1

Director Cyber Security Grc Jobs in Springfield, MA

Director Cyber Security Grc information

See Springfield, MA salary details

$56.8K

$132.5K

$185.3K

How much do director cyber security grc jobs pay per year?

As of Sep 3, 2026, the average yearly pay for director cyber security grc in Springfield, MA is $132,497.00, according to ZipRecruiter salary data. Most workers in this role earn between $110,600.00 and $149,500.00 per year, depending on experience, location, and employer.

What does a director of Cyber Security GRC do?

A Director of Cyber Security GRC (Governance, Risk, and Compliance) leads the development and management of an organization's cybersecurity governance, risk management, and compliance programs. They ensure that security policies align with business objectives and regulatory requirements, assess cyber risks, and implement strategies to mitigate them. Additionally, they oversee compliance with industry standards and frameworks, manage audit processes, and foster a security-aware culture across the organization. This role typically involves working closely with executive leadership, IT teams, and external auditors.

What are the key skills and qualifications needed to thrive as a director of Cyber Security GRC, and why are they important?

To thrive as a Director of Cyber Security GRC, you need deep expertise in governance, risk management, compliance frameworks (such as ISO 27001, NIST, or SOC 2), and a relevant degree or certifications like CISSP or CISM. Familiarity with risk assessment tools, GRC platforms (e.g., Archer, ServiceNow), and security auditing systems is crucial. Outstanding leadership, strategic thinking, and the ability to communicate complex security issues to both technical and non-technical stakeholders are key soft skills. These capabilities are vital to ensure an organization’s security posture aligns with regulatory requirements and business objectives while fostering a culture of risk awareness.

What are some common challenges faced by a director of Cyber Security GRC when aligning security initiatives with business objectives?

A Director of Cyber Security GRC often encounters challenges in balancing robust risk management practices with the need for business agility and innovation. Translating technical security requirements into business language that resonates with executive leadership and stakeholders is crucial, as is ensuring that compliance efforts do not hinder operational efficiency. Additionally, keeping up with evolving regulatory standards and integrating them into the organization's existing processes can be complex. Effective collaboration with IT, legal, and business units is essential to ensure that security initiatives support, rather than impede, overall business goals.

What is the difference between Director Cyber Security Grc vs Cyber Security Manager?

AspectDirector Cyber Security GrcCyber Security Manager
CertificationsCISSP, CISM, CRISCCISSP, CISM, CISA
Work EnvironmentStrategic, policy-focused, executive levelOperational, team management, technical focus
ResponsibilitiesOversees governance, risk, compliance frameworksManages security teams, implements security measures
Industry UsageCommon in large organizations, compliance-heavy sectorsWidely used across various organizations for security operations

The main difference between a Director Cyber Security Grc and a Cyber Security Manager lies in scope and focus. The Director Grc is responsible for strategic governance, risk management, and compliance at an executive level, while the Cyber Security Manager handles day-to-day security operations and team management. Both roles require similar certifications but differ in their strategic versus operational focus.

What are popular job titles related to Director Cyber Security Grc jobs in Springfield, MA?

For Director Cyber Security Grc jobs in Springfield, MA, the most frequently searched job titles are:

What job categories do people searching Director Cyber Security Grc jobs in Springfield, MA look for?

The top searched job categories for Director Cyber Security Grc jobs in Springfield, MA are:

Infographic showing various Director Cyber Security Grc job openings in Springfield, MA as of August 2026, with employment types broken down into 92% Full Time, and 8% Contract. Highlights an 80% In-person, and 20% Remote job distribution, with an average salary of $132,497 per year, or $63.7 per hour.

Senior Cyber Security & GRC Engineer

Emergent Staffing

Hartford, CT • On-site

$130 - $180/hr

Other

Posted 29 days ago


Key responsibilities

  • Own and mature the enterprise cybersecurity and risk management program across a multi‑entity organization.

  • Design, implement, and maintain a harmonized control framework supporting NIST CSF 2.0, GDPR, and SOX ITGC requirements.

  • Administer and optimize Vanta as the enterprise GRC system of record, including configuring controls, integrations, tests, evidence collection, continuous monitoring, and audit workflows.


Job description

**This position is a direct hire for one of our clients. Our ideal candidates live in the Hartford, Connecticut metro area. East coast & TX candidates will be considered with expectations of occasional travel to Connecticut. Eligible candidates must currently reside in the US and authorized to work in the US without visa sponsorship.**

Our client is seeking an experienced Cyber Security & GRC Engineer to lead and mature an enterprise-wide cybersecurity, governance, risk, and compliance (GRC) program across multiple organizations. This is a senior-level, hands‑on leadership role responsible for developing a unified security and compliance framework that supports NIST CSF 2.0, GDPR, and SOX IT General Controls requirements.

The ideal candidate combines strategic leadership with technical expertise, comfortably engaging executive stakeholders and auditors while also administering security tools, managing risks, implementing controls, and driving compliance initiatives. This role will serve as the owner of the enterprise GRC platform, Vanta, ensuring continuous monitoring, audit readiness, and program maturity across all entities.

Responsibilities
  • Own and mature the enterprise cybersecurity and risk management program across a multi‑entity organization.

  • Design, implement, and maintain a harmonized control framework supporting NIST CSF 2.0, GDPR, and SOX ITGC requirements.

  • Lead enterprise governance activities, including risk reviews, KPI/KRI reporting, executive reporting, and steering committee meetings.

  • Serve as the primary liaison for auditors, assessors, clients, and internal stakeholders regarding security and compliance matters.

  • Administer and optimize Vanta as the enterprise GRC system of record.

  • Configure controls, integrations, tests, evidence collection, continuous monitoring, and audit workflows within Vanta.

  • Develop, maintain, and manage enterprise security policies, standards, procedures, exceptions, and policy lifecycle processes.

  • Lead SOX ITGC readiness and compliance efforts.

  • Operationalize GDPR requirements, including records of processing, DPIAs, data subject rights management, vendor oversight, and breach response.

  • Conduct NIST CSF 2.0 assessments, maturity reviews, gap analyses, and remediation planning.

  • Manage enterprise risk assessments, risk registers, third‑party vendor risk programs, and remediation initiatives.

  • Oversee vulnerability management, patch coordination, access reviews, and technical security controls across cloud and on-premises environments.

  • Lead incident response activities, including preparation, detection, containment, recovery, and post‑incident reviews.

  • Provide security architecture guidance for new systems, integrations, cloud solutions, and data platforms.

  • Build and manage security awareness, phishing simulation, and employee training programs.

  • Partner with business and project teams to ensure security and privacy requirements are incorporated into solution design.

Required Qualifications
  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or equivalent experience.

  • 7+ years of information security, cybersecurity, or risk management experience with progression into senior program ownership responsibilities.

  • Hands‑on experience administering a GRC platform, preferably Vanta.

  • Experience implementing, operating, or auditing against NIST CSF, SOX ITGC, and GDPR requirements.

  • Demonstrated success developing and implementing security policies, controls, and governance programs.

  • One or more of the following certifications: CISSP, CISM, CRISC, or CISA.

  • Strong technical knowledge of cloud security, identity and access management, endpoint security, vulnerability management, logging, and security operations.

  • Excellent communication skills with the ability to engage technical teams, business leaders, auditors, and executives.

  • Proven ability to work independently, manage multiple priorities, and drive accountability across stakeholders.

Nice to Have Experience
  • Direct Vanta administration experience.

  • Experience supporting a publicly traded company and SOX Section 404 compliance requirements.

  • Experience leading security programs across multiple organizations or business entities.

  • ISO 27001 Lead Implementer or Lead Auditor certification.

  • SANS/GIAC certifications.

  • Construction, engineering, energy, power generation, or EPC industry experience.

  • Familiarity with AI/ML governance, data security, and secure AI deployment practices.

#J-18808-Ljbffr