Stand out for this role — generate a tailored resume and cover letter in about a minute.
Cynosure IT Innovations LLC is seeking an experienced IT Governance, Risk, and Compliance (GRC) professional to lead and manage the organization’s IT GRC program. The role focuses on strengthening governance structures, identifying and mitigating IT risks, and ensuring ongoing compliance with regulatory, legal, and industry requirements.
You will partner with business and technology teams to foster a risk-aware culture.
We are looking for an experienced IT Governance, Risk, and Compliance (GRC) professional to lead and manage the organization’s IT GRC program. The role focuses on strengthening governance structures, identifying and mitigating IT risks, and ensuring ongoing compliance with regulatory, legal, and industry requirements. The ideal candidate will act as a strategic partner to business and technology teams, driving a strong risk-aware and compliance-focused culture across the organization.
Design, implement, and oversee the end-to-end IT GRC program aligned with organizational objectives.
Establish, review, and enhance governance frameworks, policies, procedures, and standards related to information security and compliance.
Identify, assess, and prioritize IT and information security risks across systems, processes, and vendors.
Collaborate with internal stakeholders to define risk treatment plans and ensure timely and effective mitigation.
Ensure compliance with applicable laws, regulations, and industry standards.
Plan and execute regular compliance assessments, internal audits, and control reviews, addressing gaps and remediation actions.
Develop, maintain, and periodically review information security and IT governance policies.
Ensure alignment with business objectives, regulatory expectations, and recognized industry frameworks.
Lead security, risk, and compliance awareness initiatives across the organization.
Conduct training sessions on GRC best practices and collaborate with stakeholders to promote understanding of compliance obligations.
Support and lead IT and information security incident response activities as required.
Conduct investigations into security incidents, document findings, and recommend corrective and preventive actions.
Drive continuous improvement initiatives to enhance the maturity and effectiveness of the GRC program.
Stay current on emerging threats, regulatory changes, and industry trends impacting the GRC landscape.
Bachelor’s degree in Information Security, Computer Science, or a related discipline.
Professional certifications such as CISA, CISSP, CRISC, or equivalent are highly preferred.
7+ years of hands-on experience in IT Governance, Risk Management, and Compliance roles.
Proven experience implementing and managing GRC frameworks such as ISO 27001, NIST, COBIT, or similar standards.
Strong knowledge of regulatory and compliance requirements, including GDPR, HIPAA, SOX, and other applicable regulations.
Excellent communication, stakeholder management, and collaboration skills.