ServiceNow Administrator / Developer

Cynosure IT Innovations LLC

Chicago (IL)

On-site

USD 120,000 - 160,000

Full time

31 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Cynosure IT Innovations LLC is seeking an experienced IT Governance, Risk, and Compliance (GRC) professional to lead and manage the organization’s IT GRC program. The role focuses on strengthening governance structures, identifying and mitigating IT risks, and ensuring ongoing compliance with regulatory, legal, and industry requirements.

You will partner with business and technology teams to foster a risk-aware culture.

Qualifications

  • Bachelor’s degree in Information Security, Computer Science, or related discipline.
  • Professional certifications such as CISA, CISSP, CRISC are highly preferred.
  • 7+ years of hands-on experience in IT Governance, Risk Management, and Compliance roles.
  • Proven experience implementing and managing GRC frameworks such as ISO 27001, NIST, COBIT.
  • Strong knowledge of regulatory and compliance requirements including GDPR, HIPAA, SOX.

Responsibilities

  • Design, implement, and oversee the end-to-end IT GRC program.
  • Establish and enhance governance frameworks, policies, and standards.
  • Identify, assess, and prioritize IT and information security risks.

Skills

GRC experience
Stakeholder management
Communication
Collaboration

Education

Bachelor’s degree in Information Security or related

Tools

ISO 27001
NIST
COBIT

Job description

We are looking for an experienced IT Governance, Risk, and Compliance (GRC) professional to lead and manage the organization’s IT GRC program. The role focuses on strengthening governance structures, identifying and mitigating IT risks, and ensuring ongoing compliance with regulatory, legal, and industry requirements. The ideal candidate will act as a strategic partner to business and technology teams, driving a strong risk-aware and compliance-focused culture across the organization.

Key Responsibilities
GRC Program Management

Design, implement, and oversee the end-to-end IT GRC program aligned with organizational objectives.

Establish, review, and enhance governance frameworks, policies, procedures, and standards related to information security and compliance.

Identify, assess, and prioritize IT and information security risks across systems, processes, and vendors.

Collaborate with internal stakeholders to define risk treatment plans and ensure timely and effective mitigation.

Compliance Management

Ensure compliance with applicable laws, regulations, and industry standards.

Plan and execute regular compliance assessments, internal audits, and control reviews, addressing gaps and remediation actions.

Policy and Standards Development

Develop, maintain, and periodically review information security and IT governance policies.

Ensure alignment with business objectives, regulatory expectations, and recognized industry frameworks.

Training and Awareness

Lead security, risk, and compliance awareness initiatives across the organization.

Conduct training sessions on GRC best practices and collaborate with stakeholders to promote understanding of compliance obligations.

Incident Response and Investigation

Support and lead IT and information security incident response activities as required.

Conduct investigations into security incidents, document findings, and recommend corrective and preventive actions.

Drive continuous improvement initiatives to enhance the maturity and effectiveness of the GRC program.

Stay current on emerging threats, regulatory changes, and industry trends impacting the GRC landscape.

Qualifications & Experience

Bachelor’s degree in Information Security, Computer Science, or a related discipline.

Professional certifications such as CISA, CISSP, CRISC, or equivalent are highly preferred.

7+ years of hands-on experience in IT Governance, Risk Management, and Compliance roles.

Proven experience implementing and managing GRC frameworks such as ISO 27001, NIST, COBIT, or similar standards.

Strong knowledge of regulatory and compliance requirements, including GDPR, HIPAA, SOX, and other applicable regulations.

Excellent communication, stakeholder management, and collaboration skills.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

GRC (Governance, Risk, and Compliance) Consultant
GRC (Governance, Risk, and Compliance) Consultant

Zoho • United States

Remote
USD 120,000 - 180,000
IT GRC Lead Analyst
IT GRC Lead Analyst

Westfield Insurance • Westfield Center (OH)

On-site
USD 90,000 - 120,000
ServiceNow GRC Solution Architect
ServiceNow GRC Solution Architect

Net2Source (N2S) • Atlanta (GA)

On-site
USD 96,432 - 110,208
GRC Specialist (Governance, Risk & Compliance)
GRC Specialist (Governance, Risk & Compliance)

360CyberX • United States

On-site
USD 70,000 - 90,000
Sr. IT Security Analyst
Sr. IT Security Analyst

The Marzetti Company • Columbus (OH)

On-site
USD 90,000 - 120,000
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

RELX • Raleigh (NC)

On-site
USD 118,300 - 219,800
Annual incentive bonus
Cybersecurity GRC Professional
Cybersecurity GRC Professional

duvari group • United States

On-site
USD 120,000 - 190,000
IT Governance Program Lead
IT Governance Program Lead

Insight Global • United States

On-site
USD 90,000 - 130,000
Medical, dental, and vision insurance
401k retirement account access with employer matching
Paid sick leave and time off
GRC Analyst
GRC Analyst

Golden Technology • North Carolina

On-site
USD 120,000 - 160,000
Governance, Risk and Compliance (GRC) Lead - 249079
Governance, Risk and Compliance (GRC) Lead - 249079

Medix Technology • Northfield Township (IL)

On-site
USD 90,000 - 130,000