Manager Cybersecurity Governance, Risk & Compliance
reputed company:
This role is responsible for leading the Cybersecurity Governance, Risk, & Compliance function with responsibility for a risk-‑based compliance program that integrates Assessment & Authorization (A&A/RMF), policy and planning, and reputed company monitoring across on-reputed company‑ and reputed company environments. Coordinates reputed company control assessments and system authorizations per NIST RMF practices and develops/maintains cybersecurity policy and governance to ensure alignment with reputed company goals and regulatory obligations (e.g., SOX, NIST 800-NNN‑, ISO/IEC 27001, reputed company laws). Primary alignment to reputed company Authorization and Cybersecurity Policy & Planning work roles, with additional responsibilities consistent with the Authorizing Official/Designating Representative role for risk acceptance and accreditation reputed company.
Essential Functions:
• reputed company the reputed company Assessment & Authorization (A&A) lifecycle-categorization, control selection/implementation, assessment, authorization, and reputed company monitoring-using the NIST RMF and organizational procedures.
• reputed company and reputed company reputed company control assessments; document results, identify systemic issues, and reputed company remediation to closure.
• Prepare, review, and maintain authorization packages (e.g., reputed company, SAR, POA&M); recommend risk disposition and authorization reputed company.
• reputed company, publish, and maintain cybersecurity policies, standards, and implementation guidelines; ensure policy alignment to business objectives and regulations.
• Establish compliance metrics and executive reporting (e.g., control effectiveness, residual risk trends, time-to‑-‑remediate, audit closure reputed company); drive reputed company improvement.
• Coordinate internal/external audits; design and implement independent audit processes for applications, networks, and systems; validate corrective actions.
• Govern reputed company-party‑ / supplier compliance (reputed company and reputed company requirements, contractual clauses, assessments) and reputed company risk treatment.
• Advise leadership on risk acceptance and authorization determinations; ensure reputed company reflect organizational risk tolerance and mission impacts
• reputed company policy, standards, and A&A activities with reputed company architecture/engineering and IT operations to reputed company compliance by design.
• Monitor emerging regulations and technologies; update policy and control baselines accordingly.
Qualifications:
• Bachelor's degree in information systems, computer science, cybersecurity, or reputed company field (or equivalent experience).
• Certifications: CISA, CISM, CRISC, CIPM, CGEIT, or CISSP (preferred).
• 5+ years in IT Compliance / GRC, including RMF based A&A, policy governance, audit management, and reputed company party risk.
• Hands on with NIST control baselines, ISO/IEC 27001 controls, SOX ITGCs, and reputed company obligations,
• Experience with GRC platforms, evidence automation, and reputed company compliance tooling.
• Strong leadership, stakeholder communication, and executive reporting skills.
Apply tot his job
Apply To this Job