×
Register Here to Apply for Jobs or Post Jobs. X

GRC Team Lead

Job in Richmond, Henrico County, Virginia, 23214, USA
Listing for: Captech-Consulting
Full Time position
Listed on 2026-07-17
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 90000 - 150000 USD Yearly USD 90000.00 150000.00 YEAR
Job Description & How to Apply Below
  • Compensation: USD 90,000 - USD 150,000 - yearly
Company Description

Cap Tech is an award-winning consulting firm that collaborates with clients to achieve what’s possible through the power of technology. At Cap Tech, we’re passionate about the work we do and the results we achieve for our clients. From the outset, our founders shared a collective passion to create a consultancy centered on strong relationships that would stand the test of time.

Today we work alongside clients that include Fortune 100 companies, mid-sized enterprises, and government agencies, a list that spans across the country.

Job Description

The Information Security GRC Team Lead leads Cap Tech’s Governance, Risk, and Compliance (GRC) function, helping set the strategy and owning the execution, and continuous improvement of the programs that keep Cap Tech and our clients secure and compliant. This is a hands‑on leadership role: you will lead and mentor a GRC analyst while remaining personally engaged in the work, running assessments, engineering automation, and setting technical direction.

You will own Cap Tech’s compliance posture across SOC 2, NIST 800‑53, and NIST AI RMF, along with applicable privacy regulations; mature our third‑party risk management program; modernize the GRC function through automation and GRC engineering; and establish the governance practices that allow Cap Tech to adopt AI safely. This position reports to the Head of Information Security and operates with a high degree of autonomy to make decisions and set direction with minimal oversight.

Key Responsibilities:

Leadership & Team Management
  • Lead, mentor, and develop a GRC analyst, setting priorities, coaching for growth, and serving as the escalation point for complex risk and compliance matters.
  • Operate as a player‑coach: remain hands‑on in assessments, engineering, and analysis while coordinating the team’s day‑to‑day execution and quality.
  • Help set the strategic direction and roadmap for the GRC program, driving initiatives to completion and making decisions independently with minimal oversight.
  • Define goals, metrics, and quality standards for the team; provide input into performance reviews and team goals; and participate in hiring, onboarding, and career development.
  • Report on risk and compliance posture to executive leadership, translating technical risk into business terms for non‑technical stakeholders.
  • Own and mature Cap Tech’s compliance programs across SOC 2, NIST 800‑53, and NIST AI RMF, ensuring controls are well‑designed, operating effectively, and continuously monitored.
  • Extend the compliance program to applicable privacy and regulatory obligations, including HIPAA and GDPR/CCPA, as driven by Cap Tech’s client base.
  • Lead internal control assessments, gap analyses, and audit‑readiness activities; manage external audits and coordinate evidence collection end to end.
  • Develop, maintain, and enforce the information security policy suite, partnering with policy owners to keep documentation current and aligned to controls.
  • Identify, assess, and prioritize information security risks; drive remediation to closure against SLAs, negotiating compensating controls with stakeholders where appropriate.
Third‑Party Risk Management
  • Own and enhance the Third‑Party Risk Management (TPRM) framework, policy, process, and supporting technology in alignment with SOC 2 requirements.
  • Oversee technical risk evaluations and due diligence of third‑party vendors, tools, and services, and recommend actions to strengthen vendor security posture.
  • Lead responses to inbound client and partner security questionnaires, and support business development and contract‑negotiation teams to ensure security terms align with RFPs and agreed contracts.
  • Own and administer Cap Tech’s GRC / compliance‑automation platform, driving continuous control monitoring and automated evidence collection.
  • Design and build workflow automations and integrations across security, IT, and compliance tooling to reduce manual effort, improve data quality, and accelerate audit readiness.
  • Instrument GRC metrics, dashboards, and reporting so that control health and risk posture are continuously visible to stakeholders.
AI…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary