Manager, Governance, Risk and Compliance

4 weeks, 1 day ago
Full-time
Senior
Cybersecurity
Path Robotics

Path Robotics

Path Robotics creates truly autonomous robots for manufacturing, eliminating the need for skilled welders or robot programmers and allowing humans to focus on creativity.

Automotive
51-250
Founded 2014
$71M raised

Description

  • Build and lead the Cybersecurity GRC program from early stages through full service maturity.
  • Provide hands-on day-to-day management of GRC operations.
  • Manage projects across governance, risk, and compliance disciplines.
  • Develop, implement, and enforce policies, procedures, and programs that reduce risk.
  • Design and execute testing plans to verify policy, control, and regulatory compliance.
  • Conduct internal risk assessments, maintain the risk register, and coordinate remediation efforts.
  • Evaluate testing results, track control gaps to closure, and perform follow-up testing.
  • Conduct third-party risk assessments for vendors.
  • Report risk and compliance status regularly to committee members and leadership.
  • Support certification and compliance programs for ISO 27001, NIST 800-171/CMMC Level 2, and FedRAMP Moderate.
  • Own and manage GRC tooling for tracking, documentation, and reporting.
  • Advise internal teams on control improvements, audit readiness, and compliance requirements.
  • Monitor changes in laws, regulations, and frameworks and communicate updates to control owners.

Requirements

  • Bachelor’s degree in business, finance, information management, or a related field.
  • 3+ years of experience leading IT risk management, IT compliance, or audit functions.
  • 3+ years of experience working with regulatory compliance requirements such as CMMC, FISMA, GLBA, HIPAA, or SOx.
  • 5+ years of experience assessing and meeting framework control requirements such as NIST 800-53, NIST CSF, CIS, or CSA.
  • Professional certifications in two or more of the following preferred: CISSP, CISA, CISM, CGRC, CRISC, GRCP, or ISO 27001 Lead Implementer/Lead Auditor.
  • Experience supporting cloud environments such as AWS, Azure, or GCP in regulated or government-focused environments.
  • Proven track record of building GRC programs from the ground up and scaling them with business growth.
  • Experience supporting ISO 27001, CMMC Level 2, and FedRAMP compliance audits is preferred.

Benefits

  • Daily free lunch.
  • Flexible PTO.
  • Comprehensive medical, dental, and vision coverage.
  • 6 weeks fully paid parental leave, plus an additional 6–8 weeks for birthing parents.
  • 401(k) retirement plan through Empower.
  • Generous employee referral bonuses.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Technical Program Manager (TPM)

Armada 201-500 information technology & services

Armada is hiring a remote Technical Program Manager to coordinate complex infrastructure and hardware programs across engineering, construction, operations, IT, and commercial teams.

Agile
16 hours, 13 minutes ago

Analyst, Regulatory Affairs

Oscar 1K-5K Insurance

Oscar is hiring an Analyst, Regulatory Affairs to support the Evidence of Coverage team with regulatory filing coordination and related work for its health insurance operations.

16 hours, 13 minutes ago

TMF Lead II (LATAM)

Precision For Medicine 1K-5K Pharmaceuticals

Precision Medicine Group is seeking an experienced Trial Master File Lead II to help establish a new LATAM regional function and maintain high-quality study TMFs across multiple clinical projects.

16 hours, 13 minutes ago

PXM Delivery Consultant

Valtech 5K-10K Professional Services

Valtech is hiring a PXM Business Consultant / Delivery Consultant in Canada to support retail and apparel clients by translating business needs into data models and deliverables for product experience management work.

Agile ERP SAP
16 hours, 28 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers