Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Director of Governance, Risk & Compliance

Full-time

jobgether

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Director of Governance, Risk & Compliance based in the United States.

This is a hands-on leadership opportunity to own and evolve an internal Governance, Risk & Compliance (GRC) program while overseeing Managed GRC services for clients. You will shape scalable methodologies, processes, evidence standards, and quality controls while remaining directly involved in complex compliance and security initiatives. The role combines executive-level advisory work with practitioner-level engagement, requiring close collaboration with CISOs, auditors, engineers, control owners, and technical teams. A significant focus will be on federal security programs, including System Security Plans (SSPs), control implementation statements, evidence, POA&Ms, remediation, and responses to government or assessor findings. You will also guide risk assessments, audits, security questionnaires, and compliance programs across frameworks such as NIST, SOC 2, ISO 27001, CMMC, and HIPAA. The position offers the opportunity to lead and develop a growing GRC team while introducing automation and AI-enabled approaches that improve delivery, consistency, and scalability. This is a remote U.S. role with the option to work from home or from a local U.S. office.

Accountabilities:

  • Own and mature the internal GRC program and lead the operational delivery of Managed GRC services, establishing standardized methodologies, processes, templates, evidence requirements, and quality controls.
  • Lead risk assessments, control assessments, compliance readiness activities, policy governance, managed audits, managed security questionnaires, and other GRC engagements while managing client commitments, priorities, capacity, quality, and service performance.
  • Lead federal compliance activities, including the development and maintenance of System Security Plans, control implementation statements, supporting evidence, POA&Ms, remediation plans, milestones, and responses to government, assessor, and auditor findings.
  • Coordinate with engineers, security teams, control owners, and clients to validate how security controls are implemented and ensure documented controls accurately reflect the operating environment.
  • Support requirements related to NIST SP 800-53, NIST SP 800-171, FISMA, CMMC, FedRAMP concepts, and agency-specific federal security requirements, including continuous monitoring, assessments, and authorization activities.
  • Manage cybersecurity risk and compliance programs covering risk registers, control gaps, treatment plans, exceptions, remediation tracking, SOC 2, NIST, CIS, ISO 27001, PCI DSS, HIPAA, CMMC, and Microsoft security benchmarks.
  • Oversee managed audit and security questionnaire methodologies, including audit readiness, evidence management, auditor coordination, findings, remediation, and reusable response and evidence libraries.
  • Partner with senior security leadership to operate and strengthen internal compliance initiatives, including SOC 2 Type 2, policy and control governance, third-party risk, customer security reviews, audit coordination, and evidence management.
  • Act as a senior GRC advisor to client security, IT, risk, compliance, and executive leaders, translating regulatory requirements into actionable technical and operational security improvements.
  • Collaborate with Security Operations, cloud, Microsoft 365, and engineering teams to map compliance requirements to technical implementations, with working knowledge of Azure, Entra ID, Defender, Sentinel, Intune, Purview, and Azure Policy.
  • Support vCISO engagements where governance, risk, audit, and compliance expertise is required, while partnering with Sales and Client Success on service scoping, statements of work, pricing, and complex opportunities.
  • Lead, mentor, and develop GRC Analysts and Consultants while managing workload, capacity, priorities, quality assurance, escalations, and scalable processes that enable the practice to operate effectively without relying on the Director for every engagement.
  • Identify opportunities to use automation and AI to improve GRC delivery, increase consistency, and scale services efficiently.
  • Establish measurable progress through early workflow assessments and prioritized improvements, with long-term ownership of the GRC function, SOC 2 Type 2 program, Managed GRC delivery, federal SSP activities, team development, process maturity, and automation.

Requirements

  • 8+ years of experience in cybersecurity, Governance, Risk & Compliance, security assessment, audit, or a related field, with demonstrated experience leading GRC programs or teams.
  • Hands-on experience with NIST SP 800-53, System Security Plans, POA&Ms, control implementation statements, and federal security requirements.
  • Proven experience managing audits, evidence programs, risk assessments, control gaps, policies, remediation initiatives, and compliance activities.
  • Ability to translate regulatory and compliance requirements into practical technical and operational security controls.
  • Strong understanding of frameworks and standards such as SOC 2, NIST, CIS, ISO 27001, PCI DSS, HIPAA, CMMC, and Microsoft security benchmarks.
  • Strong client-facing, executive communication, facilitation, and stakeholder management skills, with the ability to communicate effectively with both senior leaders and technical practitioners.
  • Ability to work directly with engineers and control owners to understand, validate, and document security control implementations.
  • Experience in an MSSP, MSP, consulting, professional services, federal program, or government contractor environment is preferred.
  • Experience with Microsoft Azure and Microsoft 365 security technologies is strongly preferred.
  • Familiarity with Azure, Entra ID, Defender, Sentinel, Intune, Purview, and Azure Policy is an advantage.
  • Relevant certifications such as CISSP, CISM, CRISC, CISA, CGEIT, or similar are valued.
  • Demonstrated leadership qualities including low-ego collaboration, initiative, accountability, empathy, situational awareness, and a bias toward practical problem-solving.
  • Ability to operate strategically with executives while remaining comfortable engaging deeply with technical details, compliance evidence, assessments, and remediation activities.

Benefits

  • Competitive salary based on experience and skills.
  • Performance-based compensation with bonus potential in addition to base salary.
  • 401(k) plan with a 100% employer match on employee contributions up to 4% of salary.
  • 100% employer-paid health, vision, and dental insurance premiums for employees.
  • Company-paid life, AD&D, short-term disability, and long-term disability insurance.
  • Three weeks of paid time off that can be used for vacation, personal time, or sick leave.
  • 11 paid holidays each year.
  • Paid community service leave for volunteering with organizations that are meaningful to you.
  • Employee recognition and reward programs celebrating strong performance and contributions.
  • Full-time remote work from anywhere in the United States, with the option to work from a local U.S. office when available.
  • An opportunity to lead a strategic GRC function, develop a team, work on complex federal compliance programs, and build scalable processes and automation.

How Jobgether works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Vacancy posted 5 days ago
Similar jobs that could be interesting for youBased on the Director of Governance, Risk & Compliance in United States vacancy
  •  ...To build and govern Engine's risk framework, the full-time remote Director of Risk Management will establish risk tolerance guidelines, oversee risk governance...  ...requirements including BSA/AML and card issuing compliance Experience in fintech, card issuing, or lending... 
    Suggested
    Full time
    Remote work

    Virtual Vocations Inc

    United States
    2 days ago
  •  ...hospital experience as CEO, CNO, COO, CFO, Director of Business Office, Director of Quality,...  ...of regulatory and accreditation compliance and surveys (Joint Commission, DHS, CMS,...  ...Analyzes incidents, sentinel events, and risk outcomes with administrators, physicians... 
    Suggested
    Work at office

    Southern Medical Recruiters

    Goodyear, AZ
    3 days ago
  •  ...Advance Auto Parts, Inc. seeks a Sr. Manager of Cybersecurity Third-Party Risk Management to lead the enterprise program for identifying, assessing, monitoring, and reducing third-party cybersecurity risks across suppliers, vendors, and service providers. The role... 
    Suggested

    Jobleads-US

    Raleigh, NC
    1 day ago
  •  ...Advance Auto Parts seeks a Director of Governance and Risk to define and deploy governance and risk management frameworks across the company. The...  ...CISO and will oversee policy, standards, and regulatory compliance while guiding risk discussions with the Board and ERM.... 
    Suggested

    Jobleads-US

    Raleigh, NC
    1 day ago
  •  ...MISA), Atmosera expertly delivers cutting-edge, integrated solutions that deliver business value. Your Impact The Director of Governance, Risk & Compliance (GRC) leads Atmosera's internal GRC program and Managed Governance, Risk & Compliance (MGRC) services. This is a hands... 
    Suggested
    Full time
    Remote work

    Atmosera

    Remote
    5 days ago
  •  ...listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Director of Governance, Risk & Compliance based in the United States. This is a hands-on leadership opportunity to own and evolve an internal Governance, Risk... 
    Full time
    Work at office
    Local area
    Remote work
    Work from home

    Jobgether

    Remote
    5 days ago
  •  ...), Atmosera expertly delivers cutting-edge, integrated solutions that deliver business value.\n Your Impact The Director of Governance, Risk & Compliance (GRC) leads Atmosera's internal GRC program and Managed Governance, Risk & Compliance (MGRC) services. This is... 
    Full time
    Temporary work
    For contractors
    Local area
    Remote work
    Work from home
    Flexible hours

    Atmosera

    Remote
    5 days ago
  •  ...Director of Quality and Risk Management This acute care hospital is a respected healthcare provider...  ...care through strong clinical governance, regulatory excellence, and continuous...  ...risk management programs. Ensure compliance with regulatory, accreditation, and... 
    Relocation package

    MRINetwork

    Modesto, CA
    5 days ago
  •  ...Tennant Company seeks a strategic Director of Cybersecurity to lead the enterprise cybersecurity...  ...You will set the cybersecurity vision, governance and operating priorities across the...  ...to the CIO and collaborates with IT, risk management, internal audit, legal and executives... 

    Jobleads-US

    Eden Prairie, MN
    1 day ago
  • $95.9k - $178.1k

     ...and has opportunities to grow and learnWhat Youll Do:Enterprise Risk Management ExecutionLead components of the Enterprise Risk...  ...summaries, dashboards, and presentations for senior leadership and governance forumsTranslate risk insights into actionable recommendations to... 
    Minimum wage
    Full time
    Contract work
    Work at office
    Flexible hours

    DXC Technology

    Saint Paul, MN
    1 day ago
  • $125.1k - $175.1k

     ...strategic leader to join our Third Party Risk Management (TPRM) function as a Director, Line 1B. This role is...  ...leading the Quality Assurance and governance oversight function across Vendor...  ...deep expertise in audit, regulatory compliance, and Risk & Control Self-Assessment... 
    Full time
    Temporary work
    Local area
    Flexible hours

    John Hancock

    Toronto, OH
    3 days ago
  • $285k - $295k

    Title: Director, Treasury RiskJob Location: One M&T Plaza, Buffalo, NY 14...  ...regulators. Develop, review and maintain risk management processes and procedures for governance and oversight of the Firm’s...  ..., and other methods to ensure compliance with liquidity ratios, LCR, and... 
    Full time
    Work experience placement
    Bank staff
    Work at office

    M&T Bank

    Buffalo, NY
    2 days ago
  •  ...assisting the Chief Fiduciary Officer with the design, execution, and administration of a division-wide fiduciary governance, risk management, and compliance oversight framework. The role provides management-level direction for the WMAS Compliance Officer and related... 
    Full time
    Contract work
    Local area

    Washington Trust Bank

    Boise, ID
    4 days ago
  • $180.08k - $247.6k

     ...and a chance to learn, effect change, and make meaningful contributions at work and in communities. ​The Director, Global Cybersecurity Governance, Risk, Compliance & Identity is accountable for defining and executing Donaldson’s enterprise cybersecurity governance and... 
    Full time
    Work experience placement
    H1b
    Work at office
    Remote work
    Relocation

    Donaldson company

    Minneapolis, MN
    1 day ago
  • $85.5k - $185k

     ...Dundas Street WestJob Family Group:Audit, Risk & ComplianceProvides oversight,...  ...management framework that includes the governance framework & practices leveraged across BMO...  ...standards for the assigned portfolio to ensure compliance as well as effective monitoring, timely... 
    Full time
    Contract work
    Part time
    Shift work

    BMO Bank

    Toronto, OH
    1 day ago
  • $103.9k - $148.4k

    The Supplier Risk Manager is a senior-level role within Global Supplier Management (GSM...  ...risk programs and establish the governance frameworks, analytics infrastructure, and...  ...governance mechanisms to ensure policy compliance and drive continuous improvement• Partner... 
    Flexible hours

    Amazon

    Houston, TX
    4 days ago
  • As part of Risk Management and Compliance, you are at the center of keeping JPMorgan Chase strong and resilient...  ...to be best-in-class.As an Executive Director, Head of North America Capital Risk...  ...risk assessment, limits, and governance while partnering closely with senior... 

    JP Morgan Chase

    Brooklyn, NY
    22 hours ago
  •  ...Risk Manager The Manager, Risk Management leads the program...  .... This role establishes risk governance, ensures consistent identification...  ..., quality, regulatory, and compliance requirements. Coach...  ...structures across EO. Support the Director, Program Management with... 
    Flexible hours

    BWXT Technologies

    Oak Ridge, TN
    2 days ago
  •  ...Must needed Direct line phone no must needed Risk Manager New York, NY On Site Contract - 6 month(s)...  ...& Controls Manager to join its Information Security GRC (Governance, Risk & Compliance) team. In this role, the Risk & Controls Manager will be responsible... 
    Contract work
    Remote work

    3B Staffing LLC

    New York, NY
    2 days ago
  • $108k - $180k

     ...GRC Risk ManagerLos AngelesAbout SHEINSHEIN Technology is a U.S. technology company. Founded in 2012, SHEIN is a leading...  ...security infrastructure, risk management, data privacy, governance and regulatory compliance across SHEIN's global footprint. It is composed of a team... 
    Temporary work
    Work at office

    SHEIN

    Los Angeles, CA
    4 days ago
  •  ...Senior Project Risk ManagerLawrence Berkeley National Laboratory is seeking an accomplished Senior Project Risk Manager to lead integrated...  ...improve risk processes, tools, reporting, training, and governance.What You Bring8+ years of progressively responsible experience... 

    Bay Systems Consulting Inc

    Berkeley, CA
    4 days ago
  •  ...Key Responsibilities Job Title: Risk Manager Location: Washington, DC Metropolitan Area...  ...risk management, program risk governance, and strategic planning to help the organization...  ...Support audits, inspections, assessments, and compliance reviews related to risk management... 
    Full time
    Contract work
    Temporary work
    Work at office
    Local area
    Immediate start
    Home office
    Flexible hours

    Management Solutions

    Washington DC
    22 hours ago
  • Bring your expertise to JPMorgan Chase. As part of Risk Management and Compliance, you are at the center of keeping JPMorgan Chase strong and resilient...  ...credit strategy, controls, and (as applicable) model governance.Job Responsibilities: Analyzes and decisions credit... 

    JP Morgan Chase

    Plano, TX
    1 day ago
  •  ...team and our firm.Learn more about our services, industry experience and culture at weaver.com.Position ProfileWeaver’s Governance, Risk and Compliance (GRC) team is looking for a dynamic, driven, experienced Senior Manager to join our growing Public Sector practice. The... 
    Full time
    Contract work
    Local area
    Flexible hours

    Weaver and Tidwell

    Austin, TX
    3 days ago
  • Job DescriptionManager Global Risk & Controls - Chicago, IL (On-site) Role OverviewThe...  ...Audit Readiness, Controls, and Policy Governance plays a critical role in building and sustaining...  ..., not managed as after‑the‑fact compliance activities.Finance policies are clear, current... 
    Hourly pay
    Worldwide
    Flexible hours

    ADM

    Chicago, IL
    2 days ago
  • $102k - $178.4k

     ...obsessed with customer trust and are seeking an individual contributor who is creative, and passionate about delivering Governance, Risk and Compliance solutions to meet Leo's regulatory and external assurance needs. In this role, you will work collaboratively with... 
    Permanent employment
    Temporary work
    Worldwide
    Flexible hours

    Amazon

    Redmond, WA
    3 days ago
  • $201.48k - $218.01k

     ...of hire. Applicants selected will be subject to a U.S. Government security investigation and must meet eligibility...  ...Position General Dynamics Mission Systems is seeking a Director, IT Governance, Risk, Compliance & AI to lead the enterprise governance function across... 
    Work experience placement
    Flexible hours

    General Dynamics Mission Systems

    Chantilly, Loudoun County, VA
    4 days ago
  • $308k

     ...digital landscape. We are seeking a pragmatic, strategic, and highly credible Head of Enterprise Security to lead our Governance, Risk, and Compliance (GRC), and Data Security with a clear focus on AI Security and Governance. This role operates in a highly collaborative... 
    Work at office
    Relocation package
    3 days per week

    Nutanix

    San Jose, CA
    1 day ago
  • $208.55k - $254.85k

     ...authorizations to delivering comprehensive medication histories to facilitating messages between providers.Job Summary:The Director of Governance, Risk and Compliance provides strategic oversight of the Governance Risk and Compliance (GRC) information security team to ensure... 
    Full time
    Casual work
    Work at office
    Local area
    Immediate start
    Flexible hours

    Surescripts

    Arlington, VA
    22 hours ago
  •  ...Manager, this role leads and advances the business unit’s risk and compliance programs by directing risk and control assessment methodologies...  ..., new product and service risk reviews, operational risk governance, and risk reporting. The role monitors, directs, and... 
    Work experience placement
    Work at office

    Bank of Hawaii

    Honolulu, HI
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Director of Governance, Risk & Compliance. Be the first to apply!