...complex enterprise security environments. This individual will develop deep expertise in cryptographic posture management, enterprise cybersecurity, and emerging post-quantum cryptography initiatives while helping shape the future direction of the AgileSec platform....SuggestedFull timeRemote work
- About Kaseya Kaseya is the leading provider of AI-powered IT management and cybersecurity software, serving Managed Service Providers (MSPs) and internal IT organizations worldwide. Our comprehensive platform helps organizations efficiently manage, secure, and automate...SuggestedWorldwide
- ...The Impact you will have in this role: Being a member of IT Cybersecurity & Platform Engineering team, the Associate Director, AI Security & Data Protection Engineering serves as a technical leader responsible for designing, implementing, and scaling DTCC's data protection...SuggestedFull time
- ...unique to each team or employee).The Impact you will have in this role:Being a member of IT Cybersecurity & Platform Engineering team, the AI Data Security Engineer - Assocaite Director is a technical leader, responsible for designing, building, and maintaining AI‑focused...SuggestedRemote workFlexible hours
- ...from direction into delivery. You’ll report to our Co‑Founder & CPO and work closely with our Director of Engineering, design lead, and senior engineers, in a scaling cybersecurity company where ownership is high, collaboration is close, and you’ll have meaningful...Full timeRemote work
- ...sensitive roles within the technology organization that require high assurance of the integrity of staff by virtue of 1) sensitive cybersecurity and technology functions they perform within systems or 2) information they receive regarding sensitive cybersecurity or...Shift work
$220k - $260k
...disruptions. About the Role DEFCON AI is seeking a Technical Director, AI Decision Systems to lead the cross-functional team... ...architecture, applied analytics, AI solutioning, DevSecOps, cybersecurity, quality engineering, and technical transition. This is a zero...For subcontractorRemote workFlexible hours$195.4k - $293k
...globe to create, secure, and run applications that enhance how we experience our evolving digital world. We are passionate about cybersecurity, from protecting consumers from fraud to enabling companies to focus on innovation. Everything we do centers around people. That...Work at officeLocal areaRemote workWork from homeFlexible hours- ...sensitive roles within the technology organization that require high assurance of the integrity of staff by virtue of 1) sensitive cybersecurity and technology functions they perform within systems or 2) information they receive regarding sensitive cybersecurity or...
$150k - $230k
...building or maturing PMO practices, standards, or tooling. Experience leading programs across IT, Enterprise Operations, and Cybersecurity simultaneously. Background as an engineer, solutions architect, systems administrator, or technical lead before moving into program...Full timeTemporary workPart timeWorldwide$152.7k - $294k
...strategic plan writing. Technical Depth: Broad and deep knowledge of information security domains and technologies – including cybersecurity architecture, risk management, identity and access management (IAM), incident response, and emerging threat mitigation techniques...Summer holidayLocal areaFlexible hoursShift work- ...sensitive roles within the technology organization that require high assurance of the integrity of staff by virtue of 1) sensitive cybersecurity and technology functions they perform within systems or 2) information they receive regarding sensitive cybersecurity or...
- ...million opt-out removals to reduce real-world privacy and security risks associated with identity theft, spam, doxxing, and other cybersecurity threats. We deliver detailed privacy reports, continuous monitoring, and expert support to ensure ongoing protection. DeleteMe...Work from home
$50k
...serves approximately 42,000 students in 320 academic programs spanning science, engineering, medicine, health, liberal arts, AI, cybersecurity, business, education and more. With 17,000 faculty and staff, UT San Antonio has been recognized by Forbes as one of America's...Bank staffWork at officeFlexible hours- ...technologists, data scientists, and analysts with backgrounds in operational intelligence, law enforcement, large multinationals, and cybersecurity operations. We obsess about designing products that will change the way global companies, governments and nonprofits protect...Flexible hours
- ...sensitive roles within the technology organization that require high assurance of the integrity of staff by virtue of 1) sensitive cybersecurity and technology functions they perform within systems or 2) information they receive regarding sensitive cybersecurity or...
$156k - $221k
..., Infrastructure, Software Engineering, Data, and other technical teams to ensure solutions align with enterprise architecture, cybersecurity, and data governance standards Own testing, deployment, documentation, monitoring, troubleshooting, and continuous improvement of...Permanent employmentFull timeTemporary workWeekend work- ...implementation methodology and accelerators What We’re Looking For 10+ years in enterprise SaaS implementation (ideally governance, GRC, or AI) Strong systems integration experience (APIs, workflows) Ability to translate business policy into system configuration Nice to...
- ...access to high-quality, trusted delivery through Vanta. As Director, Vanta for Government (V4G) Partnerships , you will own Vanta... ...grow external partner relationships at scale — ideally within cybersecurity, GRC, or compliance-adjacent ecosystems. Experience partnering...For contractors
- Platform Architect At BNY, our culture allows us to run our company better and enables employees' growth and success. As a leading global financial services company at the heart of the global financial system, we influence nearly 20% of the world's investible assets...Worldwide
- ...methods to remove handoffs, duplicated reviews, and other sources of coordination cost Partner with model risk, technology risk, cybersecurity, compliance, and audit as design partners to embed governance and automated control evidence directly into AI engineering and...
- ...throughout all five boroughs. TFH is seeking an experienced, passionate, and detail-oriented homeless family and community Outreach Director to represent TFH in its relationships with directors of both homeless family shelters and domestic violence safe houses, residents...Temporary workMonday to FridayWeekend workAfternoon shiftWeekday work
- ...Northwell Health is seeking a full-time, board-certified Director of Pediatric Pulmonology to lead the Pediatric Pulmonary Division at Staten Island University Hospital (SIUH), a teaching hospital of the Donald and Barbara Zucker School of Medicine at Hofstra/Northwell...Full time
- What You'll Be Doing Reports to a Senior Vice President, Patient Care Services and is responsible for directing the hospital's Pharmacy program in accordance with laws relating to the storage, compounding and distribution of medications. Regularly contacts pharmaceutical...Full timeTemporary work
- MAIN FUNCTIONS: Responsible for all aspects of the verification process for medical staff Develops and implements policies and protocols related to physician, nurse and other employee verifications Ensures that the organization and staff are in accordance with...Full timeContract work
$67,080 per week
...Physician Affiliate Group of New York (PAGNY) is seeking a Director of Pediatric Otolaryngology (ENT) at NYC Health + Hospitals/Kings County . Kings County Hospital operates a world-renowned Level I Trauma Center, one of only three in Brooklyn, which serves 2.6 million...Daily paidFull timeImmediate startFlexible hours1 day per week- We're a consumer products company that owns and manages a portfolio of nationally recognized brands, and we're aiming to reach $500 million in revenue this year. Our products cover e-mobility, consumer electronics, outdoor power equipment, lawn and garden, cleaning and...Full timeOverseas
$155.9k - $207.9k
...commercial performance across our U.S. & Canada business, we are expanding our Revenue Growth Management (RGM) capability. The RGM Director will play a pivotal role in supporting the build-out and execution of Proximo’s RGM strategies—shaping pricing, trade spend and...Full time- ...make it easy for everyone else to understand the daily operations of our hotel and its financial impacts. We are currently seeking a Director of Revenue Management. The Director of Revenue Management is responsible for developing and executing the hotel's comprehensive...Temporary workHome officeFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Director, Cybersecurity GRC. Be the first to apply!
Related searches
- ai director Brooklyn, NY
- director work from home Brooklyn, NY
- director of aviation Brooklyn, NY
- director of admissions Brooklyn, NY
- lifestyle director Brooklyn, NY
- director medical information Brooklyn, NY
- children's ministry director Brooklyn, NY
- director talent management Brooklyn, NY
- director of government affairs Brooklyn, NY
- director of automation Brooklyn, NY





