JSG is seeking a Senior Manager -Governance, Risk & Compliance for a long term contract / CTH opportunity in Irvine, CA
Hybrid I M-TH Onsite /Friday WFH
The Governance, Risk & Compliance team is seeking a Senior Cybersecurity Risk Manager to help strengthen and evolve our internal security risk strategy in a fast-changing threat landscape. In this highly visible role, you’ll proactively identify, assess, and mitigate cybersecurity risks that could impact business operations, financial stability, and regulatory compliance—while building clear, executive-ready metrics and governance. You’ll report to the Director, Cybersecurity Program Management and partner cross-functionally to influence outcomes, elevate risk maturity, and help ensure the organization stays resilient and forward-thinking.
Required Skills:
- Cybersecurity risk management expertise with the ability to evaluate risk posture across systems, applications, processes, and leveraged solutions
- Experience performing risk assessments, threat modeling, and impact analysis, including interpreting findings and recommending practical risk treatment
- Ability to build, enhance, and execute a cybersecurity risk management framework aligned to business objectives and regulatory needs
- Strong knowledge of GRC processes and IT general controls, including asset classification, vulnerability/threat analysis, audit controls & remediation, and risk reporting
- Knowledge of leading security/risk frameworks and standards, including:
- ISO 27001/27002, ISO 31000:2018, ISO 27005:2022
- NIST methodologies and publications (e.g., SP 800-12, 800-30, 800-37, 800-39, 800-53, 800-150, 800-161)
- Working knowledge of relevant regulations and requirements, including CCPA, GLBA, NYDFS Cybersecurity Regulation, PCI-DSS, FFIEC, SOX, and related laws
- Ability to define and maintain security risk metrics (KRIs/KPIs) and deliver effective reporting for executives and stakeholders
- Strong communication skills—able to explain complex security concepts to both business leaders and technical teams
- Intermediate proficiency in Microsoft Office (Word, Excel, PowerPoint)
- Proven ability to work autonomously and collaboratively, with strong attention to detail, sound judgment, integrity, and a results orientation
Nice to Have Skills
- Financial services industry cybersecurity risk/GRC experience
- Experience supporting or contributing to vendor/partner security risk evaluations and alignment to cybersecurity policies and risk strategies
- Demonstrated ability to challenge existing practices constructively and drive continuous improvement
Preferred Education and Experience
- Bachelor’s degree in finance, business, or a related discipline
- 8+ years of progressive experience in cybersecurity governance, risk management, or compliance, including familiarity with SDLC and the evolving threat landscape
Other Requirement's
- Certifications are highly desirable, including: CISSP, CISM, CRISC, CGEIT, ITIL
- Role is performed in an office environment with extended periods of sitting, standing, walking, and computer use
JSG offers medical, dental, vision, life insurance options, short-term disability, 401(k), weekly pay, and more. Johnson Service Group (JSG) is an Equal Opportunity Employer. JSG provides equal employment opportunities to all applicants and employees without regard to race, color, religion, sex, age, sexual orientation, gender identity, national origin, disability, marital status, protected veteran status, or any other characteristic protected by law