GRC Lead / Cyber Risk Manager
On-siteWashington, District of Columbia, United States or Washington, United States
Job Summary
Lead and manage the enterprise GRC program, including policies, standards, and procedures. Serve as the primary advisor on cybersecurity risk and compliance matters, aligning strategy with business objectives and regulatory requirements. Conduct enterprise and system-level risk assessments, develop risk registers aligned to NIST SP 800-53 and 800-171, and define mitigation strategies. Ensure compliance with federal regulations for NIST RMF and FISMA, leading audit readiness efforts and coordinating internal/external audits. Oversee implementation of security controls, map frameworks including ISO 27001, and evaluate vendor third-party cybersecurity risks. Provide executive-level reporting on risk posture, compliance status, and remediation efforts. Requires CISSP, CISM, or CRISC certification and 8+ years of cybersecurity experience.
Required Qualifications
- Bachelor's degree in Cybersecurity, Information Technology, Risk Management, or related field
- 8+ years of experience in cybersecurity
- 3–5 years in GRC or risk management leadership roles
- Strong knowledge of NIST Cybersecurity Framework (CSF)
- Strong knowledge of NIST Risk Management Framework (RMF)
- Strong knowledge of NIST SP 800-53 / 800-171
- Experience supporting audits, compliance programs, and regulatory frameworks
- Proven ability to lead cross-functional teams and communicate with executive leadership
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- Certified in Risk and Information Systems Control (CRISC)
Desired Qualifications
- Certified Information Systems Auditor (CISA)
- Certified in Governance of Enterprise IT (CGEIT)
- ISO/IEC 27001 Lead Implementer or Lead Auditor
- CompTIA Security+ (for DoD 8570/8140 compliance environments)
- Experience with GRC tools (e.g., Archer, ServiceNow GRC)
- Strong understanding of risk quantification methodologies
- Experience with public sector or regulated environments
- Ability to translate technical risk into business impact
- Excellent written and verbal communication skills
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.