GRC Lead

Acuren

Houston, Northern (TX, KY)

Hybrid

USD 120,000 - 180,000

Full time

7 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

TIC Solutions seeks an experienced, strategic GRC Lead to own the organization’s governance, risk, and compliance program. This role will mature controls, policies, audits, and third-party risk management while partnering with senior leadership across business units.

The ideal candidate combines deep knowledge of security and privacy frameworks with program management, stakeholder communication, and leadership skills to drive evidence collection, remediation, and audit readiness across the

Qualifications

  • Bachelor’s degree in a related field; equivalent experience considered.
  • Three years of governance, risk, compliance, information security, audit, or third-party risk management.
  • Certifications such as CISA, CRISC, CISSP, CISM, ISO 27001 Lead Implementer/Auditor, CDPSE, CIPM, CIPP/US, or similar.
  • Experience with CMMC, NIST SP 800-171, and privacy/GDPR programs.
  • Strong written, verbal, and stakeholder-management skills.
  • Ability to communicate risk to technical and non-technical audiences.
  • Experience in regulated industries, government contracting, or SaaS security environments.
  • Experience leading or mentoring GRC analysts or cross-functional teams.
  • Working knowledge of CMMC, GDPR, NIST CSF, NIST SP 800-53, ISO 27001, SOC 2, PCI DSS, HIPAA.

Responsibilities

  • Lead and mature the organization’s GRC program, including CMMC, GDPR, and other applicable requirements.
  • Translate requirements into controls, policies, procedures, compliance roadmaps, and evidence-collection processes.
  • Coordinate internal and external audits, assessments, certifications, customer questionnaires, remediation plans, and compliance reporting.
  • Build and manage a third-party vendor-risk program with due diligence, risk assessments, reviews, and ongoing remediation.
  • Own the lifecycle of security, privacy, and compliance policies, including review, approval, publication, training, and exception management.
  • Develop executive dashboards and reports covering compliance posture, audit readiness, control effectiveness, vendor risk, and remediation progress.
  • Partner with Legal, Privacy, Procurement, IT, Information Security, and business stakeholders to integrate GRC requirements.
  • Support related programs such as security awareness, business continuity, incident-response governance, data protection, and customer security reviews.
  • Lead or mentor GRC personnel and serve as the primary contact for auditors, assessors, vendors, customers, and internal stakeholders.

Skills

GRC leadership
Regulatory compliance
Risk management
Policy governance
Audits & assessments
Vendor risk management
Stakeholder communication
Project management
Security & privacy frameworks
Leadership

Education

Bachelor’s degree in cybersecurity, information systems, business, risk management, law, or related field

Job description

Position Summary

TIC Solutions are seeking an experienced, strategic, and hands-on GRC Lead to lead the organization’s governance, risk, and compliance program. This role will own and mature key compliance, risk-management, policy-governance, audit, and third-party vendor management processes, while partnering across business units and executive leadership.The GRC Lead will manage compliance initiatives including CMMC, GDPR, and other applicable regulatory, contractual, and customer assurance requirements. The ideal candidate combines strong knowledge of security and privacy frameworks with practical program-management, communication, and leadership skills.Position Details:



  • Monday-Friday, full time position

  • Hybrid (Defined as 4 days a week in office)

  • Office location is Houston, TX (Galleria)


Responsibilities


  • Lead and mature the organization’s GRC program, including CMMC, GDPR, and other applicable regulatory, contractual, and customer requirements.

  • Translate requirements into controls, policies, procedures, compliance roadmaps, and evidence-collection processes.

  • Coordinate internal and external audits, assessments, certifications, customer questionnaires, remediation plans, and compliance reporting.

  • Build and manage a third-party vendor-risk program, including vendor due diligence, risk assessments, security and privacy reviews, ongoing monitoring, and remediation tracking.

  • Own the lifecycle of security, privacy, and compliance policies, including review, approval, publication, employee acknowledgment, training, and exception management.

  • Develop executive dashboards and reports covering compliance posture, audit readiness, control effectiveness, vendor risk, and remediation progress.

  • Partner with Legal, Privacy, Procurement, IT, Information Security, and business stakeholders to integrate GRC requirements into organizational processes.

  • Support related programs such as security awareness, business continuity, incident-response governance, data protection, and customer security reviews.

  • Lead or mentor GRC personnel and serve as the primary contact for auditors, assessors, vendors, customers, and internal stakeholders.


Requirements


  • Professional certifications such as CISA, CRISC, CISSP, CISM, ISO 27001 Lead Implementer or Lead Auditor, CDPSE, CIPM, CIPP/US, CIPP/E, or similar.

  • Experience supporting CMMC assessments or implementing controls aligned with NIST SP 800-171.

  • Experience with privacy-impact assessments, data-protection impact assessments, or GDPR compliance programs.

  • Familiarity with GRC, audit-management, vendor-risk-management, and workflow tools.

  • Experience in a regulated industry, government contracting environment, SaaS organization, or other security-sensitive business environment.

  • Experience leading or mentoring GRC analysts or cross-functional working groups.

  • Bachelor’s degree in cybersecurity, information systems, business, risk management, law, or a related field; equivalent relevant experience considered.

  • Three years of experience in governance, risk, compliance, information security, audit, privacy, or third-party risk management.

  • Demonstrated experience leading compliance programs, audits, risk assessments, or control implementation efforts.

  • Working knowledge of CMMC, GDPR, and common security or privacy frameworks such as NIST CSF, NIST SP 800-171, NIST SP 800-53, ISO 27001, SOC 2, CIS Controls, PCI DSS, HIPAA, or similar standards as applicable.

  • Experience designing or operating a third-party risk-management program.

  • Experience managing policies, control documentation, audit evidence, and remediation activities.

  • Strong project-management skills, including the ability to prioritize competing compliance initiatives and drive cross-functional accountability.

  • Exceptional written, verbal, and stakeholder-management skills.

  • Ability to communicate risk and compliance requirements effectively to both technical and non-technical audiences.

  • High degree of integrity, judgment, discretion, and attention to detail.


Company Overview

At TIC Solutions, we do work that matters. As a leading provider of critical asset integrity and engineering solutions, we help keep essential industries operating safely, reliably, and efficiently across North America and beyond. From infrastructure and energy to industrials and renewables, our work supports the communities where we live and work every day.


With more than 11,000 employees across 200+ locations, TIC Solutions combines global scale with local expertise, creating opportunities for employees to build meaningful careers while making a real impact. Our teams are driven by safety, innovation, collaboration, and technical excellence, and we are committed to investing in our people through growth opportunities, hands-on experience, and a strong culture of support and accountability.


Whether you are in the field, in operations, or supporting the business behind the scenes, you will be part of a team focused on solving complex challenges and delivering high-quality solutions for our customers.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Lead
GRC Lead

Acuren Inspection, Inc. • Houston (TX)

Hybrid
USD 120,000 - 170,000
GRC Lead
GRC Lead

Acuren Inspection, Inc. • Houston (TX)

Hybrid
USD 120,000 - 180,000
Hybrid GRC Lead for Regulated Compliance & Audit
Hybrid GRC Lead for Regulated Compliance & Audit

Acuren Inspection, Inc. • Houston (TX)

Hybrid
USD 120,000 - 170,000
Head of Risk and Compliance
Head of Risk and Compliance

Applied Intuition • United States

On-site
USD 180,000 - 250,000
Health Insurance
Fitness Stipend
401(k) Match
+3
Strategic GRC Lead: Build Compliance & Risk Programs
Strategic GRC Lead: Build Compliance & Risk Programs

Acuren • Houston (TX), Northern (KY)

Hybrid
USD 120,000 - 180,000
Senior Governance, Risk & Compliance (GRC) Analyst
Senior Governance, Risk & Compliance (GRC) Analyst

Cianbro • Pittsfield (ME)

On-site
Employee-owned
Equal opportunity employer
Senior Governance, Risk & Compliance (GRC) Analyst
Senior Governance, Risk & Compliance (GRC) Analyst

Cianbro • North Stonington (CT)

On-site
USD 90,000 - 110,000
Employee-owned company
IT GRC Specialist
IT GRC Specialist

Hexagon Autonomous Solutions • Tucson (AZ)

Hybrid
USD 110,000 - 170,000
Communications Manager
Communications Manager

Acuren Inspection, Inc. • Houston (TX)

On-site
USD 70,000 - 90,000
Competitive Salary
Medical and dental insurance
401K Plan
+2
Practice Lead, GRC Advisory for Shellproof Security
Practice Lead, GRC Advisory for Shellproof Security

The ProActive Technology Group • New York (NY)

On-site
USD 100,000 - 150,000
Competitive salary
Health, vision, and dental benefits
Performance-based incentives
+3