Senior GRC Officer

Apex Systems

Lincoln (NE)

Hybrid

USD 100,000 - 140,000

Full time

10 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, dental, vision insurance
ESPP & 401K with company match
Health Savings Account (HSA)
Employee Assistance Program (EAP)

Job summary

Everforth Apex Systems is seeking a Senior Governance, Risk & Compliance (GRC) Officer to lead critical compliance initiatives in a hybrid Lincoln, NE environment. This hands‑on role owns workstreams from planning through remediation and monitoring, partnering with auditors, security teams, and stakeholders.

The ideal candidate will drive risk management programs, maintain compliance documentation, and coordinate audits across frameworks such as FedRAMP, CMMC Level 2, SOC 2 Type 2, ISO 27001,

Qualifications

  • 5+ years of experience in Governance, Risk & Compliance (GRC), Information Security, Risk Management, or related fields.
  • Hands-on FedRAMP compliance experience including SSPs, POA&M management, and control implementation.
  • Strong knowledge of NIST SP 800-53 security controls.
  • Experience with risk assessments, internal audits, and gap analyses.
  • Ability to manage multiple initiatives with minimal supervision.
  • Excellent written and verbal communication for technical and non-technical audiences.
  • U.S. Citizenship required.

Responsibilities

  • Independently manage governance and compliance workstreams across frameworks (FedRAMP, CMMC, SOC 2, ISO 27001, TX‑RAMP, CJIS).
  • Develop and maintain SSPs, POA&Ms, policies, procedures, control narratives, and readiness artifacts.
  • Coordinate with auditors, assessors, consultants, and control owners during audits.
  • Implement and validate NIST SP 800-53 and CMMC requirements with cross‑functional teams.
  • Develop evidence repositories and continuous monitoring programs.
  • Oversee risk management processes, vendor risk assessments, and policy governance.
  • Support vulnerability management: remediation tracking and escalation.
  • Plan external audits, assessments, and certifications.
  • Respond to customer security questionnaires, RFIs, RFPs, and regulatory inquiries.
  • Monitor compliance status and remediation progress, report to leadership.
  • Provide risk-based security guidance for new business initiatives.

Skills

GRC leadership
Audit coordination
Policy governance
Documentation
Stakeholder communication
Risk management

Education

Bachelor's degree in a related field

Tools

NIST SP 800-53 controls
GRC platforms
Vulnerability management tooling

Job description

Job Description.

Job#: 3046586

Job Description.

Position: Senior Governance, Risk & Compliance (GRC) Officer

Location: Lincoln, NE (Hybrid)

Type: Permanent

Salary Range: $100,000 - $140,000

Travel: Yes

Citizenship Requirement: U.S. Citizenship Required

Position Overview

Apex Systems is seeking a Senior Governance, Risk & Compliance (GRC) Officer to join a growing Security & Compliance organization. This individual will independently manage critical governance, risk, and compliance initiatives while partnering closely with technical teams, auditors, and business stakeholders. The ideal candidate will possess deep experience supporting regulatory and compliance frameworks, maintaining compliance documentation, coordinating audits, and driving risk management programs in cloud-based or regulated environments.

This is a highly hands‑on position requiring ownership of compliance workstreams from planning through assessment, remediation, and continuous monitoring.

Key Responsibilities
  • Independently manage governance and compliance workstreams across frameworks including FedRAMP, CMMC Level 2, SOC 2 Type 2, ISO 27001, TX‑RAMP Level 2, and CJIS.
  • Lead development, maintenance, and quality review of compliance documentation including System Security Plans (SSPs), Plans of Action & Milestones (POA&Ms), policies, procedures, control narratives, and readiness artifacts.
  • Serve as a primary point of contact for auditors, assessors, consultants, and internal control owners throughout audit and assessment activities.
  • Coordinate implementation and validation of NIST SP 800‑53 and CMMC security requirements across engineering, cloud, IT, and product teams.
  • Develop and maintain evidence repositories and continuous monitoring programs.
  • Manage risk management processes, vendor risk assessments, policy governance activities, access reviews, and exception management.
  • Support vulnerability management efforts through prioritization, remediation tracking, escalation, and validation activities.
  • Plan and support external audits, assessments, certifications, and compliance initiatives.
  • Respond to customer security questionnaires, RFIs, RFPs, and regulatory inquiries.
  • Conduct internal compliance assessments and gap analyses, recommending and validating corrective actions.
  • Monitor and communicate compliance status, remediation progress, risks, and blockers to leadership and stakeholders.
  • Provide risk‑based security and compliance guidance for new business, operational, and technology initiatives.
Required Qualifications
  • 5+ years of experience in Governance, Risk & Compliance (GRC), Information Security, Risk Management, or related fields.
  • Hands‑on experience supporting or managing FedRAMP compliance workstreams, including:
    • SSP development
    • POA&M management
    • Control implementation
    • Evidence collection
    • Assessment preparation
    • Remediation tracking
  • Strong knowledge of NIST SP 800‑53 security controls.
  • Experience conducting risk assessments, internal audits, and compliance gap analyses.
  • Proven ability to independently manage multiple compliance or certification initiatives simultaneously.
  • Experience working with auditors, assessors, consultants, and cross‑functional stakeholders.
  • Strong documentation skills with experience developing policies, procedures, compliance artifacts, and evidence repositories.
  • Excellent written and verbal communication skills with the ability to communicate effectively with both technical and non‑technical audiences.
  • Demonstrated ability to prioritize competing initiatives and drive projects to completion with minimal supervision.
  • Experience coordinating vulnerability remediation activities and tracking corrective actions.
  • U.S. Citizenship required.
Preferred Qualifications
  • Experience supporting CMMC Level 2, SOC 2 Type 2, ISO 2701, TX‑RAMP, and/or CJIS compliance frameworks.
  • Prior experience in security operations, vulnerability management, or cloud security.
  • Familiarity with AWS and/or Azure security controls.
  • Experience utilizing GRC platforms and compliance automation tools.
  • Experience responding to customer security questionnaires, RFIs, and RFPs.
  • Professional certifications such as:
    • CISSP
    • CISM
    • CISA
    • CRISC
    • CCSP
    • PMP
    • CAP
    • CMMC‑related certifications
Why Apply?

This opportunity offers the ability to make a significant impact within a growing compliance and security organization while owning key regulatory and risk management initiatives. The role provides exposure to multiple compliance frameworks and the opportunity to work closely with technical, operational, and executive stakeholders in a highly collaborative environment.

Benefits Overview
  • Everforth Apex offers a range of supplemental benefits, including medical, dental, vision, life, disability, and other insurance plans that offer an optional layer of financial protection.
  • We offer an ESPP (employee stock purchase program) and a 401K program which allows you to contribute typically within 30 days of starting, with a company match after 12 months of tenure.
  • Everforth Apex also offers a HSA (Health Savings Account on the HDHP plan).
  • SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions, a corporate discount savings program and other discounts.
  • In terms of professional development, Everforth Apex hosts an on‑demand training program, provides access to certification prep and a library of technical and leadership courses/books/seminars once you have 6+ months of tenure.
  • Certification discounts and other perks to associations that include CompTIA and IIBA.
  • Everforth Apex has a dedicated customer service team for our Consultants that can address questions around benefits and other resources, as well as a certified Career Coach.
  • You can access a full list of our benefits, programs, support teams and resources within our ‘Welcome Packet’ as well, which an Everforth Apex team member can provide.

Everforth Apex is a world‑class IT services company that serves thousands of clients across the globe. When you join Everforth Apex, you become part of a team that values innovation, collaboration, and continuous learning. We offer quality career resources, training, certifications, development opportunities, and a comprehensive benefits package. Our commitment to excellence is reflected in many awards, including ClearlyRateds Best of Staffing® in Talent Satisfaction in the United States and Great Place to Work® in the United Kingdom and Mexico.

Everforth Apex uses a virtual recruiter as part of the application process. Click here for more details. By applying for this job, you agree to receive calls, AI‑generated calls, text messages, or emails from Everforth Apex and its affiliates, and contracted partners. Frequency varies for text messages. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You can reply STOP to cancel and HELP for help. You can access our privacy policy at https://www.apexsystems.com/privacy-policy

Everforth Apex Systems is an equal opportunity employer. We do not discriminate or allow discrimination on the basis of race, color, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), age, sexual orientation, gender identity, national origin, ancestry, citizenship, genetic information, registered domestic partner status, marital status, disability, status as a crime victim, protected veteran status, political affiliation, union membership, or any other characteristic protected by law. Everforth Apex will consider qualified applicants with criminal histories in a manner consistent with the requirements of applicable law.

If you require an accommodation under the Americans with Disabilities Act to participate in an interview with a virtual recruiter or to use our website for a search or application, please contact our Benefits Department at [email protected] or 804-523-8228. Please note that this contact information is strictly to be used for medical ADA accommodations and that no other inquiries will be answered.

UnitedHealthcare creates and publishes the Transparency in Coverage Machine‑Readable Files on behalf of Everforth Apex Systems.

© 2026 Everforth, Inc. All rights reserved.

Everforth Apex Systems is part of the Commercial Segment of Everforth, Inc.

NYSE: EFOR

4400 Cox Road

Suite 200

Glen Allen, Virginia 23060

Everforth Apex Systems is an equal opportunity employer. We do not discriminate or allow discrimination on the basis of race, color, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), age, sexual orientation, gender identity, national origin, ancestry, citizenship, genetic information, registered domestic partner status, marital status, disability, status as a crime victim, protected veteran status, political affiliation, union membership, or any other characteristic protected by law. Everforth Apex will consider qualified applicants with criminal histories in a manner consistent with the requirements of applicable law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DevSecOps Assessor
DevSecOps Assessor

Apex Systems • Richmond (VA)

On-site
USD 110,000 - 160,000
Medical insurance
401K with company match
Health Savings Account (HSA)
+1
Senior Manager of Cybersecurity
Senior Manager of Cybersecurity

Apex Systems • Town of Florida (NY)

Hybrid
USD 150,000 - 190,000
Comprehensive benefits
ESPP (employee stock purchase)
401K with company match
+2
Manager- Application & AI Security
Manager- Application & AI Security

Apex Systems • Scottsdale (AZ)

Hybrid
USD 150,000 - 190,000
Medical, dental, vision
401K with company match
ESPP
+2
Mid-Level Full Stack Software Engineer
Mid-Level Full Stack Software Engineer

Apex Systems • Dearborn (MI)

Hybrid
USD 83,000 - 138,000
.Net Developer
.Net Developer

Apex Systems • Austin (TX)

On-site
USD 120,000 - 155,000
Medical, Dental, Vision
401K with company match
ESPP
+2
GRC Analyst
GRC Analyst

Apex Systems • Charlotte (NC), Northern (KY)

Hybrid
USD 85,000 - 120,000
Hybrid work environment
Contract-to-hire opportunity
Data Base Administrator
Data Base Administrator

Apex Systems • El Segundo (CA)

On-site
USD 130,000 - 170,000
Medical insurance
Dental insurance
Vision insurance
+5
Application Programmer III
Application Programmer III

Apex Systems • Charlotte (NC)

Hybrid
USD 110,000 - 150,000
ESPP
401K company match
Health Savings Account (HSA)
+2
Senior Technical Business Analyst
Senior Technical Business Analyst

Apex Systems • Brooklyn (OH)

On-site
USD 110,000 - 150,000
401K
ESPP
HSA
+3
Sr Technical Program Manager
Sr Technical Program Manager

Apex Systems • Dearborn (MI)

Hybrid
USD 120,000 - 160,000
Health insurance
401K program
Employee stock purchase program (ESPP)
+3