More jobs:
GRC Manager
Job in
Chicago, Cook County, Illinois, 60290, USA
Listed on 2026-02-16
Listing for:
SCIGON
Full Time
position Listed on 2026-02-16
Job specializations:
-
IT/Tech
Cybersecurity, Information Security
Job Description & How to Apply Below
GRC Manager - Security Governance
Salary: $179,000-$194,000
Role OverviewWe are seeking a strategic and hands‑on GRC Manager to lead key functions within our Security Governance program. In this role, you will oversee policy management, compliance operations, vendor risk, security awareness initiatives, and broader governance activities. You’ll guide a high‑performing team, partner with technical and business leaders, and drive continuous improvements that strengthen the organization’s security posture.
Key Responsibilities Program Strategy & Leadership- Define and deliver the GRC roadmap, ensuring clear objectives, measurable outcomes, and cross‑functional accountability.
- Report on program performance, risk trends, and compliance status to senior stakeholders.
- Develop, update, and manage security policies and standards.
- Review exception requests and ensure consistent enforcement across the organization.
- Monitor regulatory and industry changes, translating them into actionable guidance for leadership.
- Lead security awareness initiatives, including phishing simulations and training content development.
- Measure and improve program effectiveness through metrics and feedback loops.
- Coordinate and support SOC 2, ISO 27001, and client‑driven assessments.
- Manage third‑party risk evaluations and ensure appropriate remediation and documentation.
- Maintain enterprise risk registers, track mitigation efforts, and guide issue resolution.
- Lead internal control testing activities and partner with technical teams on corrective action plans.
- Bachelor’s degree preferred.
- Security certifications strongly preferred (e.g.,
CISSP
, CISM
, CISA
).
- 7+ years in information security or GRC roles, including 4+ years in leadership or hands‑on program ownership.
- Demonstrated experience running GRC programs, managing assessments, and overseeing technical control testing.
- Strong knowledge of frameworks such as ISO 27001
, NIST
, and SOC 2. - Ability to translate complex technical concepts for diverse audiences and act as a trusted advisor.
- Excellent writing skills for policy, training content, and technical documentation.
- Familiarity with GRC platforms, IAM, SIEM, encryption, vulnerability management, and analytics tools (e.g., Power BI, Tableau).
- Comfortable interacting with clients, handling inquiries, and supporting audit or assessment engagements.
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×