Director; Governance, Risk & Compliance
Listed on 2026-10-10
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Cosm is seeking a seasoned Governance, Risk, and Compliance (GRC) professional to help lead and evolve our enterprise-wide security governance and risk management programs. Reporting to the Information Security Officer (ISO), you will define and operationalize GRC frameworks that ensure alignment with industry standards such as NIST CSF 2.0, SOX ITGC, and the Trusted Partner Network (TPN) content-security standard. You will operate and mature our enterprise risk register, oversee regulatory compliance, provide independent assurance over the controls that protect Cosm's platforms and creative content, and drive the policy development that strengthens our security posture and supports business growth, including our path toward IPO readiness.
As an early member of a growing Info Sec team, you will have the opportunity to shape the GRC function from the ground up, with room to grow as the team and program mature. This role is expected to build and lead the GRC function as the program scales, including hiring and developing the team that supports it. The ideal candidate brings a strong background in IT controls, audit readiness, and cross-functional collaboration, along with a passion for fostering a culture of accountability, security, and continuous improvement.
Responsibilities:Risk Management
- Operate and mature the enterprise cyber risk register, from initial population to a sustained program, including the inherent and residual scoring methodology
- Conduct business impact analyses to identify critical assets, systems, and processes and their tolerance for disruption, and use the results to inform asset criticality and risk prioritization
- Facilitate the executive risk review cycle: surface residual risks that exceed appetite, coordinate treatment versus acceptance decisions, and track risk owners and treatment plans to closure
- Maintain the risk appetite framework so that scoring, escalation thresholds, and exceeds-appetite triggers stay aligned to what the Audit Committee has approved, and support its annual review
- Provide independent verification of control design and operating effectiveness for controls implemented and operated by Engineering, Security Engineering, and IT, maintaining separation between those who build and operate controls and those who assure them
- Audit technical standards authored by Security Engineering, such as firewall and hardening baselines, against policy and framework requirements
- Own the control evidence program: ensure each control has an assigned owner and defined evidence, that collection happens on the required cadence, and that evidence remains current and audit ready
- Monitor evidence coverage and freshness across the control catalog, and drive remediation of missing, stale, or failing evidence ahead of audits
- Track control deficiencies to remediation and report residual exposure to leadership
- Track and ensure compliance with NIST CSF 2.0, SOX ITGC, TPN, and other applicable regulatory and contractual frameworks
- Plan and execute internal audits and reviews, and perform and document control testing
- Support external assessments and lead customer and partner security due diligence engagements
- Own the third-party security risk program end to end: intake, security review, risk rating, and ongoing monitoring across the vendor lifecycle
- Collect and review vendor and datacenter security attestations, tracking coverage and expiration
- Partner with Legal and Procurement to embed security requirements into vendor onboarding and contracts
- Author and maintain IT and security policies, and drive them through review, ratification, distribution, and tracked acknowledgment where they bind individuals, including contractors before access is granted
- Review technical standards authored by Security Engineering for policy alignment
- Manage the control catalog that maps Cosm's controls to its frameworks, and coordinate control ownership across the organization
- Monitor and report on the coverage and health of the control framework as risks, business needs, and regulatory requirements evolve
- Own the security awareness and role-based training program end to end: content, cadence, delivery, phishing simulation, and completion tracking
- Deliver role-specific training for administrators, privileged users, and developers
- Promote a culture of security and compliance across the…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).