Manager, Governance, Risk & Compliance

11 hours, 38 minutes ago
Full-time
Lead
Cybersecurity
Universal Martial Arts Academy

Universal Martial Arts Academy

UMA Global Network for Education, Research and Innovation. UMA is an international multidisciplinary organization dedicated to excellence in higher education, research, professional development, media, and community advancement. With more than 25 year...

Education Services
Founded 1989

Description

  • Lead and continuously improve governance, risk management, compliance, and information security frameworks.
  • Identify, assess, monitor, and mitigate cybersecurity and technology risks, including reporting material risks to leadership.
  • Partner with Legal, Compliance, IT, Engineering, and business teams on regulatory and security requirements.
  • Oversee the vulnerability management program, including scanning, prioritization, remediation tracking, exceptions, validation, and reporting.
  • Conduct and coordinate third-party information security and privacy risk assessments and ongoing vendor monitoring.
  • Develop and maintain AI governance policies, standards, intake processes, and oversight practices.
  • Manage compliance assessments, audits, policy reviews, control testing, evidence collection, and remediation activities.
  • Build dashboards, KPIs, KRIs, and executive reporting on security, risk, compliance, and audit performance.
  • Lead policy development and governance for security, privacy, data protection, AI, and compliance documents.
  • Develop and deliver security awareness and compliance training programs.
  • Coach and develop team members while providing hands-on support for projects, assessments, and remediation efforts.

Requirements

  • Bachelor’s degree in cybersecurity, information security, information systems, computer science, risk management, business administration, or related field, or equivalent experience.
  • Progressive experience in information security governance, cybersecurity risk management, regulatory compliance, or security assurance.
  • Experience leading people or directing complex, cross-functional GRC or information security programs.
  • Experience managing a vulnerability management program, including assessments, patching, remediation coordination, and reporting.
  • Experience conducting third-party security and privacy risk assessments and evaluating vendor controls, certifications, and remediation plans.
  • Working knowledge of the NIST Cybersecurity Framework, NIST Special Publications, CIS Critical Security Controls, and similar frameworks.
  • Technical understanding of cloud, IAM, endpoint security, network security, data protection, logging and monitoring, application security, and SaaS platforms.
  • Experience creating GRC metrics, KPIs, KRIs, dashboards, and executive-level reporting.
  • Experience developing and implementing security, privacy, risk, and technology policies and procedures.
  • Experience using GRC, third-party risk, privacy, vulnerability-management, audit, or security tools such as ServiceNow IRM/GRC, OneTrust, LogicGate, Tenable, Qualys, or Rapid7.
  • Knowledge of higher education regulations, including FERPA, GLBA, the FTC Safeguards Rule, and related privacy/security requirements.
  • Ability to communicate complex technical and regulatory issues clearly to technical and executive stakeholders.
  • Ability to communicate fluently in verbal and written English and support a diverse, inclusive work environment.
  • Preferred: advanced degree or equivalent experience and one or more certifications such as CISSP, CISM, CRISC, C|GRC, or CISA.
  • Preferred: experience in higher education, distance education, financial services, healthcare, nonprofit, or other highly regulated environments.
  • Preferred: proficiency with MS Office and Microsoft Teams.
  • Full-time remote work with occasional onsite travel, plus flexibility to work evenings and weekends as needed.

Benefits

  • Medical, dental, and vision insurance with UMA subsidy.
  • FSA/HSA options depending on medical plan selection.
  • Basic life insurance, employee assistance program, long-term disability, and 401(k) eligibility after 90 days.
  • Paid time off includes 15 days in year 1, 9 holidays, and 1 volunteer day.
  • Optional coverage and perks including voluntary life, short-term disability, supplemental insurance, pet insurance, and identity theft protection.
  • Anticipated starting salary of $150,000 to $159,390 USD, based on experience and qualifications.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Infringement Manager

DistroKid 251-1K Media

DistroKid is hiring an Infringement Manager to lead its infringement operations team handling copyright, trademark, and impersonation claims across the platform.

Confluence
10 hours, 53 minutes ago

Principal, Policy Development

GoFundMe 251-1K Capital Markets

GoFundMe is hiring a Principal, Policy Development to shape Trust & Safety policies that govern fraud, identity, content, and platform conduct across a large social fundraising platform.

Machine Learning
11 hours, 23 minutes ago

Compliance Associate (Junior)

D.A. Davidson Companies 1K-5K Capital Markets

D.A. Davidson Companies is seeking a Compliance Associate to support branch examinations, AML compliance, and day-to-day regulatory oversight across its financial services business.

11 hours, 52 minutes ago

Sr. Insider & Data Risk Analyst

Alpaca 51-250 Capital Markets

Alpaca is hiring a Senior Insider & Data Risk Analyst to lead insider risk investigations and strengthen data loss prevention and risk management across its global brokerage infrastructure.

AWS Azure Cybersecurity Elasticsearch GCP Python SIEM Splunk SQL
1 day, 10 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers