Senior Manager -Governance, Risk & Compliance

JSG (Johnson Service Group, Inc.)

Irvine (CA)

Hybrid

USD 150,000 - 210,000

Full time

22 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Medical insurance
Dental insurance
Vision insurance
Life insurance
401(k)

Job summary

JSG (Johnson Service Group, Inc.) is seeking a Senior Cybersecurity Risk Manager in Irvine, CA. The role focuses on strengthening and evolving our internal security risk strategy across governance, risk and compliance.

You will identify, assess, and mitigate cybersecurity risks, and build executive-ready metrics to influence risk decisions. The position is hybrid (Irvine, CA) with M-TH onsite and Friday work-from-home.

Qualifications

  • Cybersecurity risk management expertise to evaluate risk posture across systems, applications, processes and leveraged solutions.
  • Experience performing risk assessments, threat modeling, and impact analysis.
  • Ability to build, enhance, and execute a cybersecurity risk management framework aligned to business objectives and regulatory needs.
  • GRC processes and IT general controls knowledge including asset classification, vulnerability/threat analysis, audit controls & remediation, and risk reporting.
  • Knowledge of ISO 27001/27002, ISO 31000:2018, ISO 27005:2022; NIST SP 800-12, 800-30, 800-37, 800-39, 800-53, 800-150, 800-161.
  • Familiarity with regulations such as CCPA, GLBA, NYDFS Cybersecurity Regulation, PCI-DSS, FFIEC, SOX.
  • Ability to define and maintain security risk metrics (KRIs/KPIs) and report to executives.
  • Strong communication to explain security concepts to business leaders and technical teams.
  • Proficiency in Microsoft Office (Word, Excel, PowerPoint).
  • Capable of working autonomously and collaboratively with attention to detail and sound judgment.

Responsibilities

  • Identify, assess, and mitigate cybersecurity risks affecting operations and regulatory compliance.
  • Develop and evolve risk management strategies and governance with executive-ready metrics.
  • Partner cross-functionally to improve risk maturity and resilience.
  • Maintain security risk metrics and deliver reporting for executives and stakeholders.
  • Stay current with regulatory requirements and cybersecurity frameworks; influence control implementations.

Skills

Cybersecurity risk management
Risk assessments
Threat modeling
Risk framework
GRC processes
IT general controls
NIST methodologies
Regulatory awareness
Security metrics
Executive communication
MS Office
Autonomy

Education

Bachelor’s degree in finance, business, or related discipline

Tools

Microsoft Office

Job description

JSG is seeking a Senior Manager -Governance, Risk & Compliance for a long term contract / CTH opportunity in Irvine, CA

Hybrid I M-TH Onsite /Friday WFH

The Governance, Risk & Compliance team is seeking a Senior Cybersecurity Risk Manager to help strengthen and evolve our internal security risk strategy in a fast-changing threat landscape. In this highly visible role, you’ll proactively identify, assess, and mitigate cybersecurity risks that could impact business operations, financial stability, and regulatory compliance—while building clear, executive-ready metrics and governance. You’ll report to the Director, Cybersecurity Program Management and partner cross-functionally to influence outcomes, elevate risk maturity, and help ensure the organization stays resilient and forward-thinking.

Required Skills:
  • Cybersecurity risk management expertise with the ability to evaluate risk posture across systems, applications, processes, and leveraged solutions
  • Experience performing risk assessments, threat modeling, and impact analysis, including interpreting findings and recommending practical risk treatment
  • Ability to build, enhance, and execute a cybersecurity risk management framework aligned to business objectives and regulatory needs
  • Strong knowledge of GRC processes and IT general controls, including asset classification, vulnerability/threat analysis, audit controls & remediation, and risk reporting
  • Knowledge of leading security/risk frameworks and standards, including:
  • ISO 27001/27002, ISO 31000:2018, ISO 27005:2022
  • NIST methodologies and publications (e.g., SP 800-12, 800-30, 800-37, 800-39, 800-53, 800-150, 800-161)
  • Working knowledge of relevant regulations and requirements, including CCPA, GLBA, NYDFS Cybersecurity Regulation, PCI-DSS, FFIEC, SOX, and related laws
  • Ability to define and maintain security risk metrics (KRIs/KPIs) and deliver effective reporting for executives and stakeholders
  • Strong communication skills—able to explain complex security concepts to both business leaders and technical teams
  • Intermediate proficiency in Microsoft Office (Word, Excel, PowerPoint)
  • Proven ability to work autonomously and collaboratively, with strong attention to detail, sound judgment, integrity, and a results orientation
Nice to Have Skills
  • Financial services industry cybersecurity risk/GRC experience
  • Experience supporting or contributing to vendor/partner security risk evaluations and alignment to cybersecurity policies and risk strategies
  • Demonstrated ability to challenge existing practices constructively and drive continuous improvement
Preferred Education and Experience
  • Bachelor’s degree in finance, business, or a related discipline
  • 8+ years of progressive experience in cybersecurity governance, risk management, or compliance, including familiarity with SDLC and the evolving threat landscape
Other Requirement's
  • Certifications are highly desirable, including: CISSP, CISM, CRISC, CGEIT, ITIL
  • Role is performed in an office environment with extended periods of sitting, standing, walking, and computer use

JSG offers medical, dental, vision, life insurance options, short-term disability, 401(k), weekly pay, and more. Johnson Service Group (JSG) is an Equal Opportunity Employer. JSG provides equal employment opportunities to all applicants and employees without regard to race, color, religion, sex, age, sexual orientation, gender identity, national origin, disability, marital status, protected veteran status, or any other characteristic protected by law

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Risk Manager | GRC & Compliance Leader
Senior Cybersecurity Risk Manager | GRC & Compliance Leader

JSG (Johnson Service Group, Inc.) • Irvine (CA)

Hybrid
USD 150,000 - 210,000
Medical insurance
Dental insurance
Vision insurance
+2
Snr GRC Analyst
Snr GRC Analyst

Tiro Security, LLC • California (MO)

On-site
USD 100,000 - 150,000
Sr IT Manager- NIST 800-171, CMMC
Sr IT Manager- NIST 800-171, CMMC

JSG (Johnson Service Group, Inc.) • California (MO)

On-site
USD 140,000 - 160,000
Senior Cybersecurity Risk & Governance Analyst
Senior Cybersecurity Risk & Governance Analyst

mTrade, LLC. • Oxford (MS)

On-site
USD 110,000 - 160,000
Senior Cybersecurity Risk & Governance Analyst
Senior Cybersecurity Risk & Governance Analyst

Mortgage-Trade-Holding-Company,-LL • Oxford (MS)

On-site
USD 110,000 - 150,000
Junior Cybersecurity GRC Analyst
Junior Cybersecurity GRC Analyst

Talanto • Northern (KY)

Hybrid
USD 5,500 - 12,000
Medical: Health plan options with HSA
Dental: PPO coverage
Vision: Annual exam allowance
+5
GRC Analyst
GRC Analyst

The Emery Company, LLC • Houston (TX)

On-site
USD 85,000 - 110,000
GOVERNANCE, RISK, AND COMPLIANCE ANALYST
GOVERNANCE, RISK, AND COMPLIANCE ANALYST

Access Data Consulting Corporation • Phoenix (AZ)

Hybrid
USD 80,000 - 100,000
Governance, Risk & Compliance Analyst I
Governance, Risk & Compliance Analyst I

ID Projetos Educacionais • Palm Harbor (FL)

Hybrid
USD 65,000 - 90,000
Governance, Risk & Compliance Analyst I
Governance, Risk & Compliance Analyst I

Geographic Solutions, Inc. • Palm Harbor (FL)

Hybrid
USD 65,000 - 85,000