Governance, Risk & Compliance (GRC) Manager

Northwood Space

El Segundo (CA)

On-site

USD 150,000 - 230,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Northwood Space seeks a seasoned Governance, Risk & Compliance Lead to own the company’s compliance program across CMMC, FedRAMP, SOC 2 and ITAR. You will translate regulatory requirements into practical controls and work with security engineering, network and product teams to embed compliance into operations.

As the primary contact for government customers and assessors, you will manage SSPs, POA&Ms, risk registers, and audit readiness, while aligning control frameworks with NIST and ITAR/DFARS

Qualifications

  • Senior GRC professional with deep regulatory knowledge and technical fluency.
  • Ability to translate compliance requirements into operational controls.
  • Experience across government and security environments.

Responsibilities

  • Own Northwood's compliance program across CMMC Level 2, FedRAMP, SOC 2 Type II, and ITAR, including control mapping, gap assessment, remediation tracking, and audit preparation.
  • Maintain SSP, POA&M, and related documentation per NIST 800-171/800-53 and applicable frameworks.
  • Coordinate and manage third-party assessments and audits with 3PAOs and assessors.
  • Monitor regulatory changes and assess impact on compliance posture.
  • Lead risk management activities including risk registers, scoring, and executive reporting.
  • Develop and maintain security policy library and control framework mappings across NIST, SOC 2, and FedRAMP.
  • Oversee ITAR & CUI program management, data classification, handling procedures, and training.
  • Ensure readiness for audits and engage with stakeholders across security, engineering, product, and operations.

Skills

GRC leadership
Regulatory compliance
ITAR compliance
FedRAMP
CMMC
SOC 2
Risk management
Policy development
Audit readiness

Job description

Northwood is a modern space infrastructure company bringing the benefits of space to the masses through advanced communications technology. We are building a global network of phased array ground stations that enable real-time, reliable communication for satellite missions such as national security, global connectivity, and disaster response. With a vertically integrated approach, Northwood designs, builds, and rapidly deploys scalable systems that power the next generation of space missions. If you like solving complex challenges and seeing your work deployed around the world with real impact, Northwood is the place to do it.

Role Overview

As Governance, Risk & Compliance (GRC) Lead, you will own Northwood's compliance program across CMMC, FedRAMP, SOC 2, and ITAR — building the policies, processes, and evidence frameworks that enable the company to operate as a trusted dual-use space communications provider. This is a senior individual contributor role for a practitioner who combines deep regulatory knowledge with the technical fluency to work directly with security engineering, network, and product teams to translate compliance requirements into operational reality.

You will serve as the primary point of contact for government customers, third-party assessors, and internal stakeholders on all matters related to compliance posture, risk management, and audit readiness. You will work across Northwood's full security stack — spanning on-premises infrastructure, AWS GovCloud, GCC, and corporate systems — to ensure controls are implemented, documented, and defensible. This role reports to the Head of Security.

Responsibilities
Compliance Program Ownership

- Own Northwood's compliance program across CMMC Level 2, FedRAMP, SOC 2 Type II, and ITAR, including control mapping, gap assessment, remediation tracking, and audit preparation.

- Maintain Northwood's System Security Plan (SSP), Plan of Action and Milestones (POA&M), and associated compliance documentation in alignment with NIST 800-171 and applicable frameworks.

- Coordinate and manage third-party assessments, including C3PAO engagements for CMMC, FedRAMP 3PAO assessments, and SOC 2 audits, serving as the primary assessor liaison.

- Monitor the regulatory environment for changes to CMMC, FedRAMP, DFARS, and ITAR requirements and assess impact on Northwood's compliance posture.

Risk Management

- Build and maintain Northwood's enterprise risk management program, including risk register development, risk scoring methodology, and executive-level risk reporting.

- Conduct and facilitate periodic risk assessments across security domains, incorporating input from security engineering, network, product, and operations teams.

- Identify, track, and drive remediation of compliance gaps and security control deficiencies, working directly with technical teams to ensure timely closure.

- Develop and maintain risk acceptance processes, exception management workflows, and compensating control documentation.

Policy & Control Framework

- Develop, maintain, and enforce Northwood's security policy library, including acceptable use, access control, incident response, data classification, and CUI handling policies.

- Map Northwood's control environment across overlapping frameworks — NIST 800-171, NIST 800-53, SOC 2 Trust Services Criteria, and FedRAMP — to reduce duplicative compliance effort and maximize control reuse.

- Define and maintain the control evidence collection program, ensuring audit artifacts are continuously gathered, organized, and accessible for assessment cycles.

- Partner with the Security Engineering Lead, Security Operations Lead, and Product Security Lead to validate that technical controls are implemented in alignment with documented policies and compliance requirements.

ITAR & CUI Program Management

- Own Northwood's CUI program, including data classification guidance, CUI handling procedures, marking standards, and employee training.

- Maintain ITAR compliance program documentation, including technology control plans, export authorization tracking, and coordination with Northwood's legal counsel on regulatory obligations.

- Ensure network segmentation, access controls, and data handling practices across Northwood's infrastructure appropriately enforce CUI and ITAR boundaries in coordination with security and network engineering teams.

Audit Readiness & Stakeholder Engagement

- Serve as the primary compliance point of contact for

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Governance, Risk & Compliance (GRC) Manager
Governance, Risk & Compliance (GRC) Manager

Northwood Space • Torrance (CA)

On-site
USD 120,000 - 150,000
Governance, Risk & Compliance (GRC) Manager
Governance, Risk & Compliance (GRC) Manager

Industrious Ventures • Torrance (CA)

On-site
USD 120,000 - 150,000
GRC Lead: Space Tech Compliance & Risk
GRC Lead: Space Tech Compliance & Risk

Northwood Space • El Segundo (CA)

On-site
USD 150,000 - 230,000
Senior GRC Lead: CMMC, FedRAMP, SOC 2, ITAR
Senior GRC Lead: CMMC, FedRAMP, SOC 2, ITAR

Northwood Space • Torrance (CA)

On-site
USD 120,000 - 150,000
Corporate IT Security Engineer
Corporate IT Security Engineer

Northwood Space • Torrance (CA)

On-site
USD 120,000 - 170,000
Corporate IT Security Engineer
Corporate IT Security Engineer

Northwood • Torrance (CA)

On-site
USD 120,000 - 180,000
Identity & Endpoint Security Engineer
Identity & Endpoint Security Engineer

Industrious Ventures • Torrance (CA), Northern (KY)

Hybrid
USD 140,000 - 190,000
Security Operations Manager
Security Operations Manager

Industrious Ventures • Torrance (CA)

On-site
USD 120,000 - 150,000
Security Operations Manager
Security Operations Manager

Northwood Space • Torrance (CA)

On-site
USD 120,000 - 160,000
Security Operations Manager
Security Operations Manager

Northwood • Torrance (CA)

On-site
USD 120,000 - 160,000