Governance, Risk & Compliance; GRC Manager
Listed on 2026-07-14
-
IT/Tech
Cybersecurity, Information Security, Data Security, IT Project Manager
Riverside Overview
Riverside Research is an independent National Security Nonprofit dedicated to research and development in the national interest. We provide high-end technical services, research and development, and prototype solutions to some of the country’s most challenging technical problems. All Riverside Research opportunities require U.S. Citizenship.
Position OverviewThe Manager, Governance, Risk & Compliance (GRC) leads Riverside Research's Governance, Risk, and Compliance program supporting the organization's unclassified enterprise and research information systems. Reporting to the Director of Information Security, this position is responsible for maintaining and continuously maturing Riverside's cybersecurity governance framework, enterprise risk management program, and regulatory compliance initiatives.
This role serves as both a people leader and technical contributor, providing leadership for a team of GRC professionals while partnering across Information Security, Information Technology, Contracts, Human Resources, Finance, Legal, and Business Operations to ensure cybersecurity and compliance objectives align with organizational and customer requirements.
The Manager owns Riverside's Cybersecurity Maturity Model Certification (CMMC) program, leading continuous readiness activities, regulatory assessments, governance initiatives, and enterprise risk management efforts to maintain the organization's strong cybersecurity posture and support Department of Defense mission requirements.
Responsibilities- Lead Riverside Research's Governance, Risk, and Compliance (GRC) program supporting the enterprise cybersecurity strategy, governance framework, and compliance objectives.
- Own Riverside's Cybersecurity Maturity Model Certification (CMMC) program, ensuring continuous readiness for annual affirmations and Certified Third-Party Assessment Organization (C3
PAO) assessments. - Lead and mentor a team of GRC Analysts, establishing priorities, developing staff, and fostering a culture of accountability, collaboration, and continuous improvement.
- Develop, maintain, and govern enterprise cybersecurity policies, standards, procedures, and supporting documentation.
- Lead Riverside's Enterprise Risk Management (ERM) program by facilitating risk identification, assessment, mitigation planning, and executive reporting.
- Drive continuous monitoring activities through operational oversight, technical auditing, internal control assessments, and compliance reviews to ensure adherence to regulatory, contractual, and organizational security requirements.
- Manage corrective action plans, findings, Plans of Action & Milestones (POA&Ms), and remediation activities through closure.
- Provide governance oversight for cybersecurity programs including identity and access management, vulnerability management, configuration management, incident response, security awareness, external information sharing, third-party risk management, and data protection.
- Partner with Information Technology and Information Security teams to ensure enterprise architecture and technology solutions align with cybersecurity strategy, regulatory requirements, and organizational risk tolerance.
- Maintain awareness of evolving FAR, DFARS, CMMC, NIST, and Department of Defense cybersecurity requirements, advising leadership on regulatory changes and organizational impacts.
- Develop executive dashboards, metrics, and reports that communicate cybersecurity posture, enterprise risk, and compliance status to senior leadership.
- Collaborate with business stakeholders including Contracts, Human Resources, Finance, Legal, Marketing, and Business Operations to integrate cybersecurity governance into business processes.
- Serve as a trusted advisor to leadership by translating cybersecurity, compliance, and enterprise risk into actionable business recommendations.
Required Qualifications
- Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Information Assurance, Business, or a related discipline.
- Twelve (12) years of progressively responsible experience in cybersecurity, information assurance, governance, risk, compliance, or related disciplines, including at least three (3) years of leadership experience managing technical teams or enterprise cybersecurity programs.
- Demonstrated success leading external security assessments, regulatory audits, or certification efforts within a regulated industry such as the Defense Industrial Base, government contracting, financial services, healthcare, or telecommunications.
- Strong knowledge of Cybersecurity Maturity Model Certification (CMMC), NIST SP 800-171, Department of Defense Controlled Unclassified Information (CUI) requirements, and applicable FAR and DFARS cybersecurity clauses.
- Experience developing and maintaining cybersecurity governance programs, policies, standards, and enterprise compliance initiatives.
- Strong understanding of enterprise information technology including Microsoft 365, Microsoft Entra ,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).