GRC Lead

Jobtailor

Houston (TX)

On-site

USD 120,000 - 180,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Jobtailor is seeking a senior GRC leader to mature our governance, risk, and compliance program. The role focuses on translating regulatory requirements into controls, policies, and evidence collection while coordinating audits and certifications.

You will build a robust third-party risk program and own policy lifecycle, with an emphasis on data protection, privacy, and incident governance. Collaboration with Legal, IT, and stakeholders is essential.

Qualifications

  • Bachelor’s degree or equivalent experience in a relevant field.
  • Experience leading or implementing GRC programs and audits.
  • Familiarity with major compliance standards (CMMC, GDPR, NIST CSF).
  • Proven ability to translate requirements into controls, policies, and evidence collection.

Responsibilities

  • Lead and mature the organization’s GRC program, including CMMC, GDPR, and other applicable requirements.
  • Translate requirements into controls, policies, procedures, compliance roadmaps, and evidence-collection processes.
  • Coordinate audits, assessments, certifications, customer questionnaires, remediation plans, and compliance reporting.
  • Build and manage a third-party vendor-risk program with due diligence, risk assessments, and remediation tracking.
  • Own lifecycle of policies, including review, publication, training, and exception management.
  • Develop executive dashboards and reports on compliance posture, audits, and vendor risk.

Skills

Governance
Risk Management
Compliance
Audit Management
Policy Development
Control Implementation
Data Protection
Vendor Risk Management
Privacy Impact Assessment
Incident Response

Education

Bachelor’s degree in cybersecurity, information systems, business, risk management, law, or related field

Tools

GRC Tools
Audit Management Tools
Vendor Risk Management Tools
Workflow Tools

Job description

  • Lead and mature the organization’s GRC program, including CMMC, GDPR, and other applicable requirements
  • Translate requirements into controls, policies, procedures, compliance roadmaps, and evidence-collection processes
  • Coordinate internal and external audits, assessments, certifications, customer questionnaires, remediation plans, and compliance reporting
  • Build and manage a third-party vendor-risk program, including due diligence, risk assessments, security and privacy reviews, monitoring, and remediation tracking
  • Own the lifecycle of security, privacy, and compliance policies, including review, approval, publication, employee acknowledgment, training, and exception management
  • Develop executive dashboards and reports covering compliance posture, audit readiness, control effectiveness, vendor risk, and remediation progress
  • Partner with Legal, Privacy, Procurement, IT, Information Security, and business stakeholders
  • Support security awareness, business continuity, incident-response governance, data protection, and customer security reviews
  • Lead or mentor GRC personnel and serve as primary contact for auditors, assessors, vendors, customers, and internal stakeholders
Requirements
  • Professional certifications such as CISA, CRISC, CISSP, CISM, ISO 27001 Lead Implementer or Lead Auditor, CDPSE, CIPM, CIPP/US, CIPP/E, or similar
  • Experience supporting CMMC assessments or implementing controls aligned with NIST SP 800-171
  • Experience with privacy-impact assessments, data-protection impact assessments, or GDPR compliance programs
  • Familiarity with GRC, audit-management, vendor-risk-management, and workflow tools
  • Experience in a regulated industry, government contracting environment, SaaS organization, or other security-sensitive business environment
  • Experience leading or mentoring GRC analysts or cross-functional working groups
  • Bachelor’s degree in cybersecurity, information systems, business, risk management, law, or a related field; equivalent relevant experience considered
  • Three years of experience in governance, risk, compliance, information security, audit, privacy, or third-party risk management
  • Demonstrated experience leading compliance programs, audits, risk assessments, or control implementation efforts
  • Working knowledge of CMMC, GDPR, NIST CSF, NIST SP 800-171, NIST SP 800-53, ISO 27001, SOC 2, CIS Controls, PCI DSS, HIPAA, or similar standards
  • Experience designing or operating a third-party risk-management program
  • Experience managing policies, control documentation, audit evidence, and remediation activities
  • Strong project-management skills
  • Exceptional written, verbal, and stakeholder-management skills
  • Ability to communicate risk and compliance requirements to technical and non-technical audiences
  • High degree of integrity, judgment, discretion, and attention to detail
Core Competencies

Demonstrates expertise in leading Governance, Risk, and Compliance (GRC) programs, including CMMC and GDPR compliance, while effectively managing third-party vendor risk and internal audits. Proficient in developing compliance policies, procedures, and executive reporting to ensure organizational adherence to regulatory standards.

Highest-signal resume keywords
  • CMMC Compliance
  • GDPR Compliance
  • Risk Assessment
  • GRC Program Management
  • CISA Certification
ATS Optimization Keywords
Hard Skills
  • Governance
  • Risk Management
  • Compliance
  • Audit Management
  • Policy Development
  • Control Implementation
  • Data Protection
  • Vendor Risk Management
  • Privacy Impact Assessment
  • Incident Response
Soft Skills
  • Project Management
  • Stakeholder Management
  • Communication Skills
  • Mentoring
  • Attention to Detail
Certifications & Qualifications
  • CISA
  • CRISC
  • CISSP
  • CISM
  • ISO 27001 Lead Implementer
  • CDPSE
  • CIPM
  • CIPP/US
  • CIPP/E
Industry Keywords
  • NIST SP 800-171
  • NIST CSF
  • NIST SP 800-53
  • SOC 2
  • CIS Controls
  • PCI DSS
  • HIPAA
  • Regulated Industry
  • Government Contracting
  • SaaS
Tools & Technologies
  • GRC Tools
  • Audit Management Tools
  • Vendor Risk Management Tools
  • Workflow Tools
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Manager, GRC
Senior Manager, GRC

Jobtailor • California (MO)

On-site
USD 130,000 - 165,000
Senior Technical Governance Program Manager
Senior Technical Governance Program Manager

Jobtailor • California (MO)

On-site
USD 120,000 - 190,000
GRC Intern
GRC Intern

Jobtailor • Center Square (PA)

On-site
USD 35,000 - 52,000
Senior Governance, Risk & Compliance (GRC) Analyst
Senior Governance, Risk & Compliance (GRC) Analyst

Cianbro • Pittsfield (ME)

On-site
Employee-owned
Equal opportunity employer
Business Control Manager – Technology Risk & Regulatory Lead
Business Control Manager – Technology Risk & Regulatory Lead

Jobtailor • Pennington (NJ)

On-site
USD 120,000 - 180,000
GRC Analyst
GRC Analyst

Golden Technology • North Carolina

Hybrid
USD 120,000 - 160,000
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

RELX • Raleigh (NC)

On-site
USD 118,000 - 220,000
Annual incentive bonus
Senior Manager – GRC Financial Services Technology
Senior Manager – GRC Financial Services Technology

Jobtailor • Illinois

On-site
USD 110,000 - 160,000
Cyber Governance Program Lead
Cyber Governance Program Lead

Jobtailor • Town of Florida (NY)

Hybrid
USD 140,000 - 190,000
GRC Specialist II
GRC Specialist II

SCIGON • Salt Lake City (UT)

On-site
USD 116,000 - 144,000