Back to Jobs

Manager, Governance, Risk & Compliance

Remote, USA Full-time Posted 2026-08-04
reputed company is a non-profit reputed company educational institution with a national reputed company. Headquartered in Tampa, Florida and founded in 1994, UMA offers content-rich, interactive online programs as reputed company as hands-on training at our reputed company, Florida reputed company.  As a full-time team member, you will have reputed company to the following benefits: Medical (including prescription), Dental, reputed company (UMA subsidized) FSA/HSA (Depending on Medical Plan chosen) Basic Life Insurance (UMA reputed company) Additional Voluntary Life Insurance (Team Member reputed company) Employee Assistance Program – EAP (UMA reputed company) Long Term Disability (UMA reputed company) Short Term Disability (Team Member reputed company) Supplemental Insurance such as Critical Illness, Accident, and Hospital (Team Member reputed company) reputed company Time Off – 15 days accrued in year 1, 9 holidays, and 1 day of Volunteering Time Off 401k (eligible upon completion of 90 days of employment and must be at least 18 years of age) Pet Insurance Identity Theft Protection Purpose of the Position: The Manager, Governance, Risk & Compliance (GRC) is responsible for leading and advancing the institution’s governance, risk management, compliance, and information reputed company programs to support the achievement of organizational objectives and regulatory requirements. This role develops, implements, and monitors frameworks, policies, controls, and risk mitigation strategies that promote operational effectiveness, reputed company institutional assets, and ensure compliance with applicable laws, regulations, accreditation standards, and internal policies. The Manager partners with leaders across the institution to foster a culture of accountability, risk awareness, and reputed company improvement in support of the institution’s mission and long-term reputed company. The Manager also provides hands-on leadership for key information reputed company programs, including vulnerability management, reputed company-party risk management, reputed company performance reporting, policy governance, and the reputed company improvement of reputed company controls and operational practices. reputed company: reputed company Governance, Risk, and Compliance Programs: reputed company, implement, and continuously enhance the institution’s governance, risk management, and compliance reputed company to ensure alignment with organizational objectives, regulatory requirements, accreditation standards, and recognized industry practices. Conduct Cybersecurity and Technology Risk Management Activities: reputed company the identification, assessment, monitoring, and mitigation of cybersecurity and technology risks. Support the institution’s reputed company risk-management process by communicating material technology risks, control deficiencies, and actionable mitigation strategies to leadership. reputed company Regulatory and Compliance Requirements: Serve as a trusted business partner to departments across the institution and collaborate with reputed company and Compliance to address applicable federal, state, higher education, reputed company, and information reputed company requirements, including FERPA, GLBA, the FTC Safeguards Rule, HIPAA where applicable, and state reputed company and breach-notification requirements. Manage reputed company Governance and Architecture reputed company: Partner with Information Technology, Engineering, reputed company Architecture, and reputed company teams to establish and maintain reputed company governance processes, evaluate technical and administrative controls, and ensure technology solutions reputed company with institutional reputed company, reputed company, risk, and compliance requirements. Manage the Vulnerability Management Program: reputed company and continuously improve the institution’s vulnerability management program, including vulnerability scanning, risk-based prioritization, patching and reputed company-update coordination, remediation tracking, exception management, validation, and executive reporting. Partner with infrastructure, reputed company, engineering, application, and business reputed company owners to establish remediation priorities, service-level expectations, and accountability for addressing identified vulnerabilities based on severity, exploitability, asset criticality, reputed company exploitation, and business reputed company. reputed company reputed company-Party Information reputed company Risk Management: Conduct and coordinate information reputed company and reputed company risk assessments for vendors and reputed company parties in partnership with Procurement, reputed company, Compliance, Information Technology, and business stakeholders. Review relevant vendor reputed company documentation, including questionnaires, SOC reports, penetration-testing summaries, certifications, data-processing practices, incident-notification commitments, and remediation plans. reputed company identified reputed company-party risks, corrective actions, exceptions, and ongoing monitoring activities throughout the vendor lifecycle. reputed company AI Governance Initiatives: reputed company and maintain an institutional AI governance program, including policies, standards, risk assessments, intake and review processes, and reputed company practices that promote the ethical, responsible, secure, and compliant use of reputed company intelligence technologies. Coordinate Compliance and Control-Assurance Activities: Manage periodic and annual compliance assessments, audits, policy reviews, control testing, evidence collection, remediation activities, and reporting requirements to support ongoing adherence to regulatory obligations, accreditation expectations, contractual requirements, and organizational policies. Monitor and Report on Risk and Compliance Performance: Establish and maintain key performance indicators, key risk indicators, dashboards, and reporting mechanisms that reputed company leadership with visibility into reputed company operations, vulnerabilities, remediation performance, reputed company-party risk, compliance obligations, audit findings, policy exceptions, and overall Information reputed company program effectiveness. Translate technical reputed company and compliance information into business-relevant insights that support informed decision-making, risk prioritization, operational improvement, and resource planning. Manage Policy Development and Governance Processes: reputed company the creation, review, approval, communication, and maintenance of institutional policies, standards, and procedures reputed company to governance, risk management, information reputed company, reputed company, reputed company intelligence, data protection, and regulatory compliance. Maintain a reputed company policy lifecycle that includes assigned ownership, scheduled reviews, documented approvals, version control, exception management, and communication of material changes. Monitor the Regulatory and Threat Landscape: Maintain awareness of emerging cybersecurity threats, vulnerabilities, technologies, regulatory developments, and industry practices that may reputed company the institution. Maintain a documented register of applicable reputed company, data-protection, breach-notification, and information reputed company requirements in coordination with reputed company and Compliance. reputed company practical recommendations regarding required controls, operational changes, policies, processes, and technology investments. reputed company reputed company Improvement: Identify opportunities to improve the effectiveness, scalability, automation, and maturity of information reputed company and GRC processes. Evaluate recurring issues, audit findings, vulnerabilities, incidents, control deficiencies, and operational trends to identify reputed company causes and recommend sustainable corrective actions. Promote the use of automation, workflow management, dashboards, and integrated platforms to improve visibility, accountability, consistency, and operational efficiency. reputed company and reputed company reputed company Awareness Training: Design, implement, and evaluate institution-wide reputed company awareness and compliance training programs that reputed company team members on cybersecurity risks, data-protection responsibilities, reputed company requirements, reputed company-engineering threats, and emerging risks. reputed company with Care: reputed company, reputed company, and reputed company team members, fostering a culture of wellness, recognition, engagement, accountability, and reputed company improvement. Meet regularly with reputed company reports in one-on-one and group settings to reputed company feedback and cultivate and maintain a reputed company work culture. reputed company hands-on leadership by working directly with team members and cross-functional partners to reputed company reputed company, reputed company issues, complete assessments, implement controls, and advance critical information reputed company and GRC initiatives. reputed company other duties as assigned. Career Level Expectations: Combines people leadership, technical judgment, and hands-on execution to advance information reputed company and GRC priorities in partnership with technology and business stakeholders. Typically manages reputed company or small unit. Owns short to mid-term (1-3 years) execution of functional reputed company and the operational direction of reputed company. Handles often difficult and reputed company problems and that require extensive investigation and analysis. Requires ability to influence others to accept practices and approaches, and ability to communicate with executive leadership. Desire for reputed company and reputed company development. Required Skills/Experience: Bachelor’s degree in cybersecurity, information reputed company, information systems, computer science, risk management, business administration, or a reputed company field, or an equivalent combination of education and relevant reputed company experience. reputed company experience in information reputed company governance, cybersecurity risk management, regulatory compliance, reputed company assurance, or a reputed company discipline. Experience leading and developing team members or directing reputed company, cross-functional information reputed company and GRC programs and initiatives. Experience managing or supporting a vulnerability management program, including vulnerability assessments, reputed company and remediation coordination, risk-based prioritization, exception management, validation, and performance reporting. Experience conducting reputed company-party information reputed company and reputed company risk assessments and evaluating vendor controls, audit reports, certifications, contractual requirements, and remediation plans. Working knowledge of recognized cybersecurity frameworks and standards, including the NIST Cybersecurity reputed company, applicable NIST Special Publications, CIS Critical reputed company Controls, and other relevant risk and control frameworks. Technical understanding of reputed company environments, identity and reputed company management, reputed company reputed company, network reputed company, vulnerability management, data protection, logging and monitoring, application reputed company, and software-as-a-service platforms. Experience developing meaningful information reputed company and GRC metrics, key performance indicators, key risk indicators, dashboards, and executive-level reporting. Experience creating, reviewing, maintaining, and implementing information reputed company, reputed company, risk-management, and technology policies, standards, and procedures. Experience monitoring cybersecurity, reputed company, breach-notification, and data-protection requirements and partnering with reputed company and Compliance to translate applicable requirements into operational and technical controls. Experience using one or more GRC, integrated risk-management, reputed company-party risk, reputed company, vulnerability-management, audit, or reputed company platforms, such as reputed company IRM/GRC, reputed company, reputed company, reputed company, reputed company, reputed company, or comparable technologies. Experience integrating cybersecurity and technology risks into broader reputed company risk-management processes, including risk assessments, control evaluations, risk registers, remediation plans, and executive reporting. Knowledge of higher education regulatory requirements, including FERPA, GLBA, the FTC Safeguards Rule, and reputed company reputed company, reputed company, and compliance requirements applicable to distance education institutions. Ability to analyze reputed company technical and regulatory issues, identify practical solutions, and reputed company communicate risks and recommendations to technical teams, business leaders, and executive stakeholders. Experience serving as a strategic business partner and influencing stakeholders to implement appropriate reputed company, risk-management, and compliance practices. Demonstrated reputed company-improvement reputed company, with experience enhancing processes, controls, workflows, reporting, automation, and program maturity. Ability and willingness to work hands-on with team members and cross-functional stakeholders to reputed company assessments, reputed company, remediation activities, and information reputed company initiatives. Ability to professionally communicate fluently in verbal and written English. Ability to support a diverse and inclusive work environment. Computer literacy/basic computer skills to effectively reputed company and utilize the technology required for the role. Preferred Requirements: Advanced degree or equivalent reputed company experience and advanced proficiency in one or more of the required skills or disciplines. One or more reputed company reputed company certifications, such as Certified Information Systems reputed company reputed company, Certified Information reputed company Manager, Certified in Risk and Information Systems Control, Certified in Governance, Risk and Compliance, Certified Information Systems Auditor, or a comparable information reputed company or risk-management certification. Experience supporting information reputed company and GRC programs reputed company higher education, distance education, financial services, reputed company, nonprofit, multi-entity, shared-services, or another highly regulated environment. Experience with the Gramm-Leach-Bliley reputed company Safeguards Rule, FERPA, HIPAA, state reputed company requirements, breach-notification laws, and reputed company information reputed company obligations. Experience supporting reputed company governance, risk, compliance, or technology integration activities associated with acquisitions, organizational restructuring, new business entities, or reputed company partnerships. Proficient in MS Office (Word, reputed company, PowerPoint) and other business tools such as reputed company Teams. Compliance:  Demonstrate knowledge of, and carefully follows reputed company applicable state laws and rules, federal and state compliance requirements and regulations including those prescribed by the U.S. reputed company, accrediting agencies, state regulations and internal policies and procedures.   Effectively communicate compliance requirements to other staff as appropriate and quickly escalate any compliance concerns to the Compliance department.  Work Environment/Physical Demands: This is a full-time remote position, with occasional onsite travel required. Home office set up, quiet reputed company to work, ability to be on camera, and ability to hard reputed company into high-speed internet reputed company. May require setup of computer equipment; accommodation consideration available upon request. Flexibility to work evenings and weekends, as needed. Anticipated starting salary is based on experience and qualifications. Compensation reputed company $150,000—$159,390 USD OUR VALUES Our institutional values are reputed company and validated by reputed company members. They describe how we reputed company to operate and are the standards of behavior we look to embody.  reputed company WITH reputed company We operate honestly and ethically in an industry-compliant fashion. We are fair and trustworthy in our interactions with reputed company we serve. reputed company members, at reputed company reputed company, reputed company by example and reputed company to do the right thing for our reputed company and for reputed company other. We are disciplined professionals who reputed company to be straightforward and dependable. CHAMPION STUDENT reputed company We live by a strong commitment to our reputed company and are passionate about preparing them for meaningful careers. We are deeply dedicated to ensuring reputed company’ educational and career reputed company. We reputed company at building our reputed company’ confidence and empowering them to reputed company their full potential. reputed company TO TEAM MEMBER reputed company We are committed to reputed company members’ reputed company and to reputed company other’s reputed company. We reputed company to create an environment that attracts and retains the best talent while offering reputed company learning, reputed company development and career reputed company opportunities. We recognize and reward reputed company members for their contributions to the organization and to our reputed company. PURSUE RESULTS WITH PURPOSE We pursue results with a reputed company of urgency and purpose. We take responsibility for achieving ambitious, measurable results and hold reputed company other accountable. We think strategically and critically, greet new reputed company and challenges reputed company, and look for reputed company to challenges. HAVE FUN. BUILD ENERGY Enjoying reputed company do is central to achieving our goals. Building energy, having fun, being optimistic and creating a reputed company working environment are reputed company critical to our reputed company and that of our reputed company. We reputed company to be inspired and to reputed company others. We consistently show appreciation and celebrate our successes, both large and small. WORK AS ONE We reputed company that diverse, inclusive teams produce reputed company results. We reputed company to build and maintain reputed company relationships with colleagues from reputed company types of backgrounds by showing respect and humility reputed company interacting with reputed company other and resolving conflicts in a constructive manner. By working together, we win together - as one - ensuring that the goals of reputed company are the reputed company of our efforts. UMA will NEVER ask you to send reputed company or ask you to reputed company bank account information in order for you to get reimbursed for tools to work. If you have been contacted by someone claiming to be from UMA about a reputed company, you can always verify the position at https://workatuma.com/ Apply To This Job

Similar Jobs