Reporting to the Chief Information Security Officer (CISO), the Risk & Compliance Manager is responsible for designing, implementing, and leading a modern enterprise cybersecurity Governance, Risk, Compliance (GRC) program. This role ensures continuous improvements of governance, risk, and compliance capabilities, and that cybersecurity risk is identified, measured, clearly understood, and managed in alignment with adopted frameworks, agency priorities, regulatory requirements, and overall technology strategy. The manager will continuously monitor the cybersecurity risk posture, perform gap analysis, and provide recommendations for compensating technical, administrative, and physical controls. They will track the agency's alignment to information security standards, collaborate with agency stakeholders to develop prescriptive guidance to reduce risk, and review policies, standards, procedures, controls documentation, and audit results. Additionally, this role manages third-party risk by maintaining an inventory of all technology providers and service organizations, performing continuous security posture monitoring, and overseeing the agency's security awareness program.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior