Manager, Security Governance Risk and Compliance (GRC) - Tampa, FL

Posted 2 months ago
Job closed
Tuple

Manager, Security Governance Risk and Compliance (GRC) - Tampa, FL

Our Client - company

  • Tampa, FL
$110,000 - $130,000/year
Exact compensation may vary based on skills, experience, and location.
40 hrs/wk
Permanent (w2)
Remote work no
Travel not required
Start date
May 12, 2025
Superpower
Finance, Legal, Technology
Capabilities
Compliance
Regulatory
IT Security and Governance
Preferred skills
Scalability
Tool Management
Risk Management
Security Requirements Analysis
Risk Mitigation
Risk Governance
Certified In Risk And Information Systems Control
Security Governance
Security Managing
Security Controls
Security Risk Management
Treatment Planning
Internal Auditing
Incident Response
Security Risk
Preferred industry experience
Management Consulting
Experience level
5 - 8 years of experience

Job description

The Mom Project is excited to support our partner, a global consulting firm, in their search for a Manager, Security Governance Risk and Compliance (GRC). This role is onsite in Tampa, FL.


This role will play a critical role in, and will be responsible for, driving risk strategy, overseeing risk governance, managing senior-level reporting, and leading key information security risk initiatives across the organizations.

This role will be focused on the managing and maintaining the Global Security Office Information Security Risk Register, its supporting processes, governance and reporting requirements. The successful candidate requires a strong understanding of ISO 27001 security controls, exposure to the OnSpring GRC Tool and can effectively assess and communicate technical security requirements to teams across the firm.


Responsibilities:

Risk Management Leadership and Oversight:

  • Working to company policy and industry standards and lead the end-to-end information security risk management process, to ensuring risks are proactively identified, assessed, recorded, and mitigated.
  • Assess and prioritize security risks based on enterprise-wide impact, likelihood, and mitigation strategies.
  • Act as a trusted security advisor, working cross-functionally with IT, legal, compliance, Internal Audit, AI Centre of Excellence and other business leadership teams to drive a culture of risk awareness.
  • Ensure that all security risks align with regulatory requirements such as ISO 27001, NIST, GDPR, and other international security frameworks.
  • Provide oversight and work closely with risk owners manage the development, implement treatment plans to address identified risks, ensuring alignment with senior leadership expectations and business objectives.

GRC Tool Management:

  • Own, manage and continuously develop their GRC platform to provide a structured, scalable risk register and reporting capabilities to support copmpany-wide requirements, and support ISO 27001:2022 certification requirements.

Risk Audit Requirements:

  • Complete annual formal risk assessment including control maturity assessment and asset register revision.
  • Work closely with Internal Audit to ensure audit compliance and delivery for ISO 27001
  • Support ownership of minor non-conformities log of internal and external audit finding through to reporting, remediation and closure.
  • Attend ISO 27001 external audits for InfoSec Risk Management related compliance requirements.

Risk Governance:

  • Organize and facilitate bi-weekly Global Security Office Risk Management meetings, providing comprehensive tracking and updates on risk triage activities, critical risk register change and general risk reporting mitigation strategies.
  • Prepare and deliver quarterly risk updates to the Information Security Steering Committee and executive leadership, providing strategic insights in information security against the company security objectives.
  • Support risk input to bi-annual Executive Security Management Reviews

Support Global Security Office SOC on Incident Response Leadership:

  • Provide GRC oversight during security incidents, guiding the organization’s response and ensuring effective risk mitigation and reporting.

Qualifications

  • Experience in Information security risk management, governance, and compliance.
  • Proven leadership in enterprise risk management and security governance frameworks.
  • Hands-on exposure to GRC tools
  • Background knowledge of risk assessment methodologies and security frameworks such as ISO 27001, NIST, and CIS
  • Experience managing and directing enterprise-wide Information Security risk triage, risk recording, treatment planning, and reporting.
  • Ability to translate complex security risks into actionable business strategies for executive stakeholders.
  • Strong analytical, strategic thinking, and decision-making skills.
  • Excellent written and verbal communication skills, with demonstrated experience presenting risk insights to executive leadership and board members.
  • Relevant senior security certifications (e.g., CISSP, CISM, CRISC, CISA, ISO 27001 Lead Implementer/Auditor) are highly desirable.

Salary:

The salary range is $110,000 - $130,000 annually, dependent on several variables including but not limited to education, experience, skills, and geography. In addition, our client offers a discretionary bonus program which is based on a number of factors, including individual and firm performance. Please ask your recruiter for details.


Benefits:


Regular employees working 30 or more hours per week are also entitled to participate in fringe benefits consisting of healthcare plans, flexible spending and savings accounts, life, AD&D, and disability coverages at rates determined periodically as well as a 401(k) retirement savings plan. Provided the eligibility requirements are met, employees will also receive an annual discretionary contribution to their 401(k) retirement savings plan from our client. Additionally, employees are eligible for paid time off including vacation, personal days, seventy-two (72) hours of sick time (prorated for part time employees), ten federal holidays, one floating holiday, and parental leave. The amount of vacation and personal days available varies based on tenure and role type.


An Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or protected veteran status and will not be discriminated against on the basis of disability.

All applicants applying for U.S. job openings must be legally authorized to work in the United States and are required to have U.S. residency at the time of application.

If you are a person with a disability needing assistance with the application, or at any point in the hiring process, please contact us at support@themomproject.com.