Manager, Governance, Risk & Compliance

Vocate Education Solutions

Tampa (FL)

Remote

USD 150,000 - 159,000

Full time

20 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Medical, Dental, Vision benefits
401k with company match
Paid time off & holidays

Job summary

Vocate Education Solutions is seeking a Manager, Governance, Risk & Compliance (GRC) to lead our institution's governance, risk management, and compliance programs. You will shape policies, controls, and risk mitigation across technology, data protection, and regulatory obligations.

You will partner with Legal, Compliance, IT, and business units to drive risk-informed decisions, monitor security performance, and advance our GRC maturity, while guiding a team.

Qualifications

  • Bachelor's degree in cybersecurity, information security, risk management, or related field.
  • Progressive experience in information security governance, cybersecurity risk management, regulatory compliance, or related discipline.
  • Experience leading cross-functional information security and GRC programs and identifying security controls.

Responsibilities

  • Lead governance, risk, and compliance programs aligning with regulatory requirements and industry practices.
  • Oversee cybersecurity and technology risk management activities and communicate material risks to leadership.
  • Manage regulatory compliance requirements across FERPA, GLBA, FTC Safeguards Rule, HIPAA where applicable, and privacy laws.
  • Partner with IT, engineering, and security teams to establish governance and controls across technology solutions.
  • Lead vulnerability management programs including scanning, prioritization, remediation, and reporting.
  • Coordinate third-party information security risk assessments with procurement, legal, compliance, and stakeholders.
  • Develop and maintain an AI governance program to promote ethical, secure use of AI technologies.
  • Oversee policy development, control assurance activities, and compliance audits and remediation.

Skills

Governance
Risk management
Regulatory compliance
Information security
Vendor risk assessments
Leadership
English communication

Education

Bachelor's degree in cybersecurity or related field

Tools

ServiceNow IRM/GRC
OneTrust
LogicGate
Tenable
Qualys
Rapid7

Job description

Vocate is a non-profit higher education and workforce solutions provider dedicated to closing the nation's talent gaps in critical industries such as healthcare. Through its entities including Ultimate Medical Academy, American Institute, Nasium Training and Global Education Group, Vocate serves more than 20,000 adult learners nationwide, primarily in under-resourced populations. Backed by more than 130 years of combined experience in higher learning across its institutions, Vocate delivers accessible, career-aligned programs enhanced by employer partnerships and comprehensive student support services.

As a full-time team member, you will have access to the following benefits:

  • Medical (including prescription), Dental, Vision (UMA subsidized)
  • FSA/HSA (Depending on Medical Plan chosen)
  • Basic Life Insurance (UMA paid) minimum $50,000 - maximum $250,000 (1x annual salary)
  • Additional Voluntary Life Insurance (Team Member paid)
  • Employee Assistance Program – EAP (UMA paid)
  • Long Term Disability (UMA paid)
  • Short Term Disability (Team Member paid)
  • Supplemental Insurance such as Critical Illness, Accident, and Hospital (Team Member Paid)
  • Paid Time Off – 15 days accrued in year 1, 9 holidays, and 1 day of Volunteering Time Off
  • 401k (eligible upon completion of 90 days of employment and must be at least 18 years of age)
  • Pet Insurance
  • Identity Theft Protection
Purpose of the Position:

The Manager, Governance, Risk & Compliance (GRC) is responsible for leading and advancing the institution's governance, risk management, compliance, and information security programs to support the achievement of organizational objectives and regulatory requirements. This role develops, implements, and monitors frameworks, policies, controls, and risk mitigation strategies that promote operational effectiveness, safeguard institutional assets, and ensure compliance with applicable laws, regulations, accreditation standards, and internal policies. The Manager partners with leaders across the institution to foster a culture of accountability, risk awareness, and continuous improvement in support of the institution's mission and long-term success.

The Manager also provides hands-on leadership for key information security programs, including vulnerability management, third-party risk management, security performance reporting, policy governance, and the continuous improvement of security controls and operational practices.

What You'll Do:
  • Lead Governance, Risk, and Compliance Programs: Develop, implement, and continuously enhance the institution's governance, risk management, and compliance framework to ensure alignment with organizational objectives, regulatory requirements, accreditation standards, and recognized industry practices.
  • Conduct Cybersecurity and Technology Risk Management Activities: Lead the identification, assessment, monitoring, and mitigation of cybersecurity and technology risks. Support the institution's enterprise risk-management process by communicating material technology risks, control deficiencies, and actionable mitigation strategies to leadership.
  • Oversee Regulatory and Compliance Requirements: Serve as a trusted business partner to departments across the institution and collaborate with Legal and Compliance to address applicable federal, state, higher education, privacy, and information security requirements, including FERPA, GLBA, the FTC Safeguards Rule, HIPAA where applicable, and state privacy and breach-notification requirements.
  • Manage Security Governance and Architecture Oversight: Partner with Information Technology, Engineering, Enterprise Architecture, and security teams to establish and maintain security governance processes, evaluate technical and administrative controls, and ensure technology solutions align with institutional security, privacy, risk, and compliance requirements.
  • Manage the Vulnerability Management Program: Lead and continuously improve the institution's vulnerability management program, including vulnerability scanning, risk-based prioritization, patching and security-update coordination, remediation tracking, exception management, validation, and executive reporting. Partner with infrastructure, cloud, engineering, application, and business system owners to establish remediation priorities, service-level expectations, and accountability for addressing identified vulnerabilities based on severity, exploitability, asset criticality, known exploitation, and business impact.
  • Lead Third-Party Information Security Risk Management: Conduct and coordinate information security and privacy risk assessments for vendors and third parties in partnership with Procurement, Legal, Compliance, Information Technology, and business stakeholders. Review relevant vendor security documentation, including questionnaires, SOC reports, penetration-testing summaries, certifications, data-processing practices, incident-notification commitments, and remediation plans. Track identified third-party risks, corrective actions, exceptions, and ongoing monitoring activities throughout the vendor lifecycle.
  • Lead AI Governance Initiatives: Develop and maintain an institutional AI governance program, including policies, standards, risk assessments, intake and review processes, and oversight practices that promote the ethical, responsible, secure, and compliant use of artificial intelligence technologies.
  • Coordinate Compliance and Control-Assurance Activities: Manage periodic and annual compliance assessments, audits, policy reviews, control testing, evidence collection, remediation activities, and reporting requirements to support ongoing adherence to regulatory obligations, accreditation expectations, contractual requirements, and organizational policies.
  • Monitor and Report on Risk and Compliance Performance: Establish and maintain key performance indicators, key risk indicators, dashboards, and reporting mechanisms that provide leadership with visibility into security operations, vulnerabilities, remediation performance, third-party risk, compliance obligations, audit findings, policy exceptions, and overall Information Security program effectiveness. Translate technical security and compliance information into business-relevant insights that support informed decision-making, risk prioritization, operational improvement, and resource planning.
  • Manage Policy Development and Governance Processes: Lead the creation, review, approval, communication, and maintenance of institutional policies, standards, and procedures related to governance, risk management, information security, privacy, artificial intelligence, data protection, and regulatory compliance. Maintain a structured policy lifecycle that includes assigned ownership, scheduled reviews, documented approvals, version control, exception management, and communication of material changes.
  • Monitor the Regulatory and Threat Landscape: Maintain awareness of emerging cybersecurity threats, vulnerabilities, technologies, regulatory developments, and industry practices that may affect the institution. Maintain a documented register of applicable privacy, data-protection, breach-notification, and information security requirements in coordination with Legal and Compliance. Provide practical recommendations regarding required controls, operational changes, policies, processes, and technology investments.
  • Drive Continuous Improvement: Identify opportunities to improve the effectiveness, scalability, automation, and maturity of information security and GRC processes. Evaluate recurring issues, audit findings, vulnerabilities, incidents, control deficiencies, and operational trends to identify root causes and recommend sustainable corrective actions. Promote the use of automation, workflow management, dashboards, and integrated platforms to improve visibility, accountability, consistency, and operational efficiency.
  • Develop and Deliver Security Awareness Training: Design, implement, and evaluate institution-wide security awareness and compliance training programs that educate team members on cybersecurity risks, data-protection responsibilities, privacy requirements, social-engineering threats, and emerging risks.
  • Lead with Care: Lead, coach, and develop team members, fostering a culture of wellness, recognition, engagement, accountability, and continuous improvement. Meet regularly with direct reports in one-on-one and group settings to provide feedback and cultivate and maintain a positive work culture. Provide hands-on leadership by working directly with team members and cross-functional partners to deliver projects, resolve issues, complete assessments, implement controls, and advance critical information security and GRC initiatives.
  • Perform other duties as assigned.
Career Level Expectations:
  • Combines people leadership, technical judgment, and hands-on execution to advance information security and GRC priorities in partnership with technology and business stakeholders.
  • Typically manages a team or small unit.
  • Owns short to mid-term (1-3 years) execution of functional strategy and the operational direction of a team.
  • Handles often difficult and complex problems and that require extensive investigation and analysis.
  • Requires ability to influence others to accept practices and approaches, and ability to communicate with executive leadership.
  • Desire for growth and professional development.
Required Skills/Experience:
  • Bachelor's degree in cybersecurity, information security, information systems, computer science, risk management, business administration, or a related field, or an equivalent combination of education and relevant professional experience.
  • Progressive experience in information security governance, cybersecurity risk management, regulatory compliance, security assurance, or a related discipline.
  • Experience leading and developing team members or directing complex, cross-functional information security and GRC programs and initiatives.
  • Experience managing or supporting a vulnerability management program, including vulnerability assessments, patch and remediation coordination, risk-based prioritization, exception management, validation, and performance reporting.
  • Experience conducting third-party information security and privacy risk assessments and evaluating vendor controls, audit reports, certifications, contractual requirements, and remediation plans.
  • Working knowledge of recognized cybersecurity frameworks and standards, including the NIST Cybersecurity Framework, applicable NIST Special Publications, CIS Critical Security Controls, and other relevant risk and control frameworks.
  • Technical understanding of cloud environments, identity and access management, endpoint security, network security, vulnerability management, data protection, logging and monitoring, application security, and software-as-a-service platforms.
  • Experience developing meaningful information security and GRC metrics, key performance indicators, key risk indicators, dashboards, and executive-level reporting.
  • Experience creating, reviewing, maintaining, and implementing information security, privacy, risk-management, and technology policies, standards, and procedures.
  • Experience monitoring cybersecurity, privacy, breach-notification, and data-protection requirements and partnering with Legal and Compliance to translate applicable requirements into operational and technical controls.
  • Experience using one or more GRC, integrated risk-management, third-party risk, privacy, vulnerability-management, audit, or security platforms, such as ServiceNow IRM/GRC, OneTrust, LogicGate, Tenable, Qualys, Rapid7, or comparable technologies.
  • Experience integrating cybersecurity and technology risks into broader enterprise risk-management processes, including risk assessments, control evaluations, risk registers, remediation plans, and executive reporting.
  • Knowledge of higher education regulatory requirements, including FERPA, GLBA, the FTC Safeguards Rule, and related privacy, security, and compliance requirements applicable to distance education institutions.
  • Ability to analyze complex technical and regulatory issues, identify practical solutions, and clearly communicate risks and recommendations to technical teams, business leaders, and executive stakeholders.
  • Experience serving as a strategic business partner and influencing stakeholders to implement appropriate security, risk-management, and compliance practices.
  • Demonstrated continuous-improvement mindset, with experience enhancing processes, controls, workflows, reporting, automation, and program maturity.
  • Ability and willingness to work hands-on with team members and cross-functional stakeholders to deliver assessments, projects, remediation activities, and information security initiatives.
  • Ability to professionally communicate fluently in verbal and written English.
  • Ability to support a diverse and inclusive work environment.
  • Computer literacy/basic computer skills to effectively navigate and utilize the technology required for the role.
Preferred Requirements:
  • Advanced degree or equivalent professional experience and advanced proficiency in one or more of the required skills or disciplines.
  • One or more current professional certifications, such as Certified Information Systems Security Professional, Certified Information Security Manager, Certified in Risk and Information Systems Control, Certified in Governance, Risk and Compliance, Certified Information Systems Auditor, or a comparable information security or risk-management certification.
  • Experience supporting information security and GRC programs within higher education, distance education, financial services, healthcare, nonprofit, multi-entity, shared-services, or another highly regulated environment.
  • Experience with the Gramm-Leach-Bliley Act Safeguards Rule, FERPA, HIPAA, state privacy requirements, breach-notification laws, and related information security obligations.
  • Experience supporting security governance, risk, compliance, or technology integration activities associated with acquisitions, organizational restructuring, new business entities, or external partnerships.
  • Proficient in MS Office (Word, Excel, PowerPoint) and other business tools such as Microsoft Teams.
Compliance:
  • Demonstrate knowledge of, and carefully follows all applicable state laws and rules, federal and state compliance requirements and regulations including those prescribed by the U.S. Department of Education, accrediting agencies, state regulations and internal policies and procedures.
  • Effectively communicate compliance requirements to other staff as appropriate and quickly escalates any compliance concerns to the Compliance department.
Work Environment/Physical Demands:
  • This is a full-time remote position, with occasional onsite travel required.
  • Home office set up, quiet place to work, ability to be on camera, and ability to hard wire into high-speed internet connection.
  • May require setup of computer equipment; accommodation consideration available upon request.
  • Flexibility to work evenings and weekends, as needed.
Anticipated Starting Salary Is Based On Experience And Qualifications:

Compensation Range

$150,000-$159,390 USD

OUR CORE VALUES:

COLLABORATE

We achieve more together. By approaching challenges with insight and expertise, we create solutions that drive meaningful impact across our growing organization and for those we serve.

ADVOCATE

We boldly champion those we serve. With a deep understanding of our partners, and team members, we amplify and advance our shared goals and objectives to drive success.

RESPECT

We honor ourselves and each other. By fostering confidence in our own contributions, while creating space for all voices, we build stronger partnerships, better ideas, and a culture where everyone can belong and thrive.

EMPOWER

We unlock potential. We empower others by fostering continuous learning, activating strengths, and creating connections that enable opportunities — laying the foundation for transformative change.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Director of Instructional Design
Director of Instructional Design

Vocate Education Solutions • United States

Remote
USD 100,000 - 120,000
Medical, Dental, Vision
FSA/HSA
Basic Life Insurance
+9
GRC Manager
GRC Manager

G2 Crowd, Inc. • Chicago (IL)

On-site
USD 120,000 - 131,000
Flexible work
Parental leave
Unlimited PTO
Academic Compliance Manager
Academic Compliance Manager

Alvernia University • Reading

On-site
USD 65,000 - 90,000
Tuition remission
GRC Manager
GRC Manager

Valence • United States

On-site
USD 130,000 - 190,000
WFH stipend
Phone stipend
Workspace support
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta-Denta • St. Louis (MO)

On-site
USD 75,000 - 110,000
Academic Compliance Manager
Academic Compliance Manager

Alvernia University • Northern (KY)

Hybrid
USD 65,000 - 90,000
Tuition remission
403(b) plan
Flexible work options
+1
Director of Governance, Risk & Compliance
Director of Governance, Risk & Compliance

Jobgether SRL • United States

Remote
USD 140,000 - 210,000
401(k) match
Health insurance (employee)
Paid time off 3 weeks
+3
Manager of Enterprise Safety & Security
Manager of Enterprise Safety & Security

Covista • Illinois

Hybrid
USD 80,000 - 100,000
Health Insurance
Retirement 401k
Flexible Time Off
+2
Sr Programmer Analyst
Sr Programmer Analyst

UMass Global • United States

Remote
USD 97,000 - 130,000
Remote options
Tuition discounts
Generous time off
+1
Manager of Enterprise Safety & Security
Manager of Enterprise Safety & Security

Chamberlain College of Nursing, LLC • Chicago (IL)

On-site
USD 71,000 - 128,000
Health insurance
401k match
Paid holidays
+1