GRC Lead
- Location
- Houston, TX
- Work type
- Full Time · Hybrid
- Posted
- 2026-09-10
Job description
Position Details:
Monday-Friday, full time position
Hybrid (Defined as 4 days a week in office)
Office location is Houston, TX (Galleria)
Responsibilities
• Lead and mature the organization’s GRC program, including CMMC, GDPR, and other applicable regulatory, contractual, and customer requirements.
• Translate requirements into controls, policies, procedures, compliance roadmaps, and evidence-collection processes.
• Coordinate internal and external audits, assessments, certifications, customer questionnaires, remediation plans, and compliance reporting.
• Build and manage a third-party vendor-risk program, including vendor due diligence, risk assessments, security and privacy reviews, ongoing monitoring, and remediation tracking.
• Own the lifecycle of security, privacy, and compliance policies, including review, approval, publication, employee acknowledgment, training, and exception management.
• Develop executive dashboards and reports covering compliance posture, audit readiness, control effectiveness, vendor risk, and remediation progress.
• Partner with Legal, Privacy, Procurement, IT, Information Security, and business stakeholders to integrate GRC requirements into organizational processes.
• Support related programs such as security awareness, business continuity, incident-response governance, data protection, and customer security reviews.
• Lead or mentor GRC personnel and serve as the primary contact for auditors, assessors, vendors, customers, and internal stakeholders.
Requirements
• Professional certifications such as CISA, CRISC, CISSP, CISM, ISO 27001 Lead Implementer or Lead Auditor, CDPSE, CIPM, CIPP/US, CIPP/E, or similar.
• Experience supporting CMMC assessments or implementing controls aligned with NIST SP 800-171.
• Experience with privacy-impact assessments, data-protection impact assessments, or GDPR compliance programs.
• Familiarity with GRC, audit-management, vendor-risk-management, and workflow tools.
• Experience in a regulated industry, government contracting environment, SaaS organization, or other security-sensitive business environment.
• Experience leading or mentoring GRC analysts or cross-functional working groups.
• Bachelor’s degree in cybersecurity, information systems, business, risk management, law, or a related field; equivalent relevant experience considered.
• Three years of experience in governance, risk, compliance, information security, audit, privacy, or third-party risk management.
• Demonstrated experience leading compliance programs, audits, risk assessments, or control implementation efforts.
• Working knowledge of CMMC, GDPR, and common security or privacy frameworks such as NIST CSF, NIST SP 800-171, NIST SP 800-53, ISO 27001, SOC 2, CIS Controls, PCI DSS, HIPAA, or similar standards as applicable.
• Experience designing or operating a third-party risk-management program.
• Experience managing policies, control documentation, audit evidence, and remediation activities.
• Strong project-management skills, including the ability to prioritize competing compliance initiatives and drive cross-functional accountability.
• Exceptional written, verbal, and stakeholder-management skills.
• Ability to communicate risk and compliance requirements effectively to both technical and non-technical audiences.
• High degree of integrity, judgment, discretion, and attention to detail.