Senior Manager, Security GRC

AspenView Technology Partners

United States

Hybrid

USD 140,000 - 195,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive base
Flexible work model
Growth opportunities
Inclusive culture

Job summary

AspenView Technology Partners in the United States seeks a Senior Manager, Security GRC to own the enterprise GRC program, shape risk posture, and translate regulatory requirements into scalable, cross‑functional initiatives. You will partner with the CISO and executive leadership to align policy architecture with business objectives.

You will lead a high-performing team, oversee audits and controls across NIST CSF, ISO 27001, SOX, GDPR and CMMC, and drive incident response readiness,

Qualifications

  • 12+ years in cybersecurity with significant enterprise GRC leadership experience.
  • CISSP or CISM required; CRISC or CGEIT preferred.

Responsibilities

  • Own enterprise GRC strategy and program roadmap aligned to risk appetite.
  • Lead regulatory compliance across NIST CSF, ISO 27001, SOX, GDPR, and CMMC; manage audit relationships.
  • Lead Cyber-Supply Chain Risk Management and third-party security assessments.

Skills

Cybersecurity leadership
GRC program leadership
Executive advisory
Regulatory compliance

Tools

NIST CSF
NIST RMF
ISO 27001
ISO 31000

Job description

Build the Future with AspenView Technology Partners

At AspenView, we are passionate about transforming the way organizations approach technology. We specialize in creating high-performing, nearshore IT teams to help North American clients innovate faster and more efficiently.

As we continue to grow, we’re looking for exceptional people to join our team and help drive impactful change across industries.

Why Join AspenView?

At AspenView, we’re more than a nearshore IT partner—we’re a people-first, purpose-driven company that believes great culture drives great outcomes. We’re passionate about connecting talent and technology to deliver measurable value for clients—and meaningful career paths for our people.

  • Competitive base
  • Flexible work model: hybrid, remote, or in-office
  • Real growth opportunities and leadership visibility
  • Inclusive, respectful culture that blends U.S. innovation with Colombian heart
  • A company that listens, invests in you, and celebrates wins together
Senior Manager, Security GRC

The Senior Manager, Security GRC drives the enterprise security governance framework, shaping risk posture, compliance strategy, and policy architecture across global operations. Serving as the primary cyber risk advisor to the CISO and executive leadership, you will translate regulatory requirements and board-level risk appetite into actionable, enterprise-wide programs.

What you will do
Strategy & Governance Management
  • Own the enterprise GRC strategy and program roadmap aligned to business objectives and risk appetite.
  • Establish and enforce security policies, standards, and the exceptions management process.
  • Build and develop a high-performing GRC team while partnering with Legal, Internal Audit, and business unit leaders.
Risk Reporting & Compliance
  • Govern regulatory compliance across NIST CSF, ISO 27001, SOX, GDPR, and CMMC, while managing audit relationships.
  • Lead cyber risk reporting to the CISO, Board, and executive stakeholders, and define risk quantification methods.
Supply Chain & Resilience
  • Lead Cyber-Supply Chain Risk Management and third-party security assessment programs.
  • Oversee Business Continuity Planning integration with cybersecurity resilience and drive the Training & Awareness strategy.
Tools & Technologies
  • Frameworks: Mastery of NIST CSF, NIST RMF, ISO 27001, and ISO 31000.
  • Regulations: Expertise in SOX ITGC, GDPR, CMMC, and cross-jurisdictional regulatory compliance.
  • Methodologies: Advanced understanding of third-party risk, supply chain security, and business continuity methodologies.
What you bring
  • Experience: 12+ years in cybersecurity with 5+ years leading enterprise GRC programs in complex, global organizations.
  • Certification: CISSP or CISM is required; CRISC or CGEIT is highly preferred.
  • Executive Advisory: Exceptional skills with a proven ability to translate complex cyber risk into board-level narratives.
  • Leadership: Demonstrated ability to build and lead high-performing teams in a transformation or build-out context.
Visa Sponsorship

AspenView does not sponsor employment visas for this role. Applicants must be currently authorized to work in the United States on a permanent basis without the need for visa sponsorship now or in the future.

Equal Opportunity Employer

AspenView is proud to be an equal opportunity employer. We believe in creating an environment where all employees feel welcome, valued, and empowered to succeed. We celebrate diversity and strive to build a culture of inclusion where all individuals, regardless of their race, color, gender, gender identity or expression, sexual orientation, disability, age, or any other characteristic, can thrive. We encourage applicants from all walks of life to join our team and make a lasting impact.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Mid-Level Security Engineer
Mid-Level Security Engineer

AspenView Technology Partners • Colorado Springs (CO)

Hybrid
USD 80,000 - 100,000
Competitive base
Comprehensive benefits and wellness support
Real growth opportunities
+1
Senior Security GRC Leader: Strategy & Compliance (Hybrid)
Senior Security GRC Leader: Strategy & Compliance (Hybrid)

AspenView Technology Partners • United States

Hybrid
USD 140,000 - 195,000
Competitive base
Flexible work model
Growth opportunities
+1
Principal GRC Business Engineer
Principal GRC Business Engineer

Palo Alto Networks, Inc. • Santa Clara (CA)

On-site
USD 168,000 - 271,000
Principal GRC Business Engineer
Principal GRC Business Engineer

Palo Alto Networks • Santa Clara (CA)

On-site
USD 168,000 - 271,000
Principal GRC Business Engineer
Principal GRC Business Engineer

Palo Alto Networks • California (MO)

On-site
USD 168,000 - 271,000
Senior Director, GRC
Senior Director, GRC

United States Digital Space LLC • San Francisco (CA)

On-site
USD 264,000 - 363,000
Equity (where applicable)
Bonus
Health, dental and vision insurance
+3
Director, Security Risk Management
Director, Security Risk Management

CardWorks Servicing LLC • United States

Hybrid
USD 151,000 - 168,000
Medical, Dental, and Vision coverage
401(k) Plan with Company Match
Paid vacation and sick days
Information Technology Security Analyst
Information Technology Security Analyst

The Phoenix Group • Charlotte (NC)

Hybrid
USD 95,000 - 116,000
Hybrid work model
Relocation assistance
Certification sponsorship
Director GRC
Director GRC

INSPYR Solutions • Addison (TX)

Hybrid
USD 140,000 - 230,000
Governance Risk & Compliance Analyst
Governance Risk & Compliance Analyst

System One • Denver (CO)

Hybrid
USD 80,000 - 100,000
Health and welfare benefits
401(k) plan
Medical, dental, and vision coverage