×
Register Here to Apply for Jobs or Post Jobs. X

Director of Governance, Risk & Compliance

Remote / Online - Candidates ideally in
Los Angeles, Los Angeles County, California, 90079, USA
Listing for: Jobgether SRL
Remote/Work from Home position
Listed on 2026-10-04
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 140000 - 210000 USD Yearly USD 140000.00 210000.00 YEAR
Job Description & How to Apply Below

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Director of Governance, Risk & Compliance based in the United States.

This is a hands-on leadership opportunity to own and evolve an internal Governance, Risk & Compliance (GRC) program while overseeing Managed GRC services for clients. You will shape scalable methodologies, processes, evidence standards, and quality controls while remaining directly involved in complex compliance and security initiatives. The role combines executive-level advisory work with practitioner-level engagement, requiring close collaboration with CISOs, auditors, engineers, control owners, and technical teams.

A significant focus will be on federal security programs, including System Security Plans (SSPs), control implementation statements, evidence, POA&Ms, remediation, and responses to government or assessor findings. You will also guide risk assessments, audits, security questionnaires, and compliance programs across frameworks such as NIST, SOC 2, ISO 27001, CMMC, and HIPAA. The position offers the opportunity to lead and develop a growing GRC team while introducing automation and AI-enabled approaches that improve delivery, consistency, and scalability.

This is a remote U.S. role with the option to work from home or from a local U.S. office.

Accountabilities:
  • Own and mature the internal GRC program and lead the operational delivery of Managed GRC services, establishing standardized methodologies, processes, templates, evidence requirements, and quality controls.
  • Lead risk assessments, control assessments, compliance readiness activities, policy governance, managed audits, managed security questionnaires, and other GRC engagements while managing client commitments, priorities, capacity, quality, and service performance.
  • Lead federal compliance activities, including the development and maintenance of System Security Plans, control implementation statements, supporting evidence, POA&Ms, remediation plans, milestones, and responses to government, assessor, and auditor findings.
  • Coordinate with engineers, security teams, control owners, and clients to validate how security controls are implemented and ensure documented controls accurately reflect the operating environment.
  • Support requirements related to NIST SP 800-53, NIST SP 800-171, FISMA, CMMC, FedRAMP concepts, and agency-specific federal security requirements, including continuous monitoring, assessments, and authorization activities.
  • Manage cybersecurity risk and compliance programs covering risk registers, control gaps, treatment plans, exceptions, remediation tracking, SOC 2, NIST, CIS, ISO 27001, PCI DSS, HIPAA, CMMC, and Microsoft security benchmarks.
  • Oversee managed audit and security questionnaire methodologies, including audit readiness, evidence management, auditor coordination, findings, remediation, and reusable response and evidence libraries.
  • Partner with senior security leadership to operate and strengthen internal compliance initiatives, including SOC 2 Type 2, policy and control governance, third-party risk, customer security reviews, audit coordination, and evidence management.
  • Act as a senior GRC advisor to client security, IT, risk, compliance, and executive leaders, translating regulatory requirements into actionable technical and operational security improvements.
  • Collaborate with Security Operations, cloud, Microsoft 365, and engineering teams to map compliance requirements to technical implementations, with working knowledge of Azure, Entra , Defender, Sentinel, Intune, Purview, and Azure Policy.
  • Support vCISO engagements where governance, risk, audit, and compliance expertise is required, while partnering…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary