1

Cybersecurity Governance Risk Compliance Jobs in Alabama

$90 - $120/hr

Cybersecurity Risk & Compliance Consultant POSITION OVERVIEW The Cyber Security Risk and Compliance Consultant is responsible for conducting Cybersecurity gap assessments and ongoing consulting with ...

Integration Security & Governance * Conducting security architecture assessments across the ... Compliance & Risk * Working with leadership to ensure enterprise-wide compliance with FedRAMP, RMF ...

next page

Showing results 1-20

Cybersecurity Governance Risk Compliance information

What is the difference between Cybersecurity Governance Risk Compliance vs Cybersecurity Analyst?

AspectCybersecurity Governance Risk ComplianceCybersecurity Analyst
CertificationsCISA, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentPolicy development, audits, compliance frameworksMonitoring security systems, incident response
Employer & Industry UsageOrganizations with compliance needs, regulatory bodiesIT security teams, cybersecurity firms

While Cybersecurity Governance Risk Compliance focuses on establishing policies, ensuring regulatory adherence, and managing risks, Cybersecurity Analysts primarily monitor security systems, analyze threats, and respond to incidents. Both roles are essential in a comprehensive cybersecurity strategy but differ in scope and daily responsibilities.

What are the key skills and qualifications needed to thrive as a cybersecurity governance, risk, and compliance (GRC) professional?

To thrive as a Cybersecurity GRC professional, you need a solid understanding of information security frameworks, risk management principles, and regulatory compliance, often supported by a degree in cybersecurity or related fields. Familiarity with tools like GRC platforms (e.g., Archer, ServiceNow), and certifications such as CISSP, CISM, or CRISC are highly valued. Strong analytical thinking, attention to detail, and effective communication skills help you interpret regulations and collaborate with stakeholders. These skills ensure organizations can manage cybersecurity risks proactively while meeting regulatory and industry standards.

What are some typical challenges faced by professionals in cybersecurity governance, risk, and compliance (GRC) roles?

Professionals in Cybersecurity GRC roles often navigate the challenge of keeping up with rapidly changing regulatory requirements while ensuring company policies align with both business objectives and security best practices. Balancing the need for robust security controls with operational efficiency, educating non-technical stakeholders about risk, and managing audits are common aspects of the job. Additionally, GRC professionals frequently collaborate with IT, legal, and business teams to ensure a cohesive approach to risk management and compliance. This dynamic environment requires strong communication skills, adaptability, and a commitment to continuous learning.

Is cybersecurity governance risk compliance a good career?

Cybersecurity Governance, Risk, and Compliance (GRC) is a growing field that offers opportunities in managing organizational security policies, risk assessments, and regulatory compliance. It requires knowledge of security frameworks, certifications like CISSP or CISM, and strong analytical skills. The role is in demand across various industries due to increasing cybersecurity threats and regulatory requirements.

Is cybersecurity governance risk compliance a good job?

Cybersecurity Governance, Risk, and Compliance (GRC) roles are in high demand due to increasing cybersecurity threats and regulatory requirements. These jobs typically require knowledge of security frameworks, risk management, and compliance standards, offering opportunities for career growth and specialization. They often involve collaboration across departments and may require certifications like CISSP or CISA.

What is cybersecurity governance, risk, and compliance (GRC)?

Cybersecurity Governance, Risk, and Compliance (GRC) refers to a framework used by organizations to align their IT and security strategies with business objectives, manage risks, and ensure compliance with laws and regulations. Governance involves setting policies and procedures, risk focuses on identifying and addressing threats, and compliance ensures adherence to required standards. Professionals in this field help organizations protect sensitive data, avoid regulatory penalties, and build trust with stakeholders. GRC is essential for maintaining effective cybersecurity and demonstrating due diligence.
What are popular job titles related to Cybersecurity Governance Risk Compliance jobs in Alabama? For Cybersecurity Governance Risk Compliance jobs in Alabama, the most frequently searched job titles are:
What job categories do people searching Cybersecurity Governance Risk Compliance jobs in Alabama look for? The top searched job categories for Cybersecurity Governance Risk Compliance jobs in Alabama are:
What cities in Alabama are hiring for Cybersecurity Governance Risk Compliance jobs? Cities in Alabama with the most Cybersecurity Governance Risk Compliance job openings:

$180 - $250/hr

Other

Posted 15 days ago


Job description

Select how often (in days) to receive an alert:

Headquartered in Birmingham, Alabama, Moultrie (www.moultrie.com ) is the leader in game feeders and cellular camera innovation, building products used by hunters, property owners, and others for real-time remote monitoring.

We take pride in developing deep user understanding, obsessing about the details, and going the extra mile to show our users we love them. Moultrie is customer-driven – hardware, software, marketing, and customer success teams collaborate to deliver a quality user experience.

We are guided by the following principles: Customer Obsession.; Excellence is the Standard.; Bias for Action.; Act Boldly.; Deliver Results.; Hire and Develop the Best.; Be Curious and Learn.; Win as a Team

Job Summary

We are looking for a seasoned Director of Cybersecurity to lead and mature our security program across the full breadth of our business. This is a senior leadership role responsible for protecting our subscription products and customer data, securing our software engineering and DevOps pipelines, and building a governance framework that scales with the company.

You will partner closely with Software Engineering, Product, Legal, and Executive leadership to make security an essential part of our business — not just a compliance checkbox.

Job Responsibilities Subscription Business & Infrastructure Security
  • Own the end-to-end security posture of the company’s subscription platform, including customerfacing applications, APIs, and underlying cloud infrastructure.
  • Define and enforce security architecture standards for cloud environments (AWS, Azure, GCP), ensuring proper network segmentation, identity and access management (IAM), and data protection controls.
  • Lead vulnerability management, penetration testing, and red team exercises to proactively identify and remediate risk across production systems.
  • Establish and maintain a Security Operations Center (SOC) capability — whether in-house, managed, or hybrid — to ensure continuous monitoring, threat detection, and incident response readiness.
  • Oversee data security controls to protect subscriber PII and payment information in compliance with applicable regulations (PCI-DSS, CCPA, GDPR, etc.).
  • Define and rehearse incident response plans, leading the organization through security events from detection through post-mortem.
Software Development & DevSecOps
  • Embed security throughout the software development lifecycle (SDLC), partnering with Engineering and Product to shift security left without slowing delivery velocity.
  • Own the security of CI/CD build pipelines, including secrets management, pipeline integrity, dependency scanning, and supply chain security controls.
  • Drive adoption of SAST, DAST, SCA, and container/image scanning tools across development teams.
  • Define and maintain secure coding standards, conducting regular developer security training and threat modeling workshops.
  • Establish controls to detect and prevent dependency confusion, code injection, and software supply chain attacks in build and deployment processes.
  • Partner with platform and infrastructure engineering teams to ensure IaC (Terraform, Pulumi, etc.) follows security best practices and is reviewed prior to deployment.
Governance, Risk & Compliance
  • Build and maintain a cybersecurity governance framework.
  • Own the company’s risk register for cybersecurity, providing clear, quantified risk reporting to executive leadership and the board as appropriate.
  • Lead and manage third-party security assessments, customer security questionnaires, and audit responses (SOC 2 Type II, penetration test reports, etc.).
  • Develop and enforce security policies, standards, and procedures across the organization.
  • Drive vendor and third-party risk management, ensuring security requirements are embedded in procurement and contract processes.
  • Maintain awareness of the evolving regulatory landscape and ensure the company’s practices remain compliant with applicable laws and industry standards.
  • Champion a culture of security awareness through company-wide training programs, phishing simulations, and ongoing communication.
Job Requirements
  • 10+ years of progressive experience in cybersecurity, with at least three years in a leadership role managing security programs and teams.
  • Deep technical expertise in cloud security (AWS, Azure, or GCP) and securing SaaS or subscription-based products.
  • Proven experience implementing DevSecOps practices and securing CI/CD pipelines in modern engineering environments.
  • Hands-on knowledge of security tooling: SIEM, EDR, SAST/DAST, vulnerability scanners, secrets management platforms, and cloud security posture management (CSPM) tools.
  • Strong background in security governance frameworks (NIST CSF, ISO 27001, SOC 2) and working knowledge of compliance requirements (PCI-DSS, GDPR, CCPA).
  • Experience leading incident response efforts, including communication with executives, legal, and external stakeholders.
  • Excellent written and verbal communication skills — able to translate complex technical risk into clear, actionable business language.
Preferred Qualifications
  • Relevant certifications: CISSP, CISM, CISA, AWS Security Specialty, or equivalent.
  • Experience with software supply chain security frameworks (SLSA, SBOM generation, Sigstore, etc.).
  • Familiarity with zero trust architecture and its practical application in enterprise environments.
  • Experience working in a subscription or SaaS business where availability and customer trust are directly tied to revenue.
  • Background scaling security programs at a growth-stage company.

We are an equal opportunity employer and comply with all applicable federal, state, and local fair employment practices laws. We strictly prohibit and do not tolerate discrimination against employees, applicants, or any other covered persons because of race, color, sex, pregnancy status, age, national origin or ancestry, ethnicity, religion, creed, sexual orientation, gender identity, status as a veteran, and basis of disability or any other federal, state or local protected class. This policy applies to all terms and conditions of employment, including, but not limited to, hiring, training, promotion, discipline, compensation, benefits, and termination of employment.

We comply with the Americans with Disabilities Act (ADA), as amended by the ADA Amendments Act, and all applicable state or local law.


Nearest Major Market: Birmingham
Job Segment: Test Engineer, Testing, Cloud, Embedded, Compliance, Engineering, Technology, Legal

#J-18808-Ljbffr