Manager, Governance, Risk & Compliance
ACM Global Laboratories · United States · 2 days ago
RemoteRemoteSales$115k–$140k/yrFull-time
About the role
The Governance, Risk & Compliance [GRC] Manager at ACM Global Laboratories translates strategic direction into actionable workflows, coordinates cross-functional teams, supports evidence lifecycle management, maps frameworks to control implementation, leads readiness activities, and ensures all ACM GRC processes operate smoothly and efficiently.
Responsibilities
- Leads the GRC program activities and a team of professionals related to third-party risk, security internal audit, security compliance, and ISMS program management.
- Develop, document, and implement internal policies and procedures to ensure compliance with industry standards and legal requirements.
- Facilitate regular risk assessments against security frameworks such as SOC 2, ISO 27001, and PCI-DSS, maintain a risk register, and collaborate on mitigation strategies for identified threats.
- Manage CAPAs for non-compliance.
- Define specific, assignable actions to mitigate the identified risks or exploit the opportunities.
- Evaluate how to embed the planned actions directly into daily operational processes.
- Manage security responses to client questions and questionnaires, including RFPs, RFIs, annual risk reviews, and ad-hoc communication requests.
- Manage and update business continuity and disaster recovery documentation, including BIAs, plan revisions, team rosters, and dependencies.
- Plan, coordinate, and document annual exercises, such as tests, tabletops, and other exercises.
- Build and manage a security metrics (KPI’s) program.
- Develop relationships with cross-functional teams, understanding their needs in relation to security standards, to drive risk-informed decision-making and build a culture of compliance.
- Provide expert guidance and support in navigating complex regulatory environments in relation to the management of alignment to ISO-27001 and other applicable security frameworks.
- Stay updated on applicable industry trends and regulations to ensure ISMS compliance.
- Monitor and analyze GRC processes and systems, making recommendations for improvement.
- Document risk reduction plan.
- Annually, document “Opportunities” (potential positive improvements like adopting some technology for improved efficiency).
Qualifications
- Minimum of 5 years of experience leading Governance, Risk, and Compliance (GRC) programs.
- Proficiency in ISO 27001
Preferred Qualifications
- GRC certifications (e.g. CGRC, CRISC, etc)
- A bachelor’s degree in IT, cybersecurity, business, or law is preferred, or strong demonstrable background in GRC Management.
- Previous experience in GRC, risk management, or internal audit, often with a mid-level leadership background.
- Proficiency in frameworks like SOC2, NIST CSF, and HIPAA regulations.
- Strong ability to analyze risk data and translate complex regulations into actionable controls.
- Excellent communication skills to interact with stakeholders and lead team efforts.
- Experience with 3rd party/vendor risk management processes.
- Experience in working with sales teams to complete Requests for Proposals and security questionnaires.
- Understanding of GRC processes such as policy management, risk assessment, and IT audits.
- Exceptional verbal and written communication skills.
Pay
The pay range for this position is $115,000.00 - $140,000.00, determined by factors including experience, relevant qualifications, specialty, internal equity, location, and contracts.