Remote Cybersecurity GRC Program Lead – Governance

I.T. Solutions, Inc.

Walnut Creek (CA)

On-site

USD 125,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

I.T. Solutions, Inc. is seeking a Cybersecurity GRC Program Lead to establish and operationalize a governance operating system across the enterprise.

You will drive framework selection, ownership, risk assessments, evidence management, and third-party intake with practical, measurable outcomes. The role focuses on turning policy into concrete practices, aligning engineering and business teams, and delivering actionable governance that scales.

Qualifications

  • 7+ years in cybersecurity GRC, security risk, audit readiness, compliance operations, or related functions.
  • Strong experience operationalizing NIST CSF and translating controls across frameworks such as ISO 27001, SOX, SOC 2, or similar frameworks.
  • Experience building or maturing security governance programs in complex enterprise environments with multiple technical stakeholders.
  • Experience with risk assessments, control design reviews, exception management, and remediation tracking.
  • Strong understanding of third-party risk, supplier security reviews, security questionnaires, and governance workflows that scale beyond one-off reviews.
  • Experience partnering with technical teams to influence architecture, engineering, and operations outcomes in a practical, technically credible way.
  • Ability to turn policy and framework language into concrete operating practices, ownership expectations, and measurable evidence.
  • Strong writing, stakeholder management, and executive communication skills.

Responsibilities

  • Lead selection, adoption, and operationalization of client's primary cybersecurity framework and related standards structure, with NIST CSF 2.0 as the likely management layer.
  • Build and maintain a control ownership model across Technology, Engineering, Platform, Network, EUC, Asset, Data, Integrations, and Security.
  • Translate existing policies into measurable operating practices, control expectations, evidence requirements, review cadences, and exception workflows.
  • Partner with security architecture, engineering, and operations teams to ensure that governance expectations are practical, technically grounded, and enforceable.
  • Drive enterprise risk and control assessments, including facilitating discussions on control design, effectiveness, and remediation priorities.
  • Build an evidence library structure while defining repeatable collection, review, reuse, and freshness cadences.
  • Improve security questionnaire workflows through standardized responses, evidence reuse, service-level expectations, and clearer ownership.
  • Coordinate third-party security intake and help define tiering, minimum security requirements, documentation expectations, and escalation paths.
  • Partner with Internal Audit and business stakeholders on readiness efforts, compliance reviews, and operational audit support.
  • Track policy exceptions, control gaps, remediation commitments, and overdue actions through closure, including clear owners and time bounds.
  • Provide security governance input on supplier security requirements, contractual obligations, and ongoing review expectations.
  • Produce reporting for leadership on framework maturity, control ownership, policy currency, evidence readiness, exception status, and risk trends.
  • Lead the evolution to and support of continuous compliance capabilities to improve control visibility, evidence freshness, and audit readiness
  • Manage and evolve the organization's trust center, including published security documentation, customer-facing assurance materials, and the processes that keep content current and supportable

Skills

GRC program leadership
Governance
Risk assessment
Stakeholder management
Executive communication

Tools

NIST CSF 2.0
ISO 27001
SOX
SOC 2

Job description

I.T. Solutions, Inc. is seeking a Cybersecurity GRC Program Lead to establish and operationalize a governance operating system across the enterprise.

You will drive framework selection, ownership, risk assessments, evidence management, and third-party intake with practical, measurable outcomes. The role focuses on turning policy into concrete practices, aligning engineering and business teams, and delivering actionable governance that scales.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Manager: Cybersecurity Governance & Risk Leader
GRC Manager: Cybersecurity Governance & Risk Leader

Synergy Business Consulting, Inc. • Fort Lauderdale (FL)

On-site
USD 110,000 - 160,000
Remote Senior GRC Consultant: Cybersecurity Governance
Remote Senior GRC Consultant: Cybersecurity Governance

Cyberr • United States

Remote
CAD 110,000 - 150,000
Enterprise Cybersecurity GRC Program Lead
Enterprise Cybersecurity GRC Program Lead

Saigepartners • San Jose (CA), Northern (KY)

Hybrid
USD 117,000 - 131,000
Global Cybersecurity GRC Program Lead
Global Cybersecurity GRC Program Lead

Koch Business Solutions, LP • Houston (TX)

On-site
USD 140,000 - 180,000
GRC Manager
GRC Manager

Synergy Business Consulting, Inc. • Fort Lauderdale (FL)

On-site
USD 110,000 - 160,000
Cyber GRC Specialist: Policy, Risk & Audit Lead
Cyber GRC Specialist: Policy, Risk & Audit Lead

Brown Advisory • Baltimore (MD)

On-site
USD 95,000 - 125,000
Medical
Dental
Vision
+11
Senior GRC Consultant — Remote, Strategic Risk & Compliance
Senior GRC Consultant — Remote, Strategic Risk & Compliance

Cyberr • United States

On-site
USD 90,000 - 130,000
Senior Cybersecurity GRC Director - Strategy & Compliance
Senior Cybersecurity GRC Director - Strategy & Compliance

Jobtailor • California (MO)

On-site
USD 170,000 - 210,000
IT Security GRC Analyst
IT Security GRC Analyst

The Phoenix Group • Charlotte (NC)

On-site
USD 85,000 - 120,000
Cyber GRC Specialist: Policy, Risk & Audit
Cyber GRC Specialist: Policy, Risk & Audit

Brown Advisory • Washington

On-site
USD 105,000 - 127,000
Medical
Dental
Vision
+1