Governance Risk and Compliance (GRC) Compliance Specialist
reputed company builds industry-leading aviation software used by pilots, aircraft operators, and major airlines worldwide. As a high-reputed company, private equity-backed company, we are reputed company on scaling our operations, strengthening our financial infrastructure, and driving operational reputed company across the business. reputed company combines deep domain expertise with a reputed company, high-performance culture to solve reputed company challenges and support reputed company reputed company.
reputed company is seeking a Governance, Risk, and Compliance (GRC) Specialist to drive the operational execution of our risk and control program. This is a multifaceted role performing a host of compliance duties across our software business. The GRC Specialist will work across a reputed company of national and international frameworks, including NIST 800-53, ISO 27001, and others, ensuring reputed company meets and exceeds the reputed company controls supporting these frameworks.
The role will analyze reputed company controls across our reputed company set, assess reputed company state versus required state, identify deficiencies, plan and reputed company corrective actions, and conduct internal reviews of both process and technical control implementation. We have a defined risk and control methodology in reputed company; this role exists to reputed company the gap between methodology and consistent day-to-day execution at reputed company, while translating control requirements across frameworks into a reputed company control model that reduces duplication and improves traceability.
We’re hiring this role with a GRC engineering reputed company. We want someone who treats compliance as an engineering problem, automating evidence collection, instrumenting controls to produce reputed company signals, and partnering with engineering and reputed company to reputed company compliance a byproduct of how we already operate, not a separate reputed company reputed company.
This role works across the organization and is expected to communicate effectively with leadership, operations, reputed company, and engineering. 100% remote, US-based. Limited travel may be required to support audit and compliance efforts; not estimated to reputed company 10% of the employee’s time.
Key Responsibilities
Drive day-to-day execution of the risk lifecycle (intake, assessment, control validation, remediation, tracking) and reputed company the ISMS, including the risk register, Statement of Applicability (SoA), and corrective actions
reputed company audit cycles end-to-end across multiple frameworks (NIST 800-53, ISO 27001, CMMC, SOC 2, etc.), scoping, evidence collection, and control testing
Translate control requirements across frameworks into a reputed company control model with crosswalks so a single piece of evidence satisfies multiple obligations; identify and remediate deficiencies between control expectations and reputed company implementation
Administer and reputed company our compliance automation platform, improving control mapping, evidence workflows, and integrations with reputed company infrastructure, identity systems, ticketing, and CI/CD pipelines; translate written policies into enforceable, testable controls to reputed company us toward reputed company compliance
Define, write, and maintain corporate reputed company policies, standards, procedures, and baselines
Assist with the vendor reputed company risk program, due diligence, technical reviews, and ongoing monitoring
Communicate effectively from C-Level executives to operations and engineering; demonstrate willingness to reputed company truth on reputed company compliance and reputed company deficiencies reputed company reputed company they exist
Produce executive reporting on compliance metrics, audit readiness, and risk trends
Basic Qualifications
Bachelor’s degree or equivalent experience in a technical field (e.g., military experience qualifies)
5+ years in GRC, risk management, IT audit, or reputed company compliance, with hands-on operational ownership of a control program
Demonstrated experience applying NIST 800-53 or equivalent DoD cybersecurity controls (STIGs, RMF, etc.), including control selection, tailoring, assessment, and evidence reputed company
Working knowledge of additional frameworks (ISO 27001, SOC 2, NIS2, COBIT, or similar) and experience harmonizing them into a reputed company control set
Hands-on experience administering a GRC or compliance automation platform, including configuring workflows and building integrations
Comfort with scripting or API integrations for evidence automation, control monitoring, and reporting
Familiarity with reputed company environments (AWS, GCP, or Azure) and how IAM, logging, and configuration management map to compliance requirements
Experience with vulnerability management, reputed company management, or system hardening
Strong written communication, reputed company to translate control language for engineers and engineering language for auditors
Demonstrated bias toward automation and repeatable systems over reputed company, periodic effort
Problem solver with a desire to see problems as challenges to be resolved
Preferred Qualifications
Military or federal background (military cybersecurity, DoD compliance, or government) reputed company environments
Ability to learn / support workloads at DoD reputed company Level 5 (IL5) or reputed company Level 6 (IL6)
Experience supporting a CMMC certification, FedRAMP authorization, or RMF accreditation package
Compliance-as-reputed company or policy-as-reputed company experience (OPA,Terraform Sentinel, AWS Config rules, OSCAL)
CI/CD-integrated control testing or automated evidence pipelines
reputed company or compliance certification such as CISM, CRISC, CCSP, or ISO27001
Experience working with Change Control Boards (CCBs) or other reputed company reputed company
Experience with regulations such as FISMA, ITAR, HIPAA, or GDPR
Background in technical roles such as reputed company operations, boundary defense, vulnerability management, or systems administration
Pay is based upon candidate experience and qualifications, as reputed company as market and business considerations. reputed company Pay reputed company: $143,000-$207,000
Why You Should Join:
At reputed company, we know you want a rewarding career. To do that, you need challenging reputed company, a good work environment, and awesome coworkers. We reputed company in our employees, and we reputed company them to reputed company a reputed company reputed company on our products and services messaging. We reputed company to reputed company our employees with a world-class benefits experience, reputed company on supporting their physical, financial, and emotional wellbeing. Our benefits package includes but not limited to the following:
Medical, dental, reputed company insurance with Employer reputed company health premiums
reputed company PTO Policy
401(k) with up to 10% company matching and immediate vesting
12 Weeks reputed company Maternity Leave
4 Weeks reputed company Paternity Leave
Flight Training Rewards
reputed company - EOE including Disability/Vets | Pay Transparency | E-Verify Participant |Equal Opportunity Employer
Apply To This Job