Governance, Risk and Compliance Manager
About the role
The Governance, Risk, and Compliance Manager oversees and advances the organization’s governance, risk, and compliance program, ensuring that cybersecurity policies, control frameworks, vendor diligence processes, audit activities, and documentation standards consistently support secure and risk-informed operations.
Responsibilities
- Provide leadership and structure to PSRS/PEERS’ GRC functions.
- Oversight of day-to-day GRC operations, ensuring governance priorities align with organizational objectives and that GRC deliverables meet program standards for accuracy and quality.
- Build and supervise a team of analysts to support GRC functions as the program matures.
- Owning the cybersecurity policy and standards lifecycle by maintaining policies, evaluating exceptions, managing expirations, and ensuring compensating controls are properly documented.
- Maintain completeness and accuracy of incident response documentation, update playbooks, and coordinate tabletop exercises while ensuring action items resulting from exercises are addressed.
- Erect and enforce documentation standards that ensure SOPs, runbooks, and other operational materials adhere to required versioning, evidence, and repository guidelines.
- Maintain alignment with CISO-selected cybersecurity frameworks by documenting control mappings, assessing sufficiency, maintaining the control catalog, and managing the compliance calendar.
- Monitor organizational adherence to policies, maintain issue and exception registers, develop security reporting for leadership, and support Legal and IT departments in areas such as data governance, eDiscovery preparation, and preservation coordination.
- Cultivate a strong culture of governance, accountability, and continuous improvement, guiding staff development and contributing to long-term GRC program planning and budgeting.
Requirements
- Bachelor’s degree or equivalent experience in business, accounting, audit, information systems, public policy, cybersecurity, or related fields.
- Minimum of 8 years of experience in governance, risk, and compliance, audit or compliance functions, cybersecurity risk, or closely related professional areas.
- Proven experience with cybersecurity control frameworks such as NIST CSF, NIST 800-53 or 800-171, ISO 27001, or CIS Controls, along with familiarity with regulatory requirements such as HIPAA.
- Strong knowledge of third-party risk practices, including inherent risk assessment, evidence review, and remediation tracking.
- Ability to translate complex cybersecurity topics into clear, business-focused guidance that informs decisions across the organization.
- Ability to work effectively with stakeholders across functions, build strong and collaborative relationships, and communicate confidently with both technical and non-technical audiences.
- Demonstrated skill in supervising and mentoring team members.
Qualifications
- Relevant certifications such as CISA, CRISC, CGRC, ISO 27001 Lead Implementer/Lead Auditor, CISSP, or CISM are not required but are considered highly valuable for this role.
Benefits
PSRS/PEERS offers a comprehensive benefits package including a robust Health Savings Account (HSA), dental and vision coverage, and membership in a defined benefit pension plan that provides lifelong retirement benefits after just five years of vesting. Time off is generous—employees start with three weeks of paid vacation and three weeks of sick leave annually, in addition to 12 paid holidays each year. We also invest in your growth, offering tuition assistance, ongoing training, and professional development opportunities. High-performing team members may be invited to participate in our leadership development program. Beyond professional development, we foster a sense of community and connection through on-site and off-site events, volunteer initiatives, and employee-driven charitable efforts organized by our employee fund—creating countless ways to get involved and stay engaged.