- Lead and mature the organization’s GRC program, including CMMC, GDPR, and other applicable requirements
- Translate requirements into controls, policies, procedures, compliance roadmaps, and evidence-collection processes
- Coordinate internal and external audits, assessments, certifications, customer questionnaires, remediation plans, and compliance reporting
- Build and manage a third-party vendor-risk program, including due diligence, risk assessments, security and privacy reviews, monitoring, and remediation tracking
- Own the lifecycle of security, privacy, and compliance policies, including review, approval, publication, employee acknowledgment, training, and exception management
- Develop executive dashboards and reports covering compliance posture, audit readiness, control effectiveness, vendor risk, and remediation progress
- Partner with Legal, Privacy, Procurement, IT, Information Security, and business stakeholders
- Support security awareness, business continuity, incident-response governance, data protection, and customer security reviews
- Lead or mentor GRC personnel and serve as primary contact for auditors, assessors, vendors, customers, and internal stakeholders
Requirements
- Professional certifications such as CISA, CRISC, CISSP, CISM, ISO 27001 Lead Implementer or Lead Auditor, CDPSE, CIPM, CIPP/US, CIPP/E, or similar
- Experience supporting CMMC assessments or implementing controls aligned with NIST SP 800-171
- Experience with privacy-impact assessments, data-protection impact assessments, or GDPR compliance programs
- Familiarity with GRC, audit-management, vendor-risk-management, and workflow tools
- Experience in a regulated industry, government contracting environment, SaaS organization, or other security-sensitive business environment
- Experience leading or mentoring GRC analysts or cross-functional working groups
- Bachelor’s degree in cybersecurity, information systems, business, risk management, law, or a related field; equivalent relevant experience considered
- Three years of experience in governance, risk, compliance, information security, audit, privacy, or third-party risk management
- Demonstrated experience leading compliance programs, audits, risk assessments, or control implementation efforts
- Working knowledge of CMMC, GDPR, NIST CSF, NIST SP 800-171, NIST SP 800-53, ISO 27001, SOC 2, CIS Controls, PCI DSS, HIPAA, or similar standards
- Experience designing or operating a third-party risk-management program
- Experience managing policies, control documentation, audit evidence, and remediation activities
- Strong project-management skills
- Exceptional written, verbal, and stakeholder-management skills
- Ability to communicate risk and compliance requirements to technical and non-technical audiences
- High degree of integrity, judgment, discretion, and attention to detail
Core Competencies
Demonstrates expertise in leading Governance, Risk, and Compliance (GRC) programs, including CMMC and GDPR compliance, while effectively managing third-party vendor risk and internal audits. Proficient in developing compliance policies, procedures, and executive reporting to ensure organizational adherence to regulatory standards.
Highest-signal resume keywords
- CMMC Compliance
- GDPR Compliance
- Risk Assessment
- GRC Program Management
- CISA Certification
ATS Optimization Keywords
Hard Skills
- Governance
- Risk Management
- Compliance
- Audit Management
- Policy Development
- Control Implementation
- Data Protection
- Vendor Risk Management
- Privacy Impact Assessment
- Incident Response
Soft Skills
- Project Management
- Stakeholder Management
- Communication Skills
- Mentoring
- Attention to Detail
Certifications & Qualifications
- CISA
- CRISC
- CISSP
- CISM
- ISO 27001 Lead Implementer
- CDPSE
- CIPM
- CIPP/US
- CIPP/E
Industry Keywords
- NIST SP 800-171
- NIST CSF
- NIST SP 800-53
- SOC 2
- CIS Controls
- PCI DSS
- HIPAA
- Regulated Industry
- Government Contracting
- SaaS
Tools & Technologies
- GRC Tools
- Audit Management Tools
- Vendor Risk Management Tools
- Workflow Tools