Senior GRC, Technical Controls & AI Risk

Mondo

New York (NY)

Remote

USD 96,000 - 110,000

Full time

13 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Health insurance
Dental insurance
Vision insurance
401K

Job summary

Mondo is seeking a Senior GRC, Technical Controls & AI Risk to lead technical control reviews, testing, evidence evaluation and remediation planning across cybersecurity domains. You will partner with security engineering, IAM, vulnerability management, cloud, application security, data protection and business teams, supporting AI governance and risk management with NIST/ISO 27001, SOC 2 and related frameworks.

The role is remote in the U.S.

Qualifications

  • 8–13 years of cybersecurity GRC, IT risk, IT audit or related experience.
  • Experience performing technical control assessments and testing across multiple domains.
  • Strong knowledge of control design, operating effectiveness and remediation planning.
  • Experience with ServiceNow IRM, Hyperproof, or Vanta.

Responsibilities

  • Conduct technical control reviews and assessments across cybersecurity domains.
  • Design and execute control testing, evaluating design, operating effectiveness, scope and evidence quality.
  • Review audit evidence, system reports, tickets, configurations and testing results.
  • Identify control gaps, deficiencies and root causes.
  • Develop risk-based remediation plans with owners, milestones and success criteria.
  • Assess inherent risk, control effectiveness and residual risk.
  • Support internal and external audits, regulatory assessments and assurance requests.
  • Map requirements across NIST CSF, NIST SP 800-53, ISO 27001, SOC 2 and regulatory needs.
  • Develop policies, standards and evidence requirements.
  • Produce risk dashboards and executive recommendations.
  • Improve control adoption and evidence quality using tools like ServiceNow IRM, Hyperproof, and Vanta.
  • Support AI governance including AI risk matrices, vendor risk and lifecycle governance.

Skills

GRC
Cybersecurity
Risk analysis
Evidence evaluation
Audit support
Policy development
AI governance
ISO 27001
NIST frameworks
ServiceNow IRM

Tools

ServiceNow IRM
Hyperproof
Vanta

Job description

Senior GRC, Technical Controls & AI Risk
Location-Type: Remote
Start Date Is: ASAP
Duration: (contract, perm, etc)6Month Contract (option to extend or convert)
Compensation Range: $70-80/hour W2
Benefits: Eligible for Health, Dental, Vision, 401K
Must be authorized to work in the U.S. This position is not eligible for sponsorship

Position Summary

We are seeking a senior Governance, Risk and Compliance professional to lead technical control reviews, testing, evidence evaluation, risk analysis, and remediation planning across cybersecurity. This role will partner with security engineering, architecture, IAM, vulnerability management, incident response, cloud, application security, data protection, and business teams.

The ideal candidate is a strong GRC generalist with sufficient technical depth to understand how controls operate, challenge evidence, identify root causes, assess residual risk, and develop practical remediation plans. The role will also support AI governance and risk management.

Key Responsibilities
  • Conduct technical control reviews and assessments across cybersecurity domains, including IAM, vulnerability management, security operations, incident response, cloud, infrastructure, application security, data protection, and third-party risk.
  • Design and execute control testing, evaluating control design, operating effectiveness, scope, frequency, ownership, and evidence quality.
  • Review and challenge audit evidence, system reports, tickets, configurations, testing results, and management assertions.
  • Identify control gaps, deficiencies, recurring issues, exceptions, and root causes.
  • Develop risk-based remediation plans with owners, milestones, dependencies, success criteria, and sustainable corrective actions.
  • Assess inherent risk, control effectiveness, compensating controls, residual risk, and risk acceptance decisions.
  • Support internal and external audits, regulatory assessments, customer assurance requests, and certification activities.
  • Map requirements across NIST CSF, NIST SP 800-53, ISO 27001, SOC 2, and applicable regulatory requirements.
  • Develop and maintain policies, standards, control objectives, risk statements, assessment methodologies, and evidence requirements.
  • Produce risk dashboards, control maturity assessments, issue and exception reporting, and executive recommendations.
  • Improve control adoption, evidence quality, repeatable testing, and continuous monitoring using ServiceNow IRM, Hyperproof, and Vanta.
  • Support AI governance, including AI use-case assessments, AI risk and control matrices, responsible AI, model and data risks, third-party AI, agentic AI, security, privacy, transparency, human oversight, and lifecycle governance.
  • Apply ISO/IEC 42001 and the NIST AI Risk Management Framework to AI governance and control design.
  • Advise technical and business stakeholders on risk trade-offs, remediation options, and control requirements.
Required Qualifications
  • 8-13 years of experience in cybersecurity GRC, IT risk, IT audit, internal controls, compliance, security assurance, or a related discipline.
  • Experience performing technical control assessments and testing across multiple cybersecurity domains.
  • Strong knowledge of control design, operating effectiveness, evidence evaluation, risk analysis, issue management, exceptions, and remediation planning.
  • Ability to interpret technical evidence from IAM, vulnerability, incident, cloud, application security, infrastructure, and operational environments.
  • Experience with NIST, ISO 27001, SOC 2, COBIT, or comparable frameworks.
  • Strong written and verbal communication skills, including the ability to explain technical risk to business and executive stakeholders.
  • Experience with ServiceNow IRM, Hyperproof, or Vanta.
  • Preferred Qualifications
  • CISA, CIA, CISSP, CRISC, CISM, or comparable certification; CISA, CIA, and CISSP are particularly desirable.
  • Experience with ISO/IEC 42001, NIST AI RMF, AI governance, AI risk assessments, or AI control frameworks.
  • Experience developing AI risk and control matrices or assessing AI use cases, models, data, vendors, and agentic AI implementations.
  • Experience with control automation, continuous control monitoring, data analytics, or control-as-code concepts.
  • Experience supporting global, regulated, or complex enterprise environments.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior GRC & AI Risk: Technical Controls Lead (Remote)
Senior GRC & AI Risk: Technical Controls Lead (Remote)

Mondo • New York (NY)

Remote
USD 96,000 - 110,000
Health insurance
Dental insurance
Vision insurance
+1
GRC Specialist II
GRC Specialist II

Scigon Solutions, Inc. • Austin (TX)

On-site
USD 116,000 - 144,000
Senior GRC Analyst
Senior GRC Analyst

Averity • New York (NY)

On-site
USD 90,000 - 140,000
GRC Specialist II
GRC Specialist II

Scigon Solutions, Inc. • Salt Lake City (UT)

On-site
USD 116,000 - 144,000
Senior Cybersecurity Engineer, GRC Automation and Continuous Control Monitoring
Senior Cybersecurity Engineer, GRC Automation and Continuous Control Monitoring

Marathon Petroleum Corporation • Houston (TX)

On-site
USD 120,000 - 170,000
Senior Cybersecurity Engineer, GRC Automation and Continuous Control Monitoring
Senior Cybersecurity Engineer, GRC Automation and Continuous Control Monitoring

Marathon Petroleum Corporation • Findlay (OH)

On-site
USD 120,000 - 160,000
GRC (Governance, Risk, and Compliance) Consultant
GRC (Governance, Risk, and Compliance) Consultant

Zoho • United States

Remote
USD 120,000 - 180,000
GRC Analyst
GRC Analyst

The Emery Company, LLC • Houston (TX)

On-site
USD 85,000 - 110,000
Cybersecurity Governance Analyst
Cybersecurity Governance Analyst

Veriipro • Fort Lauderdale (FL)

On-site
USD 90,000 - 130,000
Senior Security Engineer
Senior Security Engineer

Prestige Staffing • Georgia

On-site
USD 140,000 - 200,000