Director of Governance, Risk & Compliance
jobgether
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Director of Governance, Risk & Compliance based in the United States.
This is a hands-on leadership opportunity to own and evolve an internal Governance, Risk & Compliance (GRC) program while overseeing Managed GRC services for clients. You will shape scalable methodologies, processes, evidence standards, and quality controls while remaining directly involved in complex compliance and security initiatives. The role combines executive-level advisory work with practitioner-level engagement, requiring close collaboration with CISOs, auditors, engineers, control owners, and technical teams. A significant focus will be on federal security programs, including System Security Plans (SSPs), control implementation statements, evidence, POA&Ms, remediation, and responses to government or assessor findings. You will also guide risk assessments, audits, security questionnaires, and compliance programs across frameworks such as NIST, SOC 2, ISO 27001, CMMC, and HIPAA. The position offers the opportunity to lead and develop a growing GRC team while introducing automation and AI-enabled approaches that improve delivery, consistency, and scalability. This is a remote U.S. role with the option to work from home or from a local U.S. office.
Accountabilities:
- Own and mature the internal GRC program and lead the operational delivery of Managed GRC services, establishing standardized methodologies, processes, templates, evidence requirements, and quality controls.
- Lead risk assessments, control assessments, compliance readiness activities, policy governance, managed audits, managed security questionnaires, and other GRC engagements while managing client commitments, priorities, capacity, quality, and service performance.
- Lead federal compliance activities, including the development and maintenance of System Security Plans, control implementation statements, supporting evidence, POA&Ms, remediation plans, milestones, and responses to government, assessor, and auditor findings.
- Coordinate with engineers, security teams, control owners, and clients to validate how security controls are implemented and ensure documented controls accurately reflect the operating environment.
- Support requirements related to NIST SP 800-53, NIST SP 800-171, FISMA, CMMC, FedRAMP concepts, and agency-specific federal security requirements, including continuous monitoring, assessments, and authorization activities.
- Manage cybersecurity risk and compliance programs covering risk registers, control gaps, treatment plans, exceptions, remediation tracking, SOC 2, NIST, CIS, ISO 27001, PCI DSS, HIPAA, CMMC, and Microsoft security benchmarks.
- Oversee managed audit and security questionnaire methodologies, including audit readiness, evidence management, auditor coordination, findings, remediation, and reusable response and evidence libraries.
- Partner with senior security leadership to operate and strengthen internal compliance initiatives, including SOC 2 Type 2, policy and control governance, third-party risk, customer security reviews, audit coordination, and evidence management.
- Act as a senior GRC advisor to client security, IT, risk, compliance, and executive leaders, translating regulatory requirements into actionable technical and operational security improvements.
- Collaborate with Security Operations, cloud, Microsoft 365, and engineering teams to map compliance requirements to technical implementations, with working knowledge of Azure, Entra ID, Defender, Sentinel, Intune, Purview, and Azure Policy.
- Support vCISO engagements where governance, risk, audit, and compliance expertise is required, while partnering with Sales and Client Success on service scoping, statements of work, pricing, and complex opportunities.
- Lead, mentor, and develop GRC Analysts and Consultants while managing workload, capacity, priorities, quality assurance, escalations, and scalable processes that enable the practice to operate effectively without relying on the Director for every engagement.
- Identify opportunities to use automation and AI to improve GRC delivery, increase consistency, and scale services efficiently.
- Establish measurable progress through early workflow assessments and prioritized improvements, with long-term ownership of the GRC function, SOC 2 Type 2 program, Managed GRC delivery, federal SSP activities, team development, process maturity, and automation.
Requirements
- 8+ years of experience in cybersecurity, Governance, Risk & Compliance, security assessment, audit, or a related field, with demonstrated experience leading GRC programs or teams.
- Hands-on experience with NIST SP 800-53, System Security Plans, POA&Ms, control implementation statements, and federal security requirements.
- Proven experience managing audits, evidence programs, risk assessments, control gaps, policies, remediation initiatives, and compliance activities.
- Ability to translate regulatory and compliance requirements into practical technical and operational security controls.
- Strong understanding of frameworks and standards such as SOC 2, NIST, CIS, ISO 27001, PCI DSS, HIPAA, CMMC, and Microsoft security benchmarks.
- Strong client-facing, executive communication, facilitation, and stakeholder management skills, with the ability to communicate effectively with both senior leaders and technical practitioners.
- Ability to work directly with engineers and control owners to understand, validate, and document security control implementations.
- Experience in an MSSP, MSP, consulting, professional services, federal program, or government contractor environment is preferred.
- Experience with Microsoft Azure and Microsoft 365 security technologies is strongly preferred.
- Familiarity with Azure, Entra ID, Defender, Sentinel, Intune, Purview, and Azure Policy is an advantage.
- Relevant certifications such as CISSP, CISM, CRISC, CISA, CGEIT, or similar are valued.
- Demonstrated leadership qualities including low-ego collaboration, initiative, accountability, empathy, situational awareness, and a bias toward practical problem-solving.
- Ability to operate strategically with executives while remaining comfortable engaging deeply with technical details, compliance evidence, assessments, and remediation activities.
Benefits
- Competitive salary based on experience and skills.
- Performance-based compensation with bonus potential in addition to base salary.
- 401(k) plan with a 100% employer match on employee contributions up to 4% of salary.
- 100% employer-paid health, vision, and dental insurance premiums for employees.
- Company-paid life, AD&D, short-term disability, and long-term disability insurance.
- Three weeks of paid time off that can be used for vacation, personal time, or sick leave.
- 11 paid holidays each year.
- Paid community service leave for volunteering with organizations that are meaningful to you.
- Employee recognition and reward programs celebrating strong performance and contributions.
- Full-time remote work from anywhere in the United States, with the option to work from a local U.S. office when available.
- An opportunity to lead a strategic GRC function, develop a team, work on complex federal compliance programs, and build scalable processes and automation.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
- ...To build and govern Engine's risk framework, the full-time remote Director of Risk Management will establish risk tolerance guidelines, oversee risk governance... ...requirements including BSA/AML and card issuing compliance Experience in fintech, card issuing, or lending...SuggestedFull timeRemote work
- ...hospital experience as CEO, CNO, COO, CFO, Director of Business Office, Director of Quality,... ...of regulatory and accreditation compliance and surveys (Joint Commission, DHS, CMS,... ...Analyzes incidents, sentinel events, and risk outcomes with administrators, physicians...SuggestedWork at office
- ...Advance Auto Parts, Inc. seeks a Sr. Manager of Cybersecurity Third-Party Risk Management to lead the enterprise program for identifying, assessing, monitoring, and reducing third-party cybersecurity risks across suppliers, vendors, and service providers. The role...Suggested
- ...Advance Auto Parts seeks a Director of Governance and Risk to define and deploy governance and risk management frameworks across the company. The... ...CISO and will oversee policy, standards, and regulatory compliance while guiding risk discussions with the Board and ERM....Suggested
- ...MISA), Atmosera expertly delivers cutting-edge, integrated solutions that deliver business value. Your Impact The Director of Governance, Risk & Compliance (GRC) leads Atmosera's internal GRC program and Managed Governance, Risk & Compliance (MGRC) services. This is a hands...SuggestedFull timeRemote work
- ...listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Director of Governance, Risk & Compliance based in the United States. This is a hands-on leadership opportunity to own and evolve an internal Governance, Risk...Full timeWork at officeLocal areaRemote workWork from home
- ...), Atmosera expertly delivers cutting-edge, integrated solutions that deliver business value.\n Your Impact The Director of Governance, Risk & Compliance (GRC) leads Atmosera's internal GRC program and Managed Governance, Risk & Compliance (MGRC) services. This is...Full timeTemporary workFor contractorsLocal areaRemote workWork from homeFlexible hours
- ...Director of Quality and Risk Management This acute care hospital is a respected healthcare provider... ...care through strong clinical governance, regulatory excellence, and continuous... ...risk management programs. Ensure compliance with regulatory, accreditation, and...Relocation package
- ...Tennant Company seeks a strategic Director of Cybersecurity to lead the enterprise cybersecurity... ...You will set the cybersecurity vision, governance and operating priorities across the... ...to the CIO and collaborates with IT, risk management, internal audit, legal and executives...
$95.9k - $178.1k
...and has opportunities to grow and learnWhat Youll Do:Enterprise Risk Management ExecutionLead components of the Enterprise Risk... ...summaries, dashboards, and presentations for senior leadership and governance forumsTranslate risk insights into actionable recommendations to...Minimum wageFull timeContract workWork at officeFlexible hours$125.1k - $175.1k
...strategic leader to join our Third Party Risk Management (TPRM) function as a Director, Line 1B. This role is... ...leading the Quality Assurance and governance oversight function across Vendor... ...deep expertise in audit, regulatory compliance, and Risk & Control Self-Assessment...Full timeTemporary workLocal areaFlexible hours$285k - $295k
Title: Director, Treasury RiskJob Location: One M&T Plaza, Buffalo, NY 14... ...regulators. Develop, review and maintain risk management processes and procedures for governance and oversight of the Firm’s... ..., and other methods to ensure compliance with liquidity ratios, LCR, and...Full timeWork experience placementBank staffWork at office- ...assisting the Chief Fiduciary Officer with the design, execution, and administration of a division-wide fiduciary governance, risk management, and compliance oversight framework. The role provides management-level direction for the WMAS Compliance Officer and related...Full timeContract workLocal area
$180.08k - $247.6k
...and a chance to learn, effect change, and make meaningful contributions at work and in communities. The Director, Global Cybersecurity Governance, Risk, Compliance & Identity is accountable for defining and executing Donaldson’s enterprise cybersecurity governance and...Full timeWork experience placementH1bWork at officeRemote workRelocation$85.5k - $185k
...Dundas Street WestJob Family Group:Audit, Risk & ComplianceProvides oversight,... ...management framework that includes the governance framework & practices leveraged across BMO... ...standards for the assigned portfolio to ensure compliance as well as effective monitoring, timely...Full timeContract workPart timeShift work$103.9k - $148.4k
The Supplier Risk Manager is a senior-level role within Global Supplier Management (GSM... ...risk programs and establish the governance frameworks, analytics infrastructure, and... ...governance mechanisms to ensure policy compliance and drive continuous improvement• Partner...Flexible hours- As part of Risk Management and Compliance, you are at the center of keeping JPMorgan Chase strong and resilient... ...to be best-in-class.As an Executive Director, Head of North America Capital Risk... ...risk assessment, limits, and governance while partnering closely with senior...
- ...Risk Manager The Manager, Risk Management leads the program... .... This role establishes risk governance, ensures consistent identification... ..., quality, regulatory, and compliance requirements. Coach... ...structures across EO. Support the Director, Program Management with...Flexible hours
- ...Must needed Direct line phone no must needed Risk Manager New York, NY On Site Contract - 6 month(s)... ...& Controls Manager to join its Information Security GRC (Governance, Risk & Compliance) team. In this role, the Risk & Controls Manager will be responsible...Contract workRemote work
$108k - $180k
...GRC Risk ManagerLos AngelesAbout SHEINSHEIN Technology is a U.S. technology company. Founded in 2012, SHEIN is a leading... ...security infrastructure, risk management, data privacy, governance and regulatory compliance across SHEIN's global footprint. It is composed of a team...Temporary workWork at office- ...Senior Project Risk ManagerLawrence Berkeley National Laboratory is seeking an accomplished Senior Project Risk Manager to lead integrated... ...improve risk processes, tools, reporting, training, and governance.What You Bring8+ years of progressively responsible experience...
- ...Key Responsibilities Job Title: Risk Manager Location: Washington, DC Metropolitan Area... ...risk management, program risk governance, and strategic planning to help the organization... ...Support audits, inspections, assessments, and compliance reviews related to risk management...Full timeContract workTemporary workWork at officeLocal areaImmediate startHome officeFlexible hours
- Bring your expertise to JPMorgan Chase. As part of Risk Management and Compliance, you are at the center of keeping JPMorgan Chase strong and resilient... ...credit strategy, controls, and (as applicable) model governance.Job Responsibilities: Analyzes and decisions credit...
- ...team and our firm.Learn more about our services, industry experience and culture at weaver.com.Position ProfileWeaver’s Governance, Risk and Compliance (GRC) team is looking for a dynamic, driven, experienced Senior Manager to join our growing Public Sector practice. The...Full timeContract workLocal areaFlexible hours
- Job DescriptionManager Global Risk & Controls - Chicago, IL (On-site) Role OverviewThe... ...Audit Readiness, Controls, and Policy Governance plays a critical role in building and sustaining... ..., not managed as after‑the‑fact compliance activities.Finance policies are clear, current...Hourly payWorldwideFlexible hours
$102k - $178.4k
...obsessed with customer trust and are seeking an individual contributor who is creative, and passionate about delivering Governance, Risk and Compliance solutions to meet Leo's regulatory and external assurance needs. In this role, you will work collaboratively with...Permanent employmentTemporary workWorldwideFlexible hours$201.48k - $218.01k
...of hire. Applicants selected will be subject to a U.S. Government security investigation and must meet eligibility... ...Position General Dynamics Mission Systems is seeking a Director, IT Governance, Risk, Compliance & AI to lead the enterprise governance function across...Work experience placementFlexible hours$308k
...digital landscape. We are seeking a pragmatic, strategic, and highly credible Head of Enterprise Security to lead our Governance, Risk, and Compliance (GRC), and Data Security with a clear focus on AI Security and Governance. This role operates in a highly collaborative...Work at officeRelocation package3 days per week$208.55k - $254.85k
...authorizations to delivering comprehensive medication histories to facilitating messages between providers.Job Summary:The Director of Governance, Risk and Compliance provides strategic oversight of the Governance Risk and Compliance (GRC) information security team to ensure...Full timeCasual workWork at officeLocal areaImmediate startFlexible hours- ...Manager, this role leads and advances the business unit’s risk and compliance programs by directing risk and control assessment methodologies... ..., new product and service risk reviews, operational risk governance, and risk reporting. The role monitors, directs, and...Work experience placementWork at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Director of Governance, Risk & Compliance. Be the first to apply!
- director of risk management United States
- risk management associate United States
- clinical risk manager United States
- operational risk manager United States
- energy risk manager United States
- risk analytics manager United States
- safety risk manager United States
- director credit risk United States
- senior risk manager United States
- security risk manager United States



