Senior GRC Officer
Core
Senior GRC Officer managing U.S. governance, risk, and compliance programs including FedRAMP, CMMC, and SOC 2 for a law enforcement data analytics company.
Role type
Senior IC GRC Officer
Builds
Compliance documentation, evidence repositories, and security control implementations for U.S. government and enterprise clients.
Domain
Cybersecurity compliance and government contracting
Required skills
FedRAMP management, CMMC Level 2, NIST SP 800-53, risk management, vendor risk assessment, audit coordination, compliance documentation, gap analysis, stakeholder communication
Preferred skills
CMMC Level 2, SOC 2 Type 2, ISO 27001, TX-RAMP, CJIS, AWS/Azure cloud security, GRC platforms, vulnerability management
Technologies
FedRAMP, CMMC, NIST SP 800-53, SOC 2, ISO 27001, TX-RAMP, CJIS, AWS, Azure
Responsibilities
Manage FedRAMP and CMMC workstreams from readiness through Agency ATO; lead development of compliance documentation and serve as primary contact for assessors; coordinate implementation of security requirements across engineering and IT teams; own risk management and vendor risk assessment; plan and support external audits and regulatory inquiries; conduct internal compliance assessments and gap analyses; provide security guidance for business and technology processes. (via careerplan.io/jobs/E5-002-8C-F63-senior-grc-officer-at-penlink)
Seniority
Senior, hands-on IC