T

GRC Program Lead

The Phoenix Group United State
Relocation
Apply
AI Summary

Lead the organization's GRC program, focusing on ISO 20000, risk assessments, and compliance frameworks. Develop and implement the GRC program, perform cybersecurity risk assessments, and maintain compliance with various standards. Strong experience with cybersecurity controls, data privacy, and GRC program implementation required.

Key Highlights
Lead the development, implementation, and management of the GRC program
Perform comprehensive cybersecurity risk assessments on applications, infrastructure, cloud environments, vendors, and business processes
Maintain and update the risk register and track remediation or mitigation activities until closure
Key Responsibilities
Lead the development, implementation, and management of the GRC program, ensuring efficient adoption of ISO 20000 standards and cybersecurity frameworks
Perform comprehensive cybersecurity risk assessments on applications, infrastructure, cloud environments, vendors, and business processes; facilitate risk identification, analysis, and treatment activities
Maintain and update the risk register and track remediation or mitigation activities until closure
Coordinate internal and external cybersecurity audits, assessments, and compliance reviews across multiple standards such as ISO 27001, NIST CSF, NIST 800-53, NIST 800-171, SOC 2, FedRAMP, CMMC, and SOX, ensuring evidence collection and control documentation
Support privacy initiatives including Data Protection Impact Assessments (DPIAs), privacy documentation, data inventories, classifications, and retention policies
Review vendor security questionnaires, third-party risk assessments, and related audit reports; ensure vendor cybersecurity and privacy compliance
Assist in maintaining cybersecurity policies, standards, and procedures; facilitate governance reviews, policy exception tracking, and metrics development
Develop dashboards, key risk indicators, compliance metrics, and trend analyses for executive reporting
Collaborate with cross-functional teams including Legal, IT, Security, and Infrastructure to embed risk and compliance controls into operational workflows
Technical Skills Required
Security frameworks Risk management Data privacy
Benefits & Perks
Salary range: Up to $90,000 annually
12% bonus potential
Hybrid work model: 2 days onsite, 3 days remote in Charlotte, NC
Nice to Have
Professional certifications such as CISSP, CISA, Security+, CRISC, ISO 27001 Lead Implementer, or CIPP are advantageous
Experience leading multi-disciplinary teams or major program initiatives with oversight responsibilities
Ability to crosswalk controls between cybersecurity frameworks and compliance requirements
Familiarity with control mapping, remediation tracking, and risk register maintenance

Job Description


Role Overview

This role involves establishing and leading the organization’s GRC program, focusing on ISO 20000, risk assessments, and compliance frameworks, with high visibility to executive leadership. The ideal candidate will have strong experience with cybersecurity controls, data privacy, and GRC program implementation, contributing to the organization’s strategic cybersecurity posture and growth.

Key Responsibilities

  • Lead the development, implementation, and management of the GRC program, ensuring efficient adoption of ISO 20000 standards and cybersecurity frameworks
  • Perform comprehensive cybersecurity risk assessments on applications, infrastructure, cloud environments, vendors, and business processes; facilitate risk identification, analysis, and treatment activities
  • Maintain and update the risk register and track remediation or mitigation activities until closure
  • Coordinate internal and external cybersecurity audits, assessments, and compliance reviews across multiple standards such as ISO 27001, NIST CSF, NIST 800-53, NIST 800-171, SOC 2, FedRAMP, CMMC, and SOX, ensuring evidence collection and control documentation
  • Support privacy initiatives including Data Protection Impact Assessments (DPIAs), privacy documentation, data inventories, classifications, and retention policies
  • Review vendor security questionnaires, third-party risk assessments, and related audit reports; ensure vendor cybersecurity and privacy compliance
  • Assist in maintaining cybersecurity policies, standards, and procedures; facilitate governance reviews, policy exception tracking, and metrics development
  • Develop dashboards, key risk indicators, compliance metrics, and trend analyses for executive reporting
  • Collaborate with cross-functional teams including Legal, IT, Security, and Infrastructure to embed risk and compliance controls into operational workflows

Core Qualifications & Requirements

  • Bachelor’s degree in Cybersecurity, Information Systems, Risk Management, Business, Legal Studies, or related field preferred
  • 2-5 years of experience in cybersecurity compliance, GRC, risk management, audit, or related roles
  • Demonstrated experience supporting cybersecurity frameworks such as ISO 20000, ISO 27001, NIST Cybersecurity Framework (CSF), NIST 800-53, NIST 800-171, SOC 2, FedRAMP, CMMC, and Sarbanes-Oxley (SOX)
  • Proven ability to perform cybersecurity risk assessments, manage compliance programs, and support audit preparation and evidence collection
  • Knowledge of data privacy principles, privacy impact assessments (PIAs), DPIAs, third-party risk reviews, and privacy-related controls
  • Strong understanding of cybersecurity controls, industry standards, and GRC platforms

Nice-to-Have Qualifications

  • Professional certifications such as CISSP, CISA, Security+, CRISC, ISO 27001 Lead Implementer, or CIPP are advantageous
  • Experience leading multi-disciplinary teams or major program initiatives with oversight responsibilities
  • Ability to crosswalk controls between cybersecurity frameworks and compliance requirements
  • Familiarity with control mapping, remediation tracking, and risk register maintenance

Core Technical Skills

  • Security frameworks: ISO 20000, ISO 27001, NIST 800-53, NIST 800-171, NIST CSF, SOC 2, FedRAMP, CMMC, SOX controls
  • Risk management: Risk assessments, risk treatment, risk registers, remediation tracking
  • Data privacy: DPIAs, PIAs, data inventories, classifications, privacy policies
  • GRC platforms: RSA Archer, ServiceNow GRC, LogicManager, MetricStream (preferred)
  • Auditing & compliance: Evidence collection, control documentation, audit readiness, vendor assessments

Career Impact

This role offers the opportunity to lead high-visibility cybersecurity compliance initiatives, collaborate with executive leadership, and shape the organization’s security governance, enabling accelerated career growth within a forward-thinking company.

Compensation and Benefits

  • Salary range: Up to $90,000 annually, with a 12% bonus potential
  • Hybrid work model: 2 days onsite, 3 days remote in Charlotte, NC
  • Opportunity for relocation and professional development, including certifications

Apply Today!

Join a growing team making a strategic impact on enterprise cybersecurity and compliance—apply now to elevate your career in a supportive, innovative environment.

The Phoenix Group Advisors is an equal opportunity employer. We are committed to creating a diverse and inclusive workplace and prohibit discrimination and harassment of any kind based on race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, genetic information, disability, or veteran status. We strive to attract talented individuals from all backgrounds and provide equal employment opportunities to all employees and applicants for


Similar Jobs

Explore other opportunities that match your interests

Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Not Applicable

boab ventures

United State

Senior Cybersecurity Researcher - Information Security & Threat Intelligence

Cyber Security
16h ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

Sandia National Laboratories

United State

Classified Cybersecurity Analyst

Cyber Security
16h ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

Northrop Grumman

United State

Subscribe our newsletter

New Things Will Always Update Regularly