1

Governance Risk Compliance Jobs in Portland, ME (NOW HIRING)

Manager, Security Compliance

Long Island, ME

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

The Security Compliance Manager is an individual contributor responsible for operationalizing ... Risk Management processes and escalate highrisk issues through established governance forums.

Location: 200 Middle Street, Suite 301, Portland Maine Job Summary We are seeking a Compliance ... Ensure governance forums receive clear, consistent risk reporting. 4. Risk Reporting & Analytics

Location: 200 Middle Street, Suite 301, Portland Maine Job Summary We are seeking a Compliance ... Ensure governance forums receive clear, consistent risk reporting. 4. Risk Reporting & Analytics

Operational Risk Manager

Portland, ME · On-site

$110K - $135K/yr

  • Medical

  • Dental

  • Life

  • Retirement

  • PTO

Key Competencies • Operational risk assessment and mitigation • Claims and incident analysis • Compliance auditing and governance • Cross functional collaboration • Data driven decision ...

Senior Leader, U.S. Trade Compliance Program

Auburn, ME · Remote

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

Governance & Internal Controls * Monitor compliance performance through Annual Trade Reviews, Global Trade Risk Assessments, metrics, and key performance indicators. * Coordinate with the Local Trade ...

Senior Leader, U.S. Trade Compliance Program

Yarmouth, ME · Remote

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

Governance & Internal Controls * Monitor compliance performance through Annual Trade Reviews, Global Trade Risk Assessments, metrics, and key performance indicators. * Coordinate with the Local Trade ...

Senior Leader, U.S. Trade Compliance Program

Portland, ME · Remote

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

Governance & Internal Controls * Monitor compliance performance through Annual Trade Reviews, Global Trade Risk Assessments, metrics, and key performance indicators. * Coordinate with the Local Trade ...

Senior Leader, U.S. Trade Compliance Program

Westbrook, ME · Remote

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

Governance & Internal Controls * Monitor compliance performance through Annual Trade Reviews, Global Trade Risk Assessments, metrics, and key performance indicators. * Coordinate with the Local Trade ...

Director, Security Risk Management

Long Island, ME · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

... governance workflows with enterprise risk management (ERM) practices. * Proven ability to collaborate across diverse stakeholders, including IT, Enterprise Risk Management, Legal, Compliance ...

Customer Success Specialist

Portland, ME · On-site

  • Medical

  • Dental

  • Retirement

  • PTO

We are the leading governance, risk, and compliance (GRC) advisor in financial services. When you join ACA, you'll become part of a team whose unique combination of talent includes the industry ...

... of Compliance/Center of Excellence programs in line with the Bank's risk philosophy and strategic direction. This role is responsible for driving infrastructure, governance, and operational ...

next page

Showing results 1-20

Governance Risk Compliance information

See Portland, ME salary details

$32.2K

$70.3K

$114.6K

How much do governance risk compliance jobs pay per year?

As of Aug 16, 2026, the average yearly pay for governance risk compliance in Portland, ME is $70,321.00, according to ZipRecruiter salary data. Most workers in this role earn between $50,100.00 and $88,500.00 per year, depending on experience, location, and employer.

What are jobs in governance risk compliance?

Governance risk compliance (GRC) is a method for managing and strategizing an organization's regulations regarding governance, financial or physical risk, and regulatory compliance. It aligns the IT aspects with business objectives and works to improve the efficiency of a company. There are GRC consultants and GRC analysts who provide an assessment of a business’s GRC, identify risks, analyze the data, develop policies to benefit the workplace, and consult on the best choice of action. Your duties may involve optimizing GRC systems, implementing tactics to lower risk, providing internal audits, assisting with cybersecurity, creating routine reports, and ensuring regulatory compliance.

What is the work of governance risk compliance?

Governance, Risk, and Compliance (GRC) professionals develop and implement policies to ensure organizations adhere to legal and regulatory requirements, manage risks, and maintain ethical standards. They analyze business processes, conduct audits, and use tools like risk management software to identify vulnerabilities and ensure compliance across departments.

What is governance risk compliance?

Governance, Risk, and Compliance (GRC) is a coordinated strategy that organizations use to manage overall governance, enterprise risk management, and compliance with regulations and standards. GRC professionals help organizations align their business objectives with risk management practices and regulatory requirements. This role involves identifying potential risks, implementing policies to mitigate those risks, and ensuring that the organization adheres to legal, ethical, and internal standards. Effective GRC management can improve decision-making, optimize processes, and protect the organization from financial or reputational harm.

How does a governance risk compliance professional typically collaborate with other departments within an organization?

GRC professionals work closely with a variety of departments, including IT, legal, finance, and operations, to ensure that organizational policies and regulatory requirements are consistently met. Collaboration often involves leading risk assessments, facilitating compliance training, and coordinating audits to identify and mitigate potential risks. Effective communication and relationship-building are key, as GRC teams must translate complex regulations into actionable steps for different business units. This cross-functional approach helps embed a culture of compliance and risk awareness throughout the organization.

What is the difference between Governance Risk Compliance vs Risk Analyst?

AspectGovernance Risk ComplianceRisk Analyst
CertificationsCRISC, CISA, CISSPCFA, FRM, CRISC
Work EnvironmentCorporate, regulated industriesFinancial, consulting firms
Employer & Industry UsageFinancial institutions, healthcare, governmentBanking, investment firms, insurance

Governance Risk Compliance focuses on establishing policies, ensuring regulatory adherence, and managing enterprise-wide risks. Risk Analysts primarily assess specific financial or operational risks through data analysis. While both roles involve risk management, Governance Risk Compliance has a broader scope related to organizational compliance and governance frameworks, whereas Risk Analysts concentrate on analyzing and quantifying particular risks.

What are the key skills and qualifications needed to thrive as a governance risk compliance professional?

To thrive as a Governance Risk Compliance professional, you need a solid understanding of regulatory frameworks, risk management principles, and policy development, often supported by a degree in business, law, or information security. Familiarity with GRC software platforms, compliance management systems, and certifications like CISA, CRISC, or CISSP is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills set top performers apart in this field. These competencies are essential for ensuring organizational compliance, minimizing risks, and maintaining robust corporate governance.

What are the most commonly searched types of Governance Risk Compliance jobs in Portland, ME?

The most popular types of Governance Risk Compliance jobs in Portland, ME are:

What job categories do people searching Governance Risk Compliance jobs in Portland, ME look for?

The top searched job categories for Governance Risk Compliance jobs in Portland, ME are:

Infographic showing various Governance Risk Compliance job openings in Portland, ME as of August 2026, with employment types broken down into 1% As Needed, 76% Full Time, 20% Part Time, and 3% Contract. Highlights an 93% Physical, 3% Hybrid, and 4% Remote job distribution, with an average salary of $70,321 per year, or $33.8 per hour.

Manager, Security Compliance

CardWorks

Long Island, ME

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 7 days ago


CardWorks rating

9.1

Company rating: 9.1 out of 10

Based on 8 frontline employees who took The Breakroom Quiz

1st of 21 rated payment service providers


Job description

Become an everyday champion - and build a career where your impact fuels financial progress.


What We Do

CardWorks Financial Group is a diversified financial services platform building ethical solutions across credit, lending, and the full customer lifecycle. Through our family of companies, CardWorks Financial Group tackles the complex challenges that larger financial institutions leave behind. We're embedded throughout the credit card ecosystem as a lender, servicer, and merchant acquirer.

Who We Are

  • Merrick Bank: The bank that builds
  • CardWorks Servicing: One partner, total performance
  • Carson Smithfield: Resolution with respect

With nearly 40 years of operating history, our track record is solid: disciplined in downturns and built to accelerate in recovery. The CardWorks Financial Group companies take precise approach in complex markets, as a top three non-prime focused general purpose card issuer and a top fifteen U.S. merchant acquirer.

Our team tackles the industry's most complex credit and payment challenges. And we believe that excellent work starts with a team that feels supported, respected, and empowered to grow.

CardWorks Servicing, LLC provides end-to end operational servicing functions for credit cards, secured cards, and installment loans. We service consumer and small business loans across the credit spectrum and offers backup servicing and due diligence services to capital providers and trustees.


Founded in 1997, Merrick Bank is an FDIC-insured financial institution headquartered in South Jordan, Utah, with over $10 billion in assets. A wholly owned subsidiary of CardWorks Financial Group, Merrick Bank serves roughly five million cardmembers and more than 100,000 merchant customers, offering credit cards, recreational loans, deposit accounts, merchant services and bank sponsorships to consumers and businesses.

Carson Smithfield, LLC provides a variety of post-charge-off debt recovery services, including digital self-service, IVR, live agent, and external agency management.

Position Summary:

The Security Compliance Manager is an individual contributor responsible for operationalizing, executing, and maturing the enterprise security compliance program. This role reports to the Director of Security Risk & Compliance and ensures that the organization's security compliance strategy is translated into effective operational processes, assessments, and workflows. Core responsibilities include managing compliance operations, executing assessments, reviewing controls, supporting audit readiness, coordinating documentation and evidence, and ensuring accuracy and consistency across compliance systems and reporting.

Essential Functions:

Compliance Program Execution

  • Execute and continuously improve enterprise security compliance processes and assessments, supporting the strategic direction established by the Manager.
  • Operate and maintain the security compliance technology platform, ensuring assessments, evidence collection, and issue tracking are completed accurately and on schedule.
  • Coordinate compliance assessment activities and ensure required documentation is complete and aligned with standards.
  • Create, manage, and maintain standardized templates, procedures, workflows, and reporting to support consistent compliance operations.

Security Exception Management

  • Execute detailed assessments of security exception requests, documenting risks, mitigating controls, approvals, and expiration tracking, in accordance with governance defined by the Director.
  • Track exception approvals, expirations, and remediation requirements, ensuring timely reminders, escalations, and accuracy of exception data.

Security Issue Escalation & Tracking

  • Manage execution of the Security Compliance Finding and Issue Escalation process, ensuring control gaps and audit findings are documented, monitored, and remediated on schedule.
  • Maintain and operationalize workflow steps aligned to governance requirements defined by the Director, ensuring appropriate escalation of overdue or highrisk issues.
  • Align information security issue tracking with Enterprise Risk Management processes and escalate highrisk issues through established governance forums.

Documentation Governance

  • Oversee the Information Security documentation governance program, ensuring policies, standards, procedures, and guidelines are accurate, current, and aligned with regulatory, customer, and internal control requirements.
  • Implement and maintain the documentation lifecycle processes, including drafting, review, approval, publication, version control, retention, and retirement.
  • Coordinate updates to documentation to ensure alignment with applicable frameworks such as CRI, NIST CSF, PCI DSS, and CIS 18, reflecting changes in technology, controls, and risk posture.
  • Track documentation quality, exceptions, gaps, and remediation activities; prepare reports and metrics to support leadership visibility and compliance oversight.
  • Partner with security, risk, IT, and compliance stakeholders to ensure documentation supports audits, assessments, and ongoing control operation.

Education and Experience

  • 8+ years of experience in information security, risk management, compliance, or related disciplines.
  • Bachelor's degree in IT or related field preferred or equivalent work experience in lieu of degree.
  • Working knowledge of security frameworks such as Cyber Risk Institute, NIST CSF, CIS Controls, and PCI DSS along with experience applying these and other industry-specific regulations to projects and infrastructure.
  • Experience in collaborating across diverse teams, including IT, business units, and external stakeholders, to address security requirements and align with project objectives.
  • Strong understanding of security risk assessment methodologies, controls implementation, and process optimization, with a track record of successfully mitigating risks and enhancing security practices.

Summary of Qualifications:

  • Strong working knowledge of major security frameworks and regulatory requirements, including CRI, NIST CSF, PCI DSS, and CIS Controls, with experience aligning compliance platforms to support assessments and evidence management.
  • Skilled in optimizing compliance workflows, dashboards, templates, and reporting to enhance operational efficiency and audit readiness.
  • Proficient with core security technologies such as vulnerability management, encryption, and identity and access management.
  • Strong analytical and communication skills, able to identify trends, explain complex technical and regulatory concepts, and support crossfunctional collaboration.
  • Highly organized, detailoriented, and capable of managing multiple priorities while improving processes, automation, and program scalability.

Ideally, the qualified candidate will work at the following location(s): Woodbury, NY; South Jordan, UT; Horsham, PA; Pittsburgh, PA; Orlando, FL. A hybrid work model or fully remote model can be considered based on hiring manager decision and priorities of the role.

The salary range for this position, if located in NY Metro/NY State is $128,490 to $142,767. However, please note that the salary range will vary for other geographic areas.

#INDHP

Our Employee Value Proposition

  • Competitive Pay, including a Bonus Target or Variable Pay Incentive Program
  • Benefits Package -Medical, Dental, and Vision (plus much more)
  • 401(k) Plan with Company Match
  • Short- & Long-Term Disability
  • Wellness Programs
  • Group Life and AD&D Insurance
  • Paid Vacation, Sick Days and bank Holidays
  • Employee Engagement Activities including Employee Appreciation Day, DEI Employee Resource Groups, Corporate Social Responsibility, Service Recognition

We offer a total rewards package comprised of a competitive base rate of pay, variable pay incentive programs based on the role, and a comprehensive benefit suite. Offered rates of pay are determined based on job-related knowledge, relevant experience, skills, certifications, and geographic location.


We are proud to be an equal opportunity employer. All qualified applicants will receive consideration without regard to age, race, color, sex, or gender identity/expression (including pregnancy, childbirth, transgender status, or sexual orientation), religion or creed, ancestry, citizenship, national origin, disability, military or veteran status, marital status, genetic information, or any other characteristic protected by applicable law.

We do not tolerate discrimination, harassment, or retaliation. Employment decisions are based solely on qualifications, merit, and business needs. Everyone is welcome here, and we hire based on your ability to do the job, not any protected characteristics.

If you need help or reasonable accommodation during the application or hiring process, please let your TA Partner know.



What CardWorks employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom