Remote GRC Leader: Governance, Risk & Compliance

Sound Physicians

Northern (KY)

Hybrid

USD 130,000 - 160,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Medical, dental & vision insurance
FSA (healthcare & dependent care)
401(k) with company match
PTO 15 days/year
10 company-paid holidays

Job summary

Sound Physicians is seeking a Senior Manager of Governance, Risk, and Compliance to lead the enterprise information security GRC program and report to the CISO. This role translates cybersecurity strategy into measurable processes, risk visibility, and a defensible compliance posture, owning day-to-day security risk management and governance.

You will mentor GRC staff, collaborate with Security, IT, Legal, Privacy, and business teams, and help advance the Strategic Information Security Program

Qualifications

  • Bachelor’s degree in Information Security, Cybersecurity, Information Systems, Computer Science, Business Administration, or related field.
  • 7+ years of experience in information security GRC or risk management.
  • Preferred: CISSP, CISM, CRISC, CISA, or similar certifications; experience in a CISO led security organization or regulated environment.

Responsibilities

  • GRC Program Execution: Operate and mature the enterprise GRC program aligned to the CISO’s strategy and risk appetite.
  • Security Risk Management: Own the security risk lifecycle, including assessments, tracking, remediation, and escalation of material risks to the CISO.
  • Governance & Policy: Maintain the security policy framework and translate standards (e.g., NIST CSF, ISO 27001, SOC 2) into actionable control requirements.
  • Compliance & Audit: Manage security related compliance activities and audits; maintain evidence and track remediation to closure.
  • Third Party Risk: Operate the vendor security risk management program and escalation high risk vendors and systemic issues.
  • Metrics & Reporting: Produce concise risk and compliance metrics and dashboards for the CISO and senior leadership.
  • Enablement & Leadership: Mentor GRC staff and act as a trusted advisor to Security, IT, Legal, Privacy, and business teams.
  • Security Program Direction: Partner with the CISO and Sr. Manager of Security Operations to update the Strategic Information Security Program.

Skills

HIPAA Security rule
NIST CSF
ISO 27001
SOC 2
Security risk practices
Risk assessments
Audits and control testing
Communicate risk to leaders
Mentor GRC team
Technology risk awareness

Education

Bachelor’s degree in Information Security, Cybersecurity, Information Systems, Computer Science, Business Administration, or related field
7+ years in information security GRC or risk management
CISSP, CISM, CRISC, CISA or similar certifications (preferred)

Job description

Sound Physicians is seeking a Senior Manager of Governance, Risk, and Compliance to lead the enterprise information security GRC program and report to the CISO. This role translates cybersecurity strategy into measurable processes, risk visibility, and a defensible compliance posture, owning day-to-day security risk management and governance.

You will mentor GRC staff, collaborate with Security, IT, Legal, Privacy, and business teams, and help advance the Strategic Information Security Program

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior GRC Manager — Remote, Risk & Compliance Strategy
Senior GRC Manager — Remote, Risk & Compliance Strategy

Sound Physicians • United States

On-site
USD 130,000 - 160,000
Senior Manager, Governance Risk & Compliance
Senior Manager, Governance Risk & Compliance

Sound Physicians • Northern (KY)

Hybrid
USD 130,000 - 160,000
Medical, dental & vision insurance
FSA (healthcare & dependent care)
401(k) with company match
+2
InfoSec GRC Leader: Governance, Risk & Compliance
InfoSec GRC Leader: Governance, Risk & Compliance

Servier • Boston (MA)

On-site
USD 180,000 - 240,000
Senior GRC Leader: Governance, Risk & Compliance Strategy
Senior GRC Leader: Governance, Risk & Compliance Strategy

Brobston Group LLC • Seattle (WA)

On-site
USD 180,000 - 260,000
Director, GRC & Security Strategy (Remote)
Director, GRC & Security Strategy (Remote)

Clover Health • United States

Remote
USD 212,000 - 230,000
401(k) matching
Comprehensive medical coverage
Mental health resources
+2
Senior GRC Manager: Risk, Audit & Compliance Lead | Flexible
Senior GRC Manager: Risk, Audit & Compliance Lead | Flexible

Harris Computer • Indiana (PA)

On-site
USD 130,000 - 150,000
Full benefits package
Vacation and personal days
Employee stock ownership
+2
Senior GRC Manager — Risk & Compliance Lead
Senior GRC Manager — Risk & Compliance Lead

Harris Computer • Utah

On-site
USD 130,000 - 150,000
Full benefits package
Vacation + personal days
Stock ownership program
+1
Sr. Director, Governance, Risk, and Compliance (GRC)
Sr. Director, Governance, Risk, and Compliance (GRC)

Brobston Group LLC • Seattle (WA)

On-site
USD 180,000 - 260,000
Senior InfoSec GRC Manager | Risk, Compliance & Governance
Senior InfoSec GRC Manager | Risk, Compliance & Governance

Sutton Bank • Columbus (OH)

On-site
USD 110,000 - 170,000
Senior GRC Manager: Risk, Policy & Audit Leadership
Senior GRC Manager: Risk, Policy & Audit Leadership

Harris Computer • Washington

On-site
USD 130,000 - 150,000
We empower our employees to make a dif
We have an award-winning culture
We offer opportunity to learn
+2