Cosm is seeking a seasoned Governance, Risk, and Compliance (GRC) professional to help lead and evolve our enterprise-wide security governance and risk management programs. Reporting to the Information Security Officer (ISO), you will define and operationalize GRC frameworks that ensure alignment with industry standards such as NIST CSF 2.0, SOX ITGC, and the Trusted Partner Network (TPN) content-security standard. You will operate and mature our enterprise risk register, oversee regulatory compliance, provide independent assurance over the controls that protect Cosm's platforms and creative content, and drive the policy development that strengthens our security posture and supports business growth, including our path toward IPO readiness. As an early member of a growing InfoSec team, you will have the opportunity to shape the GRC function from the ground up, with room to grow as the team and program mature. This role is expected to build and lead the GRC function as the program scales, including hiring and developing the team that supports it. The ideal candidate brings a strong background in IT controls, audit readiness, and cross-functional collaboration, along with a passion for fostering a culture of accountability, security, and continuous improvement.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Director