LI
Manager of Governance, Risk, and Compliance
LanceSoft Inc
- ๐บ๐ธ United States
- On-site
- Manager or above
- 1 day ago
- $82 โ $88 / hour
- Regulatory Compliance
- Risk Management
- SOX
- ServiceNow
- Change Management
- PCI DSS
- GDPR
- CCPA
- Gemini
- Claude
1 day ago
Schedule: 5 days/week | 8 hours/day | 40 hours/week
Job Description
The Client is seeking aManager of Governance, Risk, and Compliance (GRC) to oversee and support information security, IT regulatory, privacy risk, third-party risk, and compliance initiatives. This role will work closely with internal stakeholders, external auditors, and third-party vendors to maintain security controls, manage risks, support regulatory compliance, and improve the organization's overall GRC processes.
Key Responsibilities
- PerformInformation Security, IT regulatory, and privacy risk assessments across cloud and internal technology environments and systems.
- Lead theVendor Risk Management / Third-Party Risk Management (TPRM) program, including security risk assessments of third parties and contract reviews to ensure appropriate security controls are in place.
- Lead ongoing compliance activities forIT General Controls (ITGC) and SOX, coordinating with external auditors and internal stakeholders.
- Lead the organization'sSecurity Training and Awareness Program, including periodic security training for specific employee groups.
- Manage thephishing awareness program, including organization-wide simulated phishing campaigns.
- Manage and driverisk remediation activities with internal stakeholders and third parties.
- Manage theServiceNow Change Management module to support compliance with ITGC change management controls.
- Develop and maintain internalinformation security policies, standards, and procedures.
- Contribute to additional GRC and compliance programs, including:
- PCI DSS
- GDPR
- CCPA
- NIST Cybersecurity Framework (NIST CSF)
- Build and maintain strong working relationships with internal stakeholders outside of Information Security.
- Develop and maintainIT risk management metrics, dashboards, and reports.
- Strong experience acrossGovernance, Risk, and Compliance (GRC) and Information Security risk management.
- Experience withSOX, ITGC controls, IT risk assessments, vendor/third-party risk management, and audit coordination.
- Knowledge or experience with compliance frameworks and regulations such asPCI DSS, GDPR, CCPA, and NIST CSF.
- Experience working withServiceNow Change Management in support of ITGC and compliance requirements.
- Experience developingsecurity policies, standards, procedures, risk metrics, and reporting.
- Strong stakeholder management skills with the ability to work effectively with internal teams, external auditors, and third-party vendors.
- Experience usingAI tools such as Gemini Enterprise or Claude to improve GRC workflows, including:
- Automating evidence collection
- Accelerating vendor risk reviews
- Drafting policies and control narratives
- Summarizing audit and risk data
ย
Manager of Governance, Risk, and Compliance ยท LanceSoft Inc