Experience: • 12+ years in cybersecurity with a focus in security operations, monitoring ... Expertise in scaling Governance, Risk, and Compliance (GRC) frameworks across business units to ...
Experience: • 12+ years in cybersecurity with a focus in security operations, monitoring ... Expertise in scaling Governance, Risk, and Compliance (GRC) frameworks across business units to ...
The role partners closely with Technology, Corporate Security, Legal, Compliance, Risk, Audit, and ... Guide business partners through enterprise governance forums and approval processes, ensuring cyber ...
The role partners closely with Technology, Corporate Security, Legal, Compliance, Risk, Audit, and ... Guide business partners through enterprise governance forums and approval processes, ensuring cyber ...
The role partners closely with Technology, Corporate Security, Legal, Compliance, Risk, Audit, and ... Guide business partners through enterprise governance forums and approval processes, ensuring cyber ...
The role partners closely with Technology, Corporate Security, Legal, Compliance, Risk, Audit, and ... Guide business partners through enterprise governance forums and approval processes, ensuring cyber ...
The role partners closely with Technology, Corporate Security, Legal, Compliance, Risk, Audit, and ... Guide business partners through enterprise governance forums and approval processes, ensuring cyber ...
The role partners closely with Technology, Corporate Security, Legal, Compliance, Risk, Audit, and ... Guide business partners through enterprise governance forums and approval processes, ensuring cyber ...
The role partners closely with Technology, Corporate Security, Legal, Compliance, Risk, Audit, and ... Guide business partners through enterprise governance forums and approval processes, ensuring cyber ...
The role partners closely with Technology, Corporate Security, Legal, Compliance, Risk, Audit, and ... Guide business partners through enterprise governance forums and approval processes, ensuring cyber ...
Lead, Service Management
Providence, RI · On-site
$16.25 - $21.25/hr
A distinctive part of this role is establishing and leading the cybersecurity services Pearson ... Governance, risk, and compliance is a separate, independent function and a close partner of this ...
New
Lead, Service Management
Providence, RI · On-site
$16.25 - $21.25/hr
A distinctive part of this role is establishing and leading the cybersecurity services Pearson ... Governance, risk, and compliance is a separate, independent function and a close partner of this ...
New
Operational Risk Manager - Cybersecurity
Johnston, RI · On-site
$100K - $135K/yr
Operational Risk Manager - Cybersecurity Work Arrangement Hybrid work arrangement required with 4 ... program governance, while performing assurance activities to assess corporate wide compliance.
Operational Risk Manager - Cybersecurity
Johnston, RI · On-site
$100K - $135K/yr
Operational Risk Manager - Cybersecurity Work Arrangement Hybrid work arrangement required with 4 ... program governance, while performing assurance activities to assess corporate wide compliance.
Operational Risk Manager - Cybersecurity
Johnston, RI · Hybrid
$100K - $135K/yr
Description Operational Risk Manager - Cybersecurity Work Arrangement Hybrid work arrangement ... program governance, while performing assurance activities to assess corporate wide compliance.
Operational Risk Manager - Cybersecurity
Johnston, RI · Hybrid
$100K - $135K/yr
Description Operational Risk Manager - Cybersecurity Work Arrangement Hybrid work arrangement ... program governance, while performing assurance activities to assess corporate wide compliance.
Operational Risk Manager - Cybersecurity
Johnston, RI · Hybrid
$100K - $135K/yr
Operational Risk Manager - Cybersecurity Work Arrangement Hybrid work arrangement required with 4 ... program governance, while performing assurance activities to assess corporate wide compliance.
Operational Risk Manager - Cybersecurity
Johnston, RI · Hybrid
$100K - $135K/yr
Operational Risk Manager - Cybersecurity Work Arrangement Hybrid work arrangement required with 4 ... program governance, while performing assurance activities to assess corporate wide compliance.
Operational Risk Manager - Cybersecurity
Johnston, RI · Hybrid
$100K - $135K/yr
Description Operational Risk Manager - Cybersecurity Work Arrangement Hybrid work arrangement ... program governance, while performing assurance activities to assess corporate wide compliance.
Operational Risk Manager - Cybersecurity
Johnston, RI · Hybrid
$100K - $135K/yr
Description Operational Risk Manager - Cybersecurity Work Arrangement Hybrid work arrangement ... program governance, while performing assurance activities to assess corporate wide compliance.
Manager, Data Analytics and Insights
Smithfield, RI · On-site
$80K - $153K/yr
The role collaborates across business, technology, governance, risk, compliance, and data management functions to advance Fidelity's commitment to strong data stewardship, innovation, and client ...
Manager, Data Analytics and Insights
Smithfield, RI · On-site
$80K - $153K/yr
The role collaborates across business, technology, governance, risk, compliance, and data management functions to advance Fidelity's commitment to strong data stewardship, innovation, and client ...
Third Party Risk Sr Analyst - Cybersecurity
Johnston, RI · Hybrid
$95K - $123K/yr
Assisting in Governance Risk and Compliance (GRC) program's design, process reengineering or ... Understanding of Cyber Security controls. Hours & Work Schedule * Hours per Week: 40 * Work ...
Third Party Risk Sr Analyst - Cybersecurity
Johnston, RI · Hybrid
$95K - $123K/yr
Assisting in Governance Risk and Compliance (GRC) program's design, process reengineering or ... Understanding of Cyber Security controls. Hours & Work Schedule * Hours per Week: 40 * Work ...
Cybersecurity Manager
Smithfield, RI · On-site
$100K - $120K/yr
The position also provides leadership for a small risk team and helps strengthen governance around ... Legal and Compliance teams, and advancing related policies and safeguards. * Provide guidance ...
Quick apply
Cybersecurity Manager
Smithfield, RI · On-site
$100K - $120K/yr
The position also provides leadership for a small risk team and helps strengthen governance around ... Legal and Compliance teams, and advancing related policies and safeguards. * Provide guidance ...
Third Party Risk Sr Analyst - Cybersecurity
Johnston, RI · Hybrid
$95K - $123K/yr
Assisting in Governance Risk and Compliance (GRC) program's design, process reengineering or ... Understanding of Cyber Security controls. Hours & Work Schedule * Hours per Week: 40 * Work ...
Third Party Risk Sr Analyst - Cybersecurity
Johnston, RI · Hybrid
$95K - $123K/yr
Assisting in Governance Risk and Compliance (GRC) program's design, process reengineering or ... Understanding of Cyber Security controls. Hours & Work Schedule * Hours per Week: 40 * Work ...
Third Party Risk Sr Analyst - Cybersecurity
Johnston, RI · On-site
$95K - $123K/yr
Assisting in Governance Risk and Compliance (GRC) program's design, process reengineering or ... Understanding of Cyber Security controls. Hours & Work Schedule * Hours per Week: 40 * Work ...
Third Party Risk Sr Analyst - Cybersecurity
Johnston, RI · On-site
$95K - $123K/yr
Assisting in Governance Risk and Compliance (GRC) program's design, process reengineering or ... Understanding of Cyber Security controls. Hours & Work Schedule * Hours per Week: 40 * Work ...
Third Party Risk Sr Analyst - Cybersecurity
Johnston, RI · Hybrid
$95K - $123K/yr
Assisting in Governance Risk and Compliance (GRC) program's design, process reengineering or ... Understanding of Cyber Security controls. Hours & Work Schedule * Hours per Week: 40 * Work ...
Third Party Risk Sr Analyst - Cybersecurity
Johnston, RI · Hybrid
$95K - $123K/yr
Assisting in Governance Risk and Compliance (GRC) program's design, process reengineering or ... Understanding of Cyber Security controls. Hours & Work Schedule * Hours per Week: 40 * Work ...
The Analyst will work closely with business owners, Risk, Compliance, Project Management, Finance ... Evaluate risks presented by new and existing vendors across cybersecurity, operational, financial ...
The Analyst will work closely with business owners, Risk, Compliance, Project Management, Finance ... Evaluate risks presented by new and existing vendors across cybersecurity, operational, financial ...
The Analyst will work closely with business owners, Risk, Compliance, Project Management, Finance ... Evaluate risks presented by new and existing vendors across cybersecurity, operational, financial ...
The Analyst will work closely with business owners, Risk, Compliance, Project Management, Finance ... Evaluate risks presented by new and existing vendors across cybersecurity, operational, financial ...
... controls, cyber security, access management, network and cloud, resiliency, etc.) * Working ... Knowledge of Governance, Risk, and Compliance (GRC) tools, such as Archer is preferred * Your ...
... controls, cyber security, access management, network and cloud, resiliency, etc.) * Working ... Knowledge of Governance, Risk, and Compliance (GRC) tools, such as Archer is preferred * Your ...
Integrate real-time streaming data for low-latency decision systems Model Governance & Risk Compliance * Define and enforce standards, patterns, and guardrails for model deployment, explainability ...
Integrate real-time streaming data for low-latency decision systems Model Governance & Risk Compliance * Define and enforce standards, patterns, and guardrails for model deployment, explainability ...
Cybersecurity Governance Risk Compliance information
What is the difference between Cybersecurity Governance Risk Compliance vs Cybersecurity Analyst?
| Aspect | Cybersecurity Governance Risk Compliance | Cybersecurity Analyst |
|---|---|---|
| Certifications | CISA, CISSP, CISM | CompTIA Security+, CISSP, CEH |
| Work Environment | Policy development, audits, compliance frameworks | Monitoring security systems, incident response |
| Employer & Industry Usage | Organizations with compliance needs, regulatory bodies | IT security teams, cybersecurity firms |
While Cybersecurity Governance Risk Compliance focuses on establishing policies, ensuring regulatory adherence, and managing risks, Cybersecurity Analysts primarily monitor security systems, analyze threats, and respond to incidents. Both roles are essential in a comprehensive cybersecurity strategy but differ in scope and daily responsibilities.
What are the key skills and qualifications needed to thrive as a cybersecurity governance, risk, and compliance (GRC) professional?
What are some typical challenges faced by professionals in cybersecurity governance, risk, and compliance (GRC) roles?
Is cybersecurity governance risk compliance a good career?
Is cybersecurity governance risk compliance a good job?
What is cybersecurity governance, risk, and compliance (GRC)?

Full-time
Medical, Dental, Vision, Life, Retirement, PTO
Posted 12 days ago
UNFI rating
7.3
Based on 128 frontline employees who took The Breakroom Quiz
20th of 49 rated food wholesalers
Job description
The Senior Director of Security Operations and Risk leads the defensive security strategy and operational execution responsible for strategic oversight, operational excellence, and continuous maturity of the security operations center (SOC) Vulnerability Management (VM), and Governance, Risk, and Compliance (GRC).
While remote, there is a strong preference for candidates located in the New England area and within a commutable distance (approximately 150 miles) of our Providence, RI headquarters.
Job Responsibilities:
Core Responsibilities
• Develop and implement a multi-year roadmap for Defensive Security that aligns SecOps, Vulnerability Management, and GRC objectives with the organization's corporate risk priorities, security architecture, and evolving business needs.
• Act as the main point of contact for defensive security metrics, delivering clear, data-driven insights on threat of resilience and residual risk to the CISO and executive leadership.
• Oversee the lifecycle of security policies and standards, ensuring compliance, technical enforceability, and practicality for the business. Ensure that streamlined processes and comprehensive runbooks are established.
• Direct 24/7 SOC operations to deliver best-in-class monitoring, advanced threat detection, proactive analysis, dynamic threat hunting, and rapid incident response.
• Manage escalations of anomalous activities, vulnerabilities, and major cyber events by ensuring swift triage, coordinated response efforts, and consistent alignment with goals.
• Advance protection and detection capabilities by leveraging cutting-edge analytics, automation, innovative engineering, and recognized cybersecurity architectural best practices.
• Create an inclusive, high-performance environment that supports continuous learning and career development for security analysts, engineers, and risk professionals.
• Implement of retention and succession plans to address the pressures and burnout risks common in high-tempo defensive operations.
• Foster a culture of transparency and accountability, empowering team members to proactively identify and address systemic security weaknesses.
• Direct proactive threat hunting, red-team simulations, and tabletop exercises to validate incident response readiness and uncover hidden architectural gaps.
• Maintain continuous audit readiness by automating compliance evidence collection to support seamless internal and external reviews without unexpected issues
• Inspire high-performing teams and cultivate workforce excellence
Performs other duties as assigned.
Job Requirements:
Education/ Certifications:
• Bachelor's degree in computer science, information systems or related field.
• At least 1 industry recognized data, compliance, and/or cybersecurity certification.
Experience:
• 12+ years in cybersecurity with a focus in security operations, monitoring, detection, investigation, and threat intelligence
• 5+ years in a leadership position overseeing and leading a security operations program
• More than 5 years of hands-on experience with risk management frameworks (such as NIST CSF, ISO 27001, and FAIR), with a focus on data-driven risk beyond basic compliance
• Experience in managing complex third-party relationships, including auditing service provider performance against SLAs and ensuring high-fidelity alerting.
• Experience in leading a team, identifying skill gaps and creating career paths
• Demonstrated success leading enterprise-wide vulnerability management programs, emphasizing risk-based prioritization and cross-departmental remediation workflows.
• Proven incident commander experience, with the ability to lead high-pressure response efforts and clearly communicate impact to executive leadership and legal counsel.
Knowledge/Skills/ Abilities
• Incident Orchestration & Resilience: Experience leading strategic responses to high-impact security events, prioritizing business continuity and long-term remediation.
• Strategic Security Governance: Expertise in scaling Governance, Risk, and Compliance (GRC) frameworks across business units to address changing regulatory and industry standards.
• Next-Generation Architecture: In-depth knowledge of Zero Trust and SASE frameworks, with a focus on replacing legacy VPN environments.
• Emerging Tech Governance: Understanding of risks and security requirements for agentic AI workflows and autonomous entities.
• Executive Risk Communication: Ability to translate complex technical vulnerabilities and architectural changes into clear, business-focused narratives for Board and executive stakeholders.
• Strategic Vendor & MSSP Management: Proficient in managing Managed Security Service Providers (MSSPs) and large-scale SaaS vendors to ensure alignment with strategic KPIs.
• Data Security & Privacy Leadership: Ability to develop and implement data protection strategies that comply with policies, standards, controls, and regulations.
• Organizational Transformation: Ability to lead large-scale cultural shifts toward security-first practices while maintaining operational efficiency and developer productivity.
• Metrics-Driven Performance Management: Ability to define and report on maturity-based security metrics that demonstrate program ROI and risk reduction to senior leadership.
• Good judgment is required for this position as there may be times when direct supervision may not be immediately available.
Work Environment:
Remote Role:
• This position is classified as remote where the associate will perform remote work from their primary residence. While remote, there is a strong preference for candidates located in the New England area and within a commutable distance (approximately 150 miles) of our Providence, RI headquarters. Remote associates are welcome to work from the office but are not required to do so. While remote associates are not required to work from an office on a regular basis, they may be required to come to the office or other UNFI locations for necessary business reasons or if directed to do so by their manager.
Physical Environment/Demands:
Office Roles:
• Most work is performed in a temperature-controlled office environment.
• Incumbent may sit for long periods of time at a desk or computer terminal.
• While performing the duties of this job, the employee is regularly required to sit; use hands to finger, handle, or feel; reach with hands and arms; and talk or hear.
• Incumbent may use calculators, keyboards, telephones, and other office equipment in the course of a normal workday.
• Stooping, bending, twisting, and reaching may be required in the completion of job duties.
The above statements are intended to describe the general nature of the work performed by the employees assigned to this job. All employees must comply with Company policy and applicable laws. The responsibilities, duties and skills required of personnel so classified may vary within each department and/or location.
UNFI is an Equal Opportunity employer committed to creating an inclusive and respectful environment for all. All qualified applicants will receive equal consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity or expression, national origin, disability, protected veteran status, or other protected ground. Accommodation is available upon request for candidates taking part in all aspects of the job selection process. - M/F/Veteran/Disability. VEVRAA Federal Contractor.
Compensation:
UNFI anticipates paying the above-referenced pay rate (or within the above-referenced pay range) for this position. Actual Pay, where applicable, will depend on a number of factors, including, but not limited to, education, experience, training, and any requirements under applicable collective bargaining agreements. UNFI is committed to transparency in pay in compliance with applicable state and local laws.
Benefits:
For Washington positions (or positions that may be performed remotely from Washington), https://www.unfi.com/jobs-more-info-wa.html for Washington-specific paid time off details.
Candidates hired into this position will also be eligible to participate in the following benefits programs: Paid Time Off; Sick Time; paid holidays and parental leave; 401K Program; medical, dental, vision, life, and accidental death/dismemberment insurance; short-term and long-term disability insurance program, Flexible Spending Account and/or Health Savings Account, subject to meeting the eligibility requirements and the terms and conditions of these programs, and subject to any requirements under applicable collective bargaining agreements.
UNFI's compensation, benefits, and paid time off policies are subject to change in the Company's sole discretion, consistent with applicable law. This job posting should not be construed as an offer of employment with certain terms, nor should it be construed as a guaranteed minimum.
Qualified applications with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance and the California Fair Chance Act .
About UNFI
Sourced by ZipRecruiter
Industry
Food and beverage wholesalers
Company size
501 - 1,000 Employees
Headquarters location
Providence, RI, US
Year founded
1978