Executive Advisor - Governance, Risk & Compliance

Malleum

California (MO)

Hybrid

CAD 150,000 - 210,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Competitive executive compensation
Equity-style participation in practice
Certification sponsorship
Flat, high-trust culture
Continuous learning budget

Job summary

Malleum is seeking a very senior governance, risk and compliance specialist to lead strategic GRC engagements and scale our advisory practice in space, aerospace, and defense sectors. This remote role travels to client sites, typically Ontario-based, as required.

You will serve as trusted counsel to CISOs, CIOs, CROs and boards, translating regulatory complexity into pragmatic, mission-aligned programs and mentoring the next generation of Malleum advisors.

Qualifications

  • 15+ years of cybersecurity and GRC experience in leadership roles.
  • Experience building and scaling Cyber Resilience Programs.
  • Deep expertise in CMMC Levels 1–3 and CPCSC requirements.
  • Experience advising space, aerospace, and defense sectors; ITAR/CGP familiarity.
  • Strong knowledge of NIST CSF 2.0, NIST 800-53/171/172, ISO 27001/27005, ITSG‑33, SOC 2, and privacy regimes (PIPEDA, GDPR).
  • Executive presence and ability to advise CISOs, CIOs, CFOs, GCs, audit committees, boards.
  • Bachelor's degree; MBA/MS preferred.

Responsibilities

  • Lead executive-level GRC advisory engagements across space, aerospace, defense, government, and critical infrastructure.
  • Stand up and mature Cyber Resilience Programs at large enterprises, integrating governance, risk management, business continuity, third‑party risk, and incident readiness into a cohesive operating model.
  • Advise C‑suite and board stakeholders on cyber risk posture, regulatory exposure, and strategic investment priorities.
  • Lead client journeys to CMMC readiness and CPCSC requirements, including scoping, gap assessments, SSP/POAM development, and assessor coordination.
  • Lead client adoption of CPCSC for organizations supporting the Government of Canada defense supply chain.
  • Develop, operationalize, and audit programs aligned with NIST CSF 2.0, NIST 800‑53/171/172, ISO 27001/27005, ITSG‑33, SOC 2, and privacy regimes.
  • Advise space-sector clients on evolving requirements such as Space ISAC guidance and allied space defense expectations.
  • Define and implement enterprise risk management frameworks, KRIs/KPIs, risk appetite statements, and board reporting cadences.
  • Lead third‑party / supply‑chain risk programs aligned with defense industrial base and allied requirements.
  • Shape Malleum's GRC service offerings, methodologies, accelerators, and intellectual property.
  • Mentor and develop senior managers, managers, and consultants.
  • Drive business development: trusted‑advisor relationships, account growth, proposals, and thought leadership.
  • Represent Malleum in industry forums, regulator engagements, client briefings, and executive roundtables.

Skills

Cybersecurity leadership
GRC management
Regulatory compliance
CMMC knowledge
NIST CSF
Board-level advisory
Mentoring teams
Executive communication
Strategic risk thinking

Education

Bachelor's degree
MBA/MS preferred

Tools

CISSP
CISM
CRISC
CGEIT
CISA

Job description

About Malleum

Malleum is at the forefront of next-generation cyber defense, partnering with marquee clients across space, aerospace, defense, government, financial services, and critical infrastructure. We're experiencing exceptional growth as demand accelerates for trusted advisors capable of delivering at the intersection of national security, allied intelligence cooperation, and enterprise resilience. Our advisors shape the governance, risk, and compliance programs that underpin cutting-edge defensive technologies, sovereign space capabilities, and allied programs with national security impact– from satellite and launch operations to next-generation defense platforms.

If you take pride in shaping how the most consequential organizations govern cyber risk and want your counsel to influence sovereign and allied missions, Malleum is where your leadership meets purpose.

The Opportunity

We're seeking a very senior governance, risk and compliance specialist to lead our most strategic GRC engagements and to help scale our advisory practice across the space, aerospace, and defense sectors.

In this role you'll serve as a trusted counsel to CISOs, CIOs, CROs, and boards– translating regulatory complexity into pragmatic, mission-aligned programs. This is a remote position, with travel to client sites – typically Ontario-based – as required.

This is a senior leadership role for a recognized GRC practitioner who has stood up enterprise-grade cyber resilience programs, navigated the most demanding compliance regimes, and can mentor the next generation of Malleum advisors.

What You’ll Do
  • Lead executive-level GRC advisory engagements for clients across space, aerospace, defense, government, and critical infrastructure
  • Stand up and mature Cyber Resilience Programs at large enterprises, integrating governance, risk management, business continuity, third‑party risk, and incident readiness into a cohesive operating model
  • Advise C‑suite and board stakeholders on cyber risk posture, regulatory exposure, and strategic investment priorities
  • Lead client journeys to CMMC (Cybersecurity Maturity Model Certification) readiness and certification, including scoping, gap assessments, SSP/POAM development, and assessor coordination
  • Lead client adoption of the Canadian Program for Cyber Security Certification (CPCSC) for organizations supporting the Government of Canada defense supply chain
  • Develop, operationalize, and audit programs aligned with NIST CSF 2.0, NIST 800‑53/171, ISO 27001/27005, ITSG‑33, SOC 2, and sector‑specific frameworks
  • Advise space‑sector clients on emerging requirements such as Space ISAC guidance, NIST IR 8401 (Satellite Ground Segment), and allied space defense expectations
  • Define and implement enterprise risk management frameworks, KRIs/KPIs, risk appetite statements, and board reporting cadences
  • Lead third‑party / supply‑chain risk programs aligned with defense industrial base (DIB) and allied requirements
  • Shape Malleum's GRC service offerings, methodologies, accelerators, and intellectual property
  • Mentor and develop senior managers, managers, and consultants — building bench strength and a strong delivery culture
  • Drive business development: trusted‑advisor relationships, account growth, proposals, and thought leadership across the space, aerospace, and defense ecosystem
  • Represent Malleum in industry forums, regulator engagements, client briefings, and executive roundtables
What You Bring
  • 15+ years of progressive cybersecurity and GRC experience, including senior leadership roles in consulting, industry, or government
  • Demonstrated track record standing up and scaling Cyber Resilience Programs for large, complex enterprises — including governance structures, risk frameworks, control libraries, metrics, and operating cadences
  • Deep expertise across CMMC (Levels 1–3) and emerging CPCSC requirements, including how each maps to NIST 800‑171 / 800‑172 and supplier obligations
  • Hands‑on experience advising clients in space, aerospace, and defense — familiarity with ITAR, CGP, controlled goods, export controls, and allied compliance regimes
  • Strong command of NIST CSF 2.0, NIST 800‑53/171/172, ISO 27001/27005, ITSG‑33, SOC 2, PCI DSS, and relevant privacy regimes (PIPEDA, Quebec Law 25, GDPR)
  • Executive presence — proven ability to advise CISOs, CIOs, CFOs, GCs, audit committees, and boards
  • Strong commercial acumen — practice building, account growth, proposal leadership, and revenue accountability
  • Demonstrated leadership in mentoring, coaching, and developing high‑performing GRC teams
  • Certifications such as CISSP, CISM, CRISC, CGEIT, CISA, ISO 27001 Lead Auditor/Implementer, or CMMC Registered Practitioner (RP) strongly preferred
  • Eligibility for Government of Canada security clearance (Secret or higher); existing clearance highly valued
  • French fluency is an asset
  • Bachelor's degree required; advanced degree (MBA, MS in Cybersecurity) preferred
Why Malleum
  • Lead GRC programs with genuine national and allied security impact across space, aerospace, and defense
  • Shape the strategy and growth of a rapidly scaling advisory practice with direct partner‑level visibility
  • Work alongside seasoned IR, offensive security, engineering, and program leaders on the most consequential client missions
  • Highly competitive executive compensation, performance incentives, and equity‑style participation in practice growth
  • Continuous learning budget, certification sponsorship, and a platform to publish, speak, and shape industry dialogue
  • A flat, high‑trust culture that rewards judgment, ownership, and mission focus

Malleum is an equal opportunity employer. We welcome applications from all qualified candidates and are committed to building a team that reflects the communities and missions we serve.

We are committed to providing accommodations for individuals with disabilities throughout the recruitment process. Please let us know if you require accommodation at any stage.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Account Executive – Managed Services
Senior Account Executive – Managed Services

Malleum • California (MO)

Hybrid
USD 99,000 - 156,000
Competitive base salary
Performance incentives
Learning budget
Remote Senior GRC Advisor for Space & Defense
Remote Senior GRC Advisor for Space & Defense

Malleum • California (MO)

Hybrid
CAD 150,000 - 210,000
Competitive executive compensation
Equity-style participation in practice
Certification sponsorship
+2
Practice Lead, GRC Advisory for Shellproof Security
Practice Lead, GRC Advisory for Shellproof Security

The ProActive Technology Group • New York (NY)

On-site
USD 100,000 - 150,000
Competitive salary
Health, vision, and dental benefits
Performance-based incentives
+3
Cyber Advisor
Cyber Advisor

Eccalon, LLC • Detroit (MI)

On-site
USD 120,000 - 180,000
Remote Senior MSP Revenue Leader - Cybersecurity
Remote Senior MSP Revenue Leader - Cybersecurity

Malleum • California (MO)

Hybrid
USD 99,000 - 156,000
Competitive base salary
Performance incentives
Learning budget
Cyber Advisor
Cyber Advisor

Paychex Inc. • Detroit (MI), Northern (KY)

On-site
USD 120,000 - 180,000
GRC Consultant
GRC Consultant

Cyberr • United States

On-site
USD 90,000 - 130,000
Technical Cyber Advisor On-site
Technical Cyber Advisor On-site

Paychex Inc. • Detroit (MI)

Hybrid
USD 90,000 - 130,000
Cyber Advisor
Cyber Advisor

Eccalon LLC • Detroit (MI)

On-site
USD 120,000 - 170,000
Technical Cyber Advisor
Technical Cyber Advisor

Eccalon LLC • Hanover (MD)

Hybrid
USD 110,000 - 165,000