- Company Name
- Symmetrio
- Job Title
- GRC Manager
- Job Description
-
Job Title: GRC Manager
Role Summary: Lead the development, implementation, and continuous improvement of an enterprise‑wide Governance, Risk, and Compliance framework. Translate regulatory requirements into structured, automated processes that enhance policy management, audit readiness, risk modeling, and third‑party oversight.
Expectations: 5+ years of proven experience in GRC, IT audit, or cybersecurity program management. Demonstrated success implementing enterprise GRC platforms and aligning them with industry standards (NIST, ISO 27001, FISMA, FedRAMP). Strong analytical, communication, and stakeholder collaboration skills.
Key Responsibilities
- Design, develop, and roll out enterprise GRC solution, aligning policy, audit, and risk functions.
- Create integrated workflows for policy lifecycle, audit control assignment, evidence collection, testing automation, exception handling, and risk‑to‑control mapping.
- Build and maintain risk prioritization frameworks and Plans of Action & Milestones (POAMs).
- Develop vendor risk scoring models and third‑party oversight dashboards.
- Standardize templates, forms, and dashboards for system inventories, POAMs, and compliance documents.
- Define and maintain Security Minimum Baseline; map policies to frameworks (HIPAA, CJIS, IRS Pub 1075, PCI‑DSS).
- Collaborate with IT, audit, and security teams to integrate GRC workflows into enterprise platforms (ServiceNow, Archer, etc.).
- Analyze audit findings, identify control gaps, and lead corrective actions to strengthen compliance posture.
Required Skills
- Enterprise GRC framework implementation and platform management.
- Policy development, control documentation, and regulatory interpretation.
- Knowledge of NIST, ISO 27001, FISMA, FedRAMP and related control structures.
- Workflow design, risk modeling, and data-driven decision making.
- Strong written and verbal communication with cross‑functional teams.
Required Education & Certifications
- Bachelor’s degree in Information Security, Risk Management, Business Administration, or related field.
- Professional certifications preferred: CISSP, CRISC, CISA, or CGEIT.
---
Philadelphia, United states
Hybrid
Mid level
29-10-2025