Senior GRC Officer - Security & Compliance Leader

Penlink

Lincoln (NE)

Hybrid

USD 120,000 - 160,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Penlink is a technology company enabling investigators to solve crimes with secure data management in the United States. This hybrid role sits in Lincoln, NE, and leads governance, risk, and compliance programs across FedRAMP, CMMC, SOC 2, ISO 27001, and related frameworks.

You will coordinate audits, craft essential documentation, and partner with 3PAO/C3PAO assessors to ensure readiness and ongoing compliance.

Qualifications

  • 5+ years in governance, risk, compliance, or information security within SaaS/cloud/regulated environments.
  • Direct FedRAMP experience including SSP/POA&M and assessment readiness.
  • Strong knowledge of NIST SP 800-53 controls and applicability for stakeholders.

Responsibilities

  • Independently manage FedRAMP, CMMC 2, SOC 2 Type 2, ISO 27001, TX-RAMP, CJIS workstreams and readiness.
  • Lead creation and quality review of SSPs, POA&M, control narratives, policies, procedures, and readiness artifacts; act as primary contact for 3PAO/C3PAO.
  • Coordinate implementation/validation of NIST SP 800-53 and CMMC across engineering, cloud, IT, and product; maintain evidence repositories.
  • Own risk management, vendor risk assessment, policy governance, access review, and exception management; lead Cloud Vulnerability Task Force.
  • Plan and support external audits/certifications; respond to RFIs/RFPs and customer security questionnaires.
  • Prioritize multiple workstreams; track remediation; elevate risks; provide status updates to management.
  • Conduct internal assessments and gap analyses; recommend remediation actions.
  • Provide guidance as a trusted security/compliance reviewer to ensure risks and controls are considered before implementation.

Skills

GRC Leadership
FedRAMP Experience
NIST SP 800-53
Risk Assessment
Audit Coordination
Documentation Quality
Stakeholder Communication
Regulatory Compliance

Job description

Penlink is a technology company enabling investigators to solve crimes with secure data management in the United States. This hybrid role sits in Lincoln, NE, and leads governance, risk, and compliance programs across FedRAMP, CMMC, SOC 2, ISO 27001, and related frameworks.

You will coordinate audits, craft essential documentation, and partner with 3PAO/C3PAO assessors to ensure readiness and ongoing compliance.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior GRC Leader - Cybersecurity & Compliance (Remote)
Senior GRC Leader - Cybersecurity & Compliance (Remote)

Pellera Technologies • United States

On-site
USD 150,000 - 210,000
Senior Public Sector GRC Engineer – FedRAMP/SOC2
Senior Public Sector GRC Engineer – FedRAMP/SOC2

Triwill Group • Northern (KY)

Hybrid
USD 139,000 - 196,000
GRC Lead: Federal Compliance & Risk (Onsite)
GRC Lead: Federal Compliance & Risk (Onsite)

NextgenID • Fairfax (VA), Northern (KY)

Hybrid
USD 95,000 - 120,000
Impactful Law Enforcement Tech Program Lead
Impactful Law Enforcement Tech Program Lead

Penlink • Lincoln (NE)

On-site
USD 110,000 - 140,000
Public Sector GRC & Security Compliance Lead
Public Sector GRC & Security Compliance Lead

GitLab • United States

On-site
USD 139,000 - 196,000
Benefits to support health and well‑be
Flexible Paid Time Off
Equity Compensation & Stock Purchase
+2
Senior GRC & Third-Party Risk Lead, Data Protection
Senior GRC & Third-Party Risk Lead, Data Protection

Peraton • Herndon (VA)

On-site
USD 104,000 - 166,000
Senior GRC Lead: CMMC, FedRAMP, SOC 2, ITAR
Senior GRC Lead: CMMC, FedRAMP, SOC 2, ITAR

Northwood Space • Torrance (CA)

On-site
USD 120,000 - 150,000
GRC Lead - FedRAMP High & DoD IL4-6
GRC Lead - FedRAMP High & DoD IL4-6

peregrine technologies • Washington

Hybrid
USD 158,000 - 184,000
Remote Senior Security GRC Engineer: FedRAMP/ISO 27001
Remote Senior Security GRC Engineer: FedRAMP/ISO 27001

GitLab Inc. • Northern (KY)

Hybrid
USD 140,000 - 190,000
Strategic FedRAMP & DoD GRC Leader
Strategic FedRAMP & DoD GRC Leader

Mosaic.tech • Washington

Hybrid
USD 158,000 - 184,000