1

Grc Director Jobs (NOW HIRING)

... direct client interaction skills is critical • Ability to multitask and adapt to new domains Qualifications • Skill set keywords: Archer;GRC;XSLT;WEBAPI;RESTAPI;Compliance Management;Audit ...

We seek a GRC Strategy & Security Insights Lead to drive a data driven shift in our GRC program. This role is positioned where strategy, action, and communication meet. Translate security priorities ...

Experienced or Senior GRC Analyst

Fort Worth, TX · Remote

$84K - $111K/yr

This role requires direct accountability for work product and outcomes. If your experience has been ... If you are confident in your GRC expertise, this is your opportunity to show it. Why Hotman Group ...

Senior Security GRC Analyst

San Mateo, CA · On-site

$209K - $271K/yr

GRC partners closely with Engineering, Legal, Finance, and leadership - including providing regular reporting to the Board of Directors and the Audit & Compliance Committee - to ensure that security ...

GRC Lead

New York, NY · On-site

$232K - $273K/yr

We fight for excellence: high standards, direct, ego-free feedback. * We grow together: as a team ... Your peer, the AI GRC Engineer, builds the platform underneath - the evidence pipelines and agents ...

We seek a GRC Strategy & Security Insights Lead to drive a data driven shift in our GRC program. This role is positioned where strategy, action, and communication meet. Translate security priorities ...

We seek a GRC Strategy & Security Insights Lead to drive a data driven shift in our GRC program. This role is positioned where strategy, action, and communication meet. Translate security priorities ...

Showing results 41-60

Grc Director information

What are some common challenges a GRC Director faces when aligning compliance initiatives across multiple departments?

A GRC Director often encounters challenges such as differing departmental priorities, varying levels of compliance awareness, and inconsistent processes. Successfully aligning compliance initiatives requires strong communication, the ability to build consensus, and the development of standardized frameworks that can be adapted across departments. Regular cross-functional meetings and ongoing training can help overcome these barriers and ensure that all teams are working towards the same compliance objectives.

What is the difference between Grc Director vs Compliance Manager?

AspectGrc DirectorCompliance Manager
CredentialsCertifications like CRISC, CISA, or CISM often preferredSimilar certifications, often CCEP or CISA
Work EnvironmentOversees enterprise-wide risk, governance, and compliance strategiesFocuses on specific compliance programs within organizations
Industry UsageCommon in finance, healthcare, and large corporationsWidespread across industries, especially regulated sectors
Search IntentUnderstanding high-level risk and governance rolesLooking for specific compliance responsibilities

The Grc Director typically manages enterprise risk, governance, and compliance strategies at a high level, requiring broader oversight and strategic planning. In contrast, a Compliance Manager focuses on implementing and maintaining specific compliance programs within an organization. Both roles require similar certifications and are prevalent in regulated industries, but the Grc Director has a wider scope and strategic responsibilities.

What are the key skills and qualifications needed to thrive as a GRC Director?

To thrive as a GRC Director, you need deep knowledge of governance, risk management, and compliance frameworks, often supported by a relevant degree and certifications such as CISA, CRISC, or CISSP. Expertise with GRC software platforms, regulatory databases, and risk assessment tools is typically required. Exceptional leadership, strategic thinking, and communication skills enable effective cross-functional collaboration and influence at the executive level. These capabilities are critical for ensuring organizational resilience, regulatory adherence, and informed decision-making across the enterprise.

What does a GRC Director do?

A GRC Director oversees an organization’s Governance, Risk, and Compliance (GRC) programs. They are responsible for developing strategies and policies to ensure the company meets regulatory requirements, manages risks effectively, and maintains strong corporate governance. This role involves coordinating cross-functional teams, implementing compliance frameworks, and reporting to senior leadership on risk exposures and controls. The GRC Director also stays updated on changing regulations and industry best practices to protect the organization from legal and reputational risks.

Are GRC director jobs hard to get?

GRC Director roles are competitive and typically require extensive experience in governance, risk management, and compliance, along with relevant certifications such as CISA or CISSP. Strong leadership skills and knowledge of regulatory frameworks can improve chances, but the position often demands a proven track record in managing complex security and compliance programs.
More about Grc Director jobs

What cities are hiring for Grc Director jobs?

Cities with the most Grc Director job openings:

What are the most commonly searched types of Grc jobs?

The most popular types of Grc jobs are:

What states have the most Grc Director jobs?

States with the most job openings for Grc Director jobs include:

Infographic showing various Grc Director job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 85% Full Time, 12% Part Time, 1% Temporary, and 1% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution.

Senior Cyber Security & GRC Engineer

Emergent Staffing

Hartford, CT • On-site

$130 - $180/hr

Other

Posted 8 days ago


Job description

**This position is a direct hire for one of our clients. Our ideal candidates live in the Hartford, Connecticut metro area. East coast & TX candidates will be considered with expectations of occasional travel to Connecticut. Eligible candidates must currently reside in the US and authorized to work in the US without visa sponsorship.**

Our client is seeking an experienced Cyber Security & GRC Engineer to lead and mature an enterprise-wide cybersecurity, governance, risk, and compliance (GRC) program across multiple organizations. This is a senior-level, hands‑on leadership role responsible for developing a unified security and compliance framework that supports NIST CSF 2.0, GDPR, and SOX IT General Controls requirements.

The ideal candidate combines strategic leadership with technical expertise, comfortably engaging executive stakeholders and auditors while also administering security tools, managing risks, implementing controls, and driving compliance initiatives. This role will serve as the owner of the enterprise GRC platform, Vanta, ensuring continuous monitoring, audit readiness, and program maturity across all entities.

Responsibilities
  • Own and mature the enterprise cybersecurity and risk management program across a multi‑entity organization.

  • Design, implement, and maintain a harmonized control framework supporting NIST CSF 2.0, GDPR, and SOX ITGC requirements.

  • Lead enterprise governance activities, including risk reviews, KPI/KRI reporting, executive reporting, and steering committee meetings.

  • Serve as the primary liaison for auditors, assessors, clients, and internal stakeholders regarding security and compliance matters.

  • Administer and optimize Vanta as the enterprise GRC system of record.

  • Configure controls, integrations, tests, evidence collection, continuous monitoring, and audit workflows within Vanta.

  • Develop, maintain, and manage enterprise security policies, standards, procedures, exceptions, and policy lifecycle processes.

  • Lead SOX ITGC readiness and compliance efforts.

  • Operationalize GDPR requirements, including records of processing, DPIAs, data subject rights management, vendor oversight, and breach response.

  • Conduct NIST CSF 2.0 assessments, maturity reviews, gap analyses, and remediation planning.

  • Manage enterprise risk assessments, risk registers, third‑party vendor risk programs, and remediation initiatives.

  • Oversee vulnerability management, patch coordination, access reviews, and technical security controls across cloud and on-premises environments.

  • Lead incident response activities, including preparation, detection, containment, recovery, and post‑incident reviews.

  • Provide security architecture guidance for new systems, integrations, cloud solutions, and data platforms.

  • Build and manage security awareness, phishing simulation, and employee training programs.

  • Partner with business and project teams to ensure security and privacy requirements are incorporated into solution design.

Required Qualifications
  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or equivalent experience.

  • 7+ years of information security, cybersecurity, or risk management experience with progression into senior program ownership responsibilities.

  • Hands‑on experience administering a GRC platform, preferably Vanta.

  • Experience implementing, operating, or auditing against NIST CSF, SOX ITGC, and GDPR requirements.

  • Demonstrated success developing and implementing security policies, controls, and governance programs.

  • One or more of the following certifications: CISSP, CISM, CRISC, or CISA.

  • Strong technical knowledge of cloud security, identity and access management, endpoint security, vulnerability management, logging, and security operations.

  • Excellent communication skills with the ability to engage technical teams, business leaders, auditors, and executives.

  • Proven ability to work independently, manage multiple priorities, and drive accountability across stakeholders.

Nice to Have Experience
  • Direct Vanta administration experience.

  • Experience supporting a publicly traded company and SOX Section 404 compliance requirements.

  • Experience leading security programs across multiple organizations or business entities.

  • ISO 27001 Lead Implementer or Lead Auditor certification.

  • SANS/GIAC certifications.

  • Construction, engineering, energy, power generation, or EPC industry experience.

  • Familiarity with AI/ML governance, data security, and secure AI deployment practices.

#J-18808-Ljbffr