1

Grc Project Manager Jobs in Oregon (NOW HIRING)

OR ยท On-site

By unifying SecOps and GRC, this leader ensures timely threat mitigation, streamlined audit ... Third-Party & Project Oversight: Manage third parties, including managed security service providers ...

OR

$60K - $70K/yr

Workflow & Project Management * Execute long-term projects against milestones; mature workflows to ... OneTrust Tech Risk and Compliance GRC experience. * Progress toward CompTIA Security+, healthcare ...

... GRC) , to join our rapidly growing and innovative cybersecurity team. Named one of the Best Places ... Provide Project management support following industry standards, frameworks, and methodologies to ...

OR ยท On-site

$114K - $156K/yr

... GRC functions. This capability exists to solve a real problem: as we scale and mature, we must move ... Partner with our risk management function to build a secure mechanism to generate agentic risk ...

OR ยท On-site

... GRC. Our team is looking for an experienced, hands-on security practitioner, who will drive the ... Develop processes, tooling and automation to scale incident management response and mitigate risks ...

Ability to manage multiple priorities and work independently to achieve production goals. * Comfort working directly with both project team members and client counterparts. * Experience with GRC ...

ETP Specialist

Medford, OR ยท On-site

$65K - $70K/yr

Disseminate fund corporate action notifications to APs * Assist with other assigned projects To ... GRC and protect and grow their businesses. Our innovative approach integrates consulting, managed ...

Senior ServiceNow Developer III

Portland, OR ยท Remote

$92K - $143K/yr

Demonstrated project management skills * Ability to work on several concurrent tasks and prioritize ... Expertise in GRC/IRM is highly preferred * College Degree or equivalent work experience preferred ...

next page

Showing results 1-20

Grc Project Manager information

Is GRC a GRC Project Manager job?

A GRC Project Manager is a role responsible for overseeing governance, risk management, and compliance initiatives within an organization. The position typically requires project management skills, knowledge of GRC frameworks, and relevant certifications such as CISSP or CISA. It involves coordinating teams, managing timelines, and ensuring regulatory requirements are met.

How does a GRC Project Manager typically collaborate with cross-functional teams to implement compliance initiatives?

A GRC Project Manager works closely with departments such as IT, Legal, Risk, and Internal Audit to ensure that governance, risk management, and compliance initiatives are effectively integrated across the organization. This role involves facilitating regular meetings, aligning project goals with organizational policies, and clearly communicating regulatory requirements to various stakeholders. The GRC Project Manager often serves as a liaison, translating technical or legal concepts into actionable tasks for different teams, and ensuring that project milestones are met while maintaining compliance standards.

Are GRC project manager jobs hard to get?

GRC project manager jobs can be competitive, especially for roles requiring experience in governance, risk management, and compliance frameworks. Strong skills in project management, relevant certifications like PMP or CISA, and knowledge of tools such as RSA Archer or ServiceNow can improve job prospects. Entry-level positions may be easier to obtain, but advanced roles typically require several years of experience.

What are the key skills and qualifications needed to thrive as a GRC Project Manager, and why are they important?

To thrive as a GRC Project Manager, you need expertise in governance, risk management, compliance frameworks, and project management methodologies, often supported by a bachelor's degree and certifications like PMP or CISA. Familiarity with GRC software platforms, risk assessment tools, and regulatory compliance systems is typically required. Exceptional organizational, leadership, and stakeholder communication skills help drive cross-functional projects and adapt to changing regulatory landscapes. These competencies are crucial for ensuring projects meet compliance objectives, mitigate risks, and deliver organizational value.

What is the difference between Grc Project Manager vs Grc Analyst?

AspectGrc Project ManagerGrc Analyst
CertificationsISO 27001 Lead Implementer, PMP, CISACISA, CRISC, CISSP
Work EnvironmentOversees projects, manages teams, coordinates compliance effortsAnalyzes risks, assesses controls, supports compliance activities
Employer & Industry UsageFinancial, healthcare, technology sectorsFinancial institutions, consulting firms, tech companies
Search & Comparison IntentUnderstanding project management roles in GRCUnderstanding analytical roles supporting GRC projects

The Grc Project Manager focuses on leading GRC initiatives, managing teams, and ensuring project delivery. The Grc Analyst supports these efforts by analyzing risks, evaluating controls, and providing compliance insights. Both roles require similar certifications and are integral to GRC efforts, but they differ in scope and responsibilities within organizations.

What are popular job titles related to Grc Project Manager jobs in Oregon? For Grc Project Manager jobs in Oregon, the most frequently searched job titles are:
What cities in Oregon are hiring for Grc Project Manager jobs? Cities in Oregon with the most Grc Project Manager job openings:
Infographic showing various Grc Project Manager job openings in Oregon as of June 2026, with employment types broken down into 87% Full Time, 12% Part Time, and 1% Contract. Highlights an 76% Physical, 8% Hybrid, and 16% Remote job distribution.

Principal, Public Sector SecOps & GRC

Consensus Cloud Solutions

OR โ€ข On-site

Full-time

Re-posted 4 days ago


Job description

How you will impact the organization...

The Principal, Public Sector SecOps & GRC serves as the central security and compliance leader for all public sector engagements, encompassing federal, state, and local mandates. Evolving from a purely compliance-focused mandate, this role bridges Security Operations (SecOps) and Governance, Risk, and Compliance (GRC) to ensure comprehensive defense and continuous authorization across Consensus' public sector SaaS platforms.

This role is vital to Consensus' mission of providing secure and trusted communication solutions to public sector partners. The Principal leads the design, implementation, and oversight of a unified security framework that aligns with NIST 800-53 Rev. 5 controls, FedRAMP High authorizations, GovRAMP, CMMC, and emerging SLED requirements (such as TexasRAMP and StateRAMP). By unifying SecOps and GRC, this leader ensures timely threat mitigation, streamlined audit processes, and the secure delivery of cloud services to government agencies at all levels.

The value you will deliver...

  • Public Sector GRC Leadership: Lead the design, implementation, and ongoing management of a unified GRC program encompassing FedRAMP High Rev. 5, GovRAMP, CMMC, and SLED/StateRAMP frameworks.
  • Continuous Monitoring & Reporting: Compile and submit Monthly Continuous Monitoring (ConMon) reports, including vulnerability scans, POA&M trackers, and asset inventories for all applicable public sector frameworks.
  • Vulnerability & SecOps Management: Oversee threat hunting and vulnerability remediation to ensure compliance with strict federal timelines, specifically: High (30 days), Moderate (90 days), and Low (180 days).
  • POA&M Escalation: Escalate unremediated vulnerabilities and initiate Plan of Action and Milestones (POA&M) creation within 7 days of issue identification when remediation deadlines cannot be met.
  • Audit Coordination: Coordinate and lead Annual 3PAO Security Assessments, including penetration testing and red team exercises, across FedRAMP and other public sector programs.
  • Artifact Management: Manage and maintain a compliant, hosted secure repository for storing, retrieving, and provisioning access to security packages and artifacts.
  • Third-Party & Project Oversight: Manage third parties, including managed security service providers (MSSPs) performing public sector security functions, and direct project management support for these programs.
  • System Stewardship: Serve as System Steward for the VA-F package in eMASS, managing Risk Management Framework (RMF) activities, ATO assessments, and workflows.
  • Marketplace Maintenance: Submit and maintain accurate documentation for the initial and ongoing marketplace listings (e.g., FedRAMP, StateRAMP) of Consensus as a Cloud Service Provider (CSP).
  • Incident Response Operations: Oversee actionable incident response testing every 6 months , and administer incident response training to all assigned personnel within 10 days of role assignment and annually thereafter.
  • Access & Trust Governance: Oversee background checks and reinvestigations for all personnel requiring system access, consistent with high-impact public trust requirements , and enforce Rules of Behavior agreements.
  • Architecture & Change Control: Maintain current SaaS platform architecture diagrams and submit all Security Change Requests (SCRs) and Deviation Requests for approval.
  • Commercial Framework Integration: Contribute to non-FedRAMP commercial compliance frameworks, such as ISO 27001, SOC 2, or HIPAA, ensuring unified control mappings across public and private sector services.
  • Cross-Functional Enablement: Provide security and compliance guidance to IT, engineering, and development teams to support the design of secure, compliant, and resilient cloud-based architectures.
  • Tooling & Automation: Identify, evaluate, and implement GRC and SecOps tools that support policy automation, identity management, and threat intelligence.
  • Customer Trust: Assist with responses to customer security assessments and third-party due diligence requests from prospective SLED and federal agencies.
  • Mentorship: Mentor junior staff or cross-functional team members in information security, compliance best practices, and secure development lifecycles.
  • Resilience Planning: Support business continuity planning, disaster recovery documentation, and live operational exercises.
  • Perform other duties and responsibilities as required, assigned, or requested. Consensus reserves the right to add or change duties at any time.

What you will bring to the table...

  • Required Degree: Bachelor's degree in computer science, information technology, or cybersecurity.
  • Required Certifications: Active Certified Information Systems Security Professional (CISSP) and Project Management Professional (PMP) certification.
  • Required Background Checks: Undergo a Public Trust Background Investigation with a favorable suitability determination.
  • 8+ years of experience in information security governance, risk, and compliance, with at least 5 years specifically supporting FedRAMP High, FISMA, NIST SP 800-53 rev 5, or RMF.
  • 5+ years in the ISSM or ISSO role managing the security package for federal government agencies high-impact systems.
  • 5+ years of experience managing or supporting security assessments with Third Party Assessment Organizations (3PAOs).
  • 3+ years of hands-on experience using GRC platforms (e.g., RSA Archer, ServiceNow GRC, OneTrust) and vulnerability management platforms (e.g., Tenable, Qualys, Rapid7).
  • 2+ years direct experience mapping controls and leading assessments for GovRAMP, CMMC (Level 2+), and StateRAMP/SLED requirements.
  • 2+ years of experience with identity and access management systems (e.g., Okta, Azure AD) for access control governance.
  • Cloud Architecture Proficiency: Demonstrated experience working within cloud environments such as AWS GovCloud or Azure Government, including cloud-native security controls.
  • Systems & Tooling Mastery: Proficiency with AWS CLI, Powershell and scripting automated compliance tasks in Windows and Linux systems tools, Nessus Pro, Burp Suite, Splunk, AWS IAM, Jira, FortiGate firewalls, eMASS, Box.com for Gov, and Okta for Gov Identity Provider.
  • Analytical Critical Thinking: Demonstrates strong analytical skills to assess complex security risks, interpret compliance requirements, and evaluate technical vulnerabilities.
  • Process Engineering: Builds and refines repeatable, auditable processes for security governance, risk management, and compliance activities.
  • Cross-Functional Communication: Communicates clearly and effectively with technical and non-technical stakeholders, including auditors, developers, and executive leadership.
  • Continuous Assessment: Ability to implement continuous monitoring and assessment programs to identify and address security threats in real-time, maintaining a proactive SecOps stance.

Additional details...ย 

  • Location requirements: Fully remote within the U.S.ย 
  • Travel requirements: Up to 10% travel.ย 
  • Physical requirements: Must be able to sit for long periods, as well as, handle long periods of screen time.
  • Technology requirements: Reliable, high speed internet.
  • Eligible for sponsorship: No.
  • This position is contingent upon satisfactory completion of a more extensive background check through the Federal Government as a Public Trust Position. Requirements include (subject to change), but are not limited to, active U.S. Citizenship or green card holder residing in the U.S. for a minimum of 3 consecutive years and working location is in the U.S.


The salary range for this role is $160,000 - $170,000 USDย annually.ย  The total compensation package for this position is negotiable and may also include annual performance bonus, ESPP, enhanced time off packages and benefits. This job doesn't have an expiration date and will remain open until a qualified candidate is hired.ย