Director, Cybersecurity GRC

Communitybrands

United States

On-site

USD 190,000 - 240,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Momentive Software seeks a Director of Cybersecurity GRC to lead governance, risk, and compliance activities, align with regulations, and guide contract reviews. This executive will partner with Legal, IT, and business units to drive a robust IS GRC program, uphold ISMS, and support growth and M&A readiness.

The role focuses on strategy, stakeholder engagement, and continual program improvement across Cybersecurity, IT, and external partners within a fast-moving environment.

Qualifications

  • Experience leading GRC programs and cybersecurity operations.
  • Strong knowledge of governance, risk, and compliance frameworks.
  • Contract review, client audits, and regulatory due diligence.

Responsibilities

  • Own IS GRC governance, risk assessment, compliance, and audit support.
  • Improve cybersecurity program using technology, processes, and people leadership.
  • Provide audit support for client engagements, RFPs, and regulatory reviews.
  • Oversee IS GRC toolsets, platforms, and operating procedures; manage budget.

Job description

Job Description
POSITION OVERVIEW

The Director, Cybersecurity GRC manages the people, processes, and technology related to Momentive Software's Cybersecurity GRC group - overseeing governance, risk, and compliance activities including client audit support, RFP response, internal IT audit, and contract review. This role carries out GRC activities in alignment with the Firm's business objectives, regulatory requirements, and strategic goals, with a focus on recognized cybersecurity frameworks and contractual compliance. The Director serves as the process owner for all IS GRC-related projects and activities and assists the CISO in planning, developing, and overseeing the cybersecurity program. The role integrates across Cybersecurity, Information Technology, new business development, the Office of General Counsel, and the professional responsibility function. In addition to ongoing governance and operational oversight, this position supports strategic alignment with the business, cybersecurity outreach, and expert guidance to internal and external stakeholders. As a strategic partner to the business, this role helps Momentive win and retain enterprise clients, support growth and M&A readiness, and position the GRC program as a business enabler - not just a compliance function.

KEY RESPONSIBILITIES
GRC Program Leadership
  • Maintain direct responsibility for all aspects of IS GRC, including governance, risk assessment, compliance, and audit support.
  • Ensure continual improvement of the cybersecurity program through effective application of technology, systems, processes, personnel development, and leadership.
  • Provide cybersecurity services that meet or exceed the Firm's professional, contractual, regulatory, and certification requirements.
  • Manage the Firm's IS GRC people, processes, and technology infrastructure, including creation and review of IS GRC standards, guidelines, and operating procedures.
  • Serve as the business owner for IS GRC toolsets, platforms, and processes.
  • Manage the IS GRC team budget.
  • Consult with Legal regarding acceptable contract terms and conditions related to cybersecurity.
ISMS & System Governance
  • Lead the System Governance Virtual Team, promoting continual ISMS improvement across the Firm.
  • Provide direction on risk assessment requirements and assistance evaluating risk treatment plans.
  • Provide input on the selection and design of IS controls.
  • Provide input on metrics developed to monitor and test the effectiveness of the Firm's IS controls.
  • Define documentation requirements to ensure compliance with ISMS requirements.
  • Advise the team on client contractual requirements and Firm commitments relative to GRC practices.
  • Assist the team in developing systems and processes that ensure ISMS compliance and continual improvement.
  • Maintain the Firm's Cybersecurity Management System (ISMS), including the creation and review of policies, standards, and procedures.
  • Enforce, monitor, and report on compliance with the Firm's ISMS.
  • Partner with the Director, AI Governance to co-develop and align AI policies, assess AI-related risks, and integrate AI governance practices into the ISMS framework.
Cybersecurity Operations & Engineering Integration
  • Work closely with Cybersecurity Operations and Engineering teams to define, develop, and facilitate efficient and effective service delivery.
  • Oversee integrated vendor and other risk assessment activities in coordination with technical teams.
  • Liaise with system and business owners to ensure new platforms comply with Firm cybersecurity requirements.
  • Serve within the Firm's Computer Cybersecurity Incident Response Team (CSIRT).
Compliance & Audit
  • Oversee cybersecurity risk assessments and provide audit mechanisms for the cybersecurity process.
  • Meet published SLAs for the provisioning and support of cybersecurity GRC operations and activities.
  • Provide evidence and expert support for client audits, RFP responses, and regulatory reviews.
  • Track compliance with applicable regulatory schemes and monitor changes in legislation and accreditation standards.
Cybersecurity Awareness & Culture
  • Manage the cybersecurity awareness program, including phishing simulation and constituent outreach initiatives.
  • Initiate, facil...
  • Maintain and contribute to the Firm's cybersecurity-related information repositories.
Leadership & People Management
  • Mentor and lead members of the Cybersecurity GRC group through effective performance reviews, development opportunities, and a culture of performance excellence.
  • Direct reports include TPRM Advisors, who manage third-party risk management activities across the organization; this role carries full people management accountability for that team.
  • Transform executive priorities into operational GRC initiatives with clear vision, support, and expectation-setting.
  • Provide status reports and relevant metrics to the CISO.
  • Serve in a proactive, consultative role to othe
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Director, Cybersecurity GRC & Strategic Risk
Director, Cybersecurity GRC & Strategic Risk

Momentive Software, Inc. • United States

Hybrid
USD 180,000 - 260,000
Remote Work Flexibility
401(k) Savings Plan with Company Match
Flexible Planned Paid Time Off
Cyber GRC Director: Strategy, Risk & Compliance
Cyber GRC Director: Strategy, Risk & Compliance

Communitybrands • United States

On-site
USD 190,000 - 240,000
Remote Director, Cybersecurity GRC & Strategy
Remote Director, Cybersecurity GRC & Strategy

Momentive Software, Inc. • Northern (KY)

Remote
USD 180,000 - 240,000
Director, Cybersecurity GRC
Director, Cybersecurity GRC

Momentive Software, Inc. • United States

Hybrid
USD 180,000 - 260,000
Remote Work Flexibility
401(k) Savings Plan with Company Match
Flexible Planned Paid Time Off
IT Sr Director, Compliance and Risk Governance
IT Sr Director, Compliance and Risk Governance

Intuitive • Sunnyvale (CA)

On-site
USD 180,000 - 300,000
Director, Cybersecurity GRC
Director, Cybersecurity GRC

Momentive Software, Inc. • Northern (KY)

Remote
USD 180,000 - 240,000
GRC, Data Privacy & Technical Cybersecurity SME - Senior Manager
GRC, Data Privacy & Technical Cybersecurity SME - Senior Manager

CFGI • United States

On-site
USD 170,000 - 260,000
Director of Cybersecurity, Governance, Risk and Compliance
Director of Cybersecurity, Governance, Risk and Compliance

Gross, Mendelsohn & Associates, P.A. • Baltimore (MD)

On-site
USD 180,000 - 240,000
Senior Analyst, Cyber Governance, Risk and Compliance (GRC)
Senior Analyst, Cyber Governance, Risk and Compliance (GRC)

H.I.G. Capital • Coral Gables (FL)

On-site
USD 120,000 - 170,000
VP of Governance, Risk & Compliance
VP of Governance, Risk & Compliance

Tiro Security • Los Angeles (CA)

On-site
USD 200,000 - 280,000