Governance Risk Compliance Senior Manager

B12 Consulting

Houston (TX)

On-site

USD 147,050 - 230,850

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

A leading consulting firm seeks a Governance Risk Compliance Senior Manager to oversee GRC programs, ensuring effective policies and compliance standards are met. This role requires expertise in compliance frameworks, risk management, and leadership skills in a cross-functional environment. Ideal candidates will possess a Bachelor's degree and 5–7 years in GRC or related fields, including experience with PCI DSS and SOC compliance. Offering a competitive salary range and full-time engagement in Houston, TX.

Qualifications

  • 5–7 years of progressive experience in GRC, compliance, audit, or risk management roles.
  • Minimum 2–3 years of direct experience managing PCI DSS and SOC 1/SOC 2 compliance efforts.
  • Proven experience in developing and managing vendor risk and third-party assessment programs.

Responsibilities

  • Provide executive oversight of Governance, Risk & Compliance programs.
  • Direct and support the activities of compliance managers.
  • Ensure compliance with data security standards including PCI DSS, SOC 1, and SOC 2.

Skills

Compliance and assurance frameworks knowledge
Risk management
Governance models
Change management frameworks
IT controls understanding
Analytical skills
Communication skills
Strategic planning skills
Public sector regulatory knowledge
Cross-functional relationship building

Education

Bachelor’s degree in Information Security, Risk Management, Business Administration or related field

Job description

Governance Risk Compliance Senior Manager

Provide executive oversight of Governance, Risk & Compliance programs including policy governance, enterprise risk management, compliance frameworks, and change initiatives.

Direct and support the activities of the Manager of Governance, Manager of Risk & Compliance, and Manager of Change Management to ensure program integration, continuity, and effectiveness.

Ensure compliance with data security and assurance standards including PCI DSS, SOC 1, and SOC 2 by developing and maintaining relevant policies, controls, and audits.

Develop and maintain a comprehensive risk assessment and mitigation strategy for the company's Tolling Operations.

Oversee the third‑party risk management (TPRM) program, conducting vendor due diligence, security assessments, and contract reviews to ensure appropriate risk controls are in place.

Collaborate with internal departments and external partners to improve operational governance and risk posture.

Lead strategic planning and reporting related to GRC objectives and performance metrics.

Support training, communication, and awareness programs to cultivate a risk‑informed organizational culture. Participate in audit and incident response processes to ensure transparency and appropriate mitigation.

Knowledge, Skills and Abilities
  • Expert knowledge of compliance and assurance frameworks including PCI DSS, SOC 1, and SOC 2 reporting requirements.
  • Extensive knowledge of risk management, compliance regulations, governance models, and change management frameworks.
  • Strong understanding of IT controls, data protection policies, and third‑party risk.
  • Proven leadership and people management skills in cross‑functional environments.
  • Excellent analytical, communication, and strategic planning skills with the ability to translate complex security and compliance issues into business‑relevant language.
  • Deep understanding of public sector regulatory environments and operations.
  • Ability to build cross‑functional relationships and lead multi‑departmental initiatives.
Required Education/Experience
  • Bachelor’s degree in Information Security, Risk Management, Business Administration, or related field.
  • 5–7 years of progressive experience in GRC, compliance, audit, or risk management roles.
  • Minimum 2–3 years of direct experience managing PCI DSS and SOC 1/SOC 2 compliance efforts.
  • Proven experience developing and managing vendor risk and third‑party assessment programs.
  • Leadership or mentoring experience in a GRC or risk‑focused role.
Preferred Professional Certifications
  • Certified Information Systems Auditor (CISA)
  • Certified in Risk and Information Systems Control (CRISC)
  • Certified Information Security Manager (CISM)
  • Certified Information Systems Security Professional (CISSP)
  • Certified in Governance of Enterprise IT (CGEIT)
  • PCI Professional (PCIP) or similar PCI‑related certification
Employment Details
  • Seniority level: Mid‑Senior level
  • Employment type: Full‑time
  • Job function: Information Technology and Consulting
  • Industries: Transportation, Logistics, Supply Chain and Storage
  • Location: Spring, TX
  • Salary: $147,050.00–$230,850.00
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Governance, Risk and Compliance (GRC) Lead - 249079
Governance, Risk and Compliance (GRC) Lead - 249079

Medix Technology • Northfield Township (IL)

On-site
USD 90,000 - 130,000
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

LexisNexis • Raleigh (NC)

On-site
USD 118,000 - 220,000
Manager - IT Governance, Risk and Compliance
Manager - IT Governance, Risk and Compliance

Plexus Corp. • Neenah (WI)

On-site
USD 112,000 - 169,000
Manager of Information Security and Compliance
Manager of Information Security and Compliance

iboss • United States

On-site
USD 100,000 - 130,000
Health, Vision, Dental
401(k) with company match
Unlimited Paid Time Off
+1
Manager, IT Security, Governance, Risk and Compliance
Manager, IT Security, Governance, Risk and Compliance

Burlington Stores, Inc. • Beverly (NJ)

Hybrid
USD 115,000 - 150,000
Medical, dental, and vision coverage
Paid time off and holidays
401(k) plan
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

RELX • Raleigh (NC)

On-site
USD 118,000 - 220,000
Annual incentive bonus
Governance, Risk and Compliance Analyst Senior
Governance, Risk and Compliance Analyst Senior

Cone Health • Greensboro (NC)

On-site
USD 90,000 - 130,000
Senior GRC Leader: Risk, Compliance & IT Controls
Senior GRC Leader: Risk, Compliance & IT Controls

B12 Consulting • Houston (TX)

On-site
USD 147,000 - 231,000
IT GRC Lead Analyst
IT GRC Lead Analyst

Westfield Insurance • Westfield Center (OH)

Hybrid
USD 90,000 - 120,000
Information Technology Governance Manager
Information Technology Governance Manager

Signet Jewelers • United States

Hybrid
USD 140,000 - 170,000
401(k) matching