Manager, GRC

3 weeks ago


Overland MO United States Clayco Full time

About Us

Clayco is a full-service, turnkey real estate development, master planning, architecture, engineering, and construction firm that safely delivers clients across North America the highest quality solutions on time, on budget, and above and beyond expectations. With $5.8 billion in revenue for 2023, Clayco specializes in the "art and science of building," providing fast track, efficient solutions for industrial, commercial, institutional, and residential related building projects.


The Role We Want You For

Under the direction of the CISO, the Governance, Risk Management, & Compliance (GRC) Manager is a process-oriented, Risk-focused leadership role that ensures that all Risk exposure to Clayco Information Assets is identified, documented, communicated, and treated to an acceptable level across the Clayco organization. This role will also manage the GRC team’s efforts to educate Clayco Employees on current user-relevant threats and Risks, ways to identify them, and their proper responses which includes simulated testing to measure retention and gaps.


The GRC Manager will also regularly evaluate operating environments, processes, capabilities, controls, and configurations for their compliance levels relative to Clayco’s current policies, adopted Frameworks and Standards, and any applicable Laws, Regulations, or contractual commitments. This includes contribution to our quarterly assessment and reporting of Clayco’s Cybersecurity Posture Maturity.


Any travel is usually planned in advance, but issues may arise which warrant immediate travel to one or more satellite locations.



The Specifics of the Role

  • Ensures that ALL identified Risks, vulnerabilities, non-compliance, and misconfigurations are captured, assessed, prioritized, and communicated in a timely and effective manner to ensure foreseeable, negative impact to the Business is avoided
  • Manages and contributes to the Enterprise Risk Register, ensuring Risk statements are documented, Risks are entered with appropriate quantification, rating, and tracking with regular reporting on high-severity risks to leadership
  • Manages and contributes to the Controls Catalog to ensure that control objectives align with our adopted Frameworks and Standards as well as any Regulatory or contractual requirements
  • Manages and contributes to Third-Party Risk Management (TPRM) by evaluating Vendor Risk, maintaining Vendor assessments, and managing protocols to ensure appropriate treatment of Risk is communicated and executed for reduction to acceptable levels
  • Manages and contributes to the analysis, benchmark testing, monitoring, and occasional audit of production Systems and Services configuration and control deployment to determine compliance with Policies, Regulations, and contractual commitments
  • Manages and contributes to the tracking, monitoring, and reporting on performance metrics and status of remediation action plans including the escalation of inadequate response
  • Manages and contributes to the Security Awareness Program to include curation of online training content, Phishing simulation campaigns, and coordination of engagement events and associated communication to the user base for Cybersecurity-related special events
  • Coordinates and contributes to Third-Party audits and assessments to gather and submit discovery and transactional responses and artifacts as required per engagement
  • Identifies and reports findings, trends, and activities that may indicate a need for change in policies, procedures, internal controls, or training
  • Collaborates cross-functionally with other Information Technology teams and Business Stakeholders across the Organization
  • Disseminates changes in related Regulations or Security Frameworks and Standards, and the application of such changes to current policies, procedures or processes to appropriate staff
  • Contributes to major organizational initiatives to ensure new Systems and Services align with existing policies, regulations, and contractual commitments



Requirements

  • 8+ years’ experience in GRC, Information Security, or Audit & Compliance roles
  • 3+ years’ experience in a Management or Lead capacity within GRC or similar discipline
  • Bachelor’s degree in Information Technology, Cybersecurity, or related field (Master’s preferred) or equivalent experience.
  • Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified in Risk & Information Systems Control (CRISC), GIAC Critical Controls Certification (GCCC), and Certified NIST Cybersecurity Framework 2.0 Lead Implementer (CSF LI); current status or obtained within 12 months of assuming role
  • Strong understanding of requirements to ensure effectiveness and compliance with all applicable Regulations, Frameworks, and Standards (ITAR/EAR, CCPA/CPRA, NIST 800-171 & CSF, CIS Critical Controls as well as familiarity with PCI DSS and HIPAA)
  • Strong experience leveraging auditing principles and methods to evaluate policies, processes, Systems, and Services to identify business risks and control gaps
  • Experience drafting and implementing policies and processes to ensure compliance
  • Experience in Enterprise Client-Server, Cloud, & IoT Hybrid environments and knowledge of how various technologies and processes interact and behave.
  • Experience with administering compliance programs and maintaining a Risk Register and related GRC tools to track and communicate identified Risks and recommended treatments
  • Knowledge of statistics, reporting and analytical tools to analyze and solve complex problems
  • Operate with strong integrity with ability to handle projects of a sensitive & confidential nature
  • Exceptional communication skills, capable of translating technical details into business insights for diverse audiences.
  • Ability to thrive in a fast-paced environment.



Some Things You Should Know

  • No other builder can offer the collaborative design-build approach that Clayco does.
  • We work on creative, complex, award-winning, high-profile jobs.
  • The pace is fast


Why Clayco?

  • Best Places to Work – St. Louis Business Journal, Los Angeles Business Journal, Phoenix Business Journal.
  • ENR – Top Midwest Contractors (#1), Top Design Build Contractors (#4), Top 400 Contractors (#23), ENR – Top Green Builders (#5).


Compensation and Benefits

  • Competitive Annual Salary: Based on qualifications, skills, training, experience, and location.
  • Discretionary Annual Bonus: Subject to company performance and individual contribution.
  • Comprehensive Benefits Package Including: Medical, dental and vision plans, 401k, generous PTO and paid company holidays, employee assistance program, flexible spending accounts, life insurance, disability coverage, learning & development programs and more

  • Manager, GRC

    3 weeks ago


    Overland, United States Clayco Full time

    About UsClayco is a full-service, turnkey real estate development, master planning, architecture, engineering, and construction firm that safely delivers clients across North America the highest quality solutions on time, on budget, and above and beyond expectations. With $5.8 billion in revenue for 2023, Clayco specializes in the "art and science of...

  • IT GRC Manager WI

    7 days ago


    Madison, WI, United States Creative Financial Staffing Full time

    IT GRC Manager Position Overview: We are looking for a proactive and experienced IT Governance, Risk, and Compliance (GRC) Manager to become a key member of our team. In this position, you will oversee and enhance the organization's IT GRC program, with an emphasis on SOX compliance, application and data transfer controls, the accuracy and completeness of...

  • IT GRC Manager OH

    5 days ago


    Columbus, OH, United States Creative Financial Staffing Full time

    IT GRC Manager Position Overview: We are looking for a proactive and experienced IT Governance, Risk, and Compliance (GRC) Manager to become a key member of our team. In this position, you will oversee and enhance the organization's IT GRC program, with an emphasis on SOX compliance, application and data transfer controls, the accuracy and completeness of...

  • GRC Analyst

    3 weeks ago


    Shelton, CT, United States Ovise Full time

    Ovise is exclusively partnered with one of the largest restaurant and franchisee brands in the world! They are looking to build out their GRC function, and as a GRC analyst, you will be directly involved with this initiative.The GRC Analyst will be responsible for assessing, managing, and mitigating risks related to an organization's information assets. This...

  • Senior GRC Analyst

    3 weeks ago


    Overland, MO, United States Clayco Full time

    About UsClayco is a full-service, turnkey real estate development, master planning, architecture, engineering, and construction firm that safely delivers clients across North America the highest quality solutions on time, on budget, and above and beyond expectations. With $5.8 billion in revenue for 2023, Clayco specializes in the "art and science of...


  • Ashburn, VA, United States Infinitive Full time

    *Candidates must be local to the Washington D.C. metro area. About Infinitive:Infinitive is a data and AI consultancy that enables its clients to modernize, monetize and operationalize their data to create lasting and substantial value. We possess deep industry and technology expertise to drive and sustain adoption of new capabilities. We match our people...


  • Atlanta, GA, United States Delta Air Lines, Inc. Full time

    How you'll help us Keep Climbing (overview & key responsibilities) Join Delta IT on our journey to becoming the best IT organization in the airline industry. Delta IT is on a journey of transformation. We are changing the way we do business from top to bottom. As thought leaders within Delta, we strive to create meaningful and innovative solutions and are...


  • Atlanta, GA, United States Delta Air Lines, Inc. Full time

    How you'll help us Keep Climbing (overview & key responsibilities) Join Delta IT on our journey to becoming the best IT organization in the airline industry. Delta IT is on a journey of transformation. We are changing the way we do business from top to bottom. As thought leaders within Delta, we strive to create meaningful and innovative solutions and are...

  • GRC Platform Lead

    3 weeks ago


    New York, NY, United States Solomon Page Full time

    Our direct global corporate financials client is seeking to add a dynamic GRC Platform Product Lead to their team in a long term contract consulting capacity (possibility of conversion to FTE down the line for the right candidate). This role requires a hands-on leader who is equally comfortable driving execution, managing projects, and engaging with...


  • San Antonio, TX, United States Insight Global Full time

    Location: San Antonio, TXDuration: 12-Month Contract w/ extensions Required Skills & Experience- Bachelor’s degree in Cybersecurity, Information Technology, or a related field.-Minimum of 3 years of experience in a cybersecurity role with a focus on GRC.- Proficiency in CJIS system configurations and NIST controls.-Strong analytical, problem-solving, and...


  • McLean, VA, United States Convergenz Full time

    Risk / GRC Analyst - Capital Markets and Mortgage RequiredEnsuring they are compliant with Mortgage and Capital Markets guidelines. Risk assessments on a quarterly bases, issue remediation- helping team on incident write ups, operational breakdown, control testing, adhoc projects- process documentation, helping with Gap Assessments. More on compliance /...

  • Senior GRC Analyst

    2 months ago


    Overland, United States Clayco Full time

    About UsClayco is a full-service, turnkey real estate development, master planning, architecture, engineering, and construction firm that safely delivers clients across North America the highest quality solutions on time, on budget, and above and beyond expectations. With $5.8 billion in revenue for 2023, Clayco specializes in the "art and science of...

  • GRC Architect

    4 weeks ago


    Chicago, IL, United States Cognizant Full time

    Job Title : GRC Architect Location-Chicago, IL Roles and Responsibilities 1. Must have hands on experience in Security Domain. 2. Single point of contact for Compliance Requirement. 3. Delivery progress measurement, Weekly Dashboard and status reporting on project health to Client and Cognizant Leadership. 4. Perform security and compliance assessments on...


  • Chicago, IL, United States Request Technology, LLC Full time

    ***We are unable to sponsor for this permanent full-time role******Position is bonus eligible***Prestigious Financial Institution is currently seeking a GRC Compliance Monitoring Manager, preferably with RSA Archer experience. Candidate will provide execution and oversight for the programs that oversee compliance with regulatory and internal control...

  • Senior GRC Analyst

    3 weeks ago


    New York, NY, United States Cantor Fitzgerald Full time

    The Information Security-GRC (Governance Risk and Compliance) Team is looking for an experienced risk and compliance professional to help drive the efforts across Cybersecurity controls framework initiatives, such as user access recertification, policy management, vendor assessment and client due diligence. This role will also be responsible furthering...


  • Houston, TX, United States CDW Full time

    CDW has a large SAP implementation project going on and we are looking for an SAP Security Architect to consult with the SAP Authorization piece. Candidates must have SAP Authorization experience and must have SAP-GRC - specifically around Business Role management, EAM (emergency role management), and Kubernetes administration experience. This position is a...


  • York, PA, United States Comcast Corporation Full time

    FreeWheel, a Comcast company, provides comprehensive ad platforms for publishers, advertisers, and media buyers. Powered by premium video content, robust data, and advanced technology, we're making it easier for buyers and sellers to transact across all screens, data types, and sales channels. As a global company, we have offices in nine countries and can...


  • Farmington, MI, United States comerica Full time

    Risk Governance Reporting AnalystSeeking a professional to perform operational risk and third-party risk management reporting and analysis to improve effectiveness and efficiency. This Analyst will assume responsibility for creating reports for varying levels of the Bank in a timely and accurate manner as well as analyzing the data for trends indicating...

  • IT Security Manager

    6 months ago


    Overland Park, United States True North Consulting Full time

    Company Description Solid stable, long standing company that is very employee oriented with great benefits. They are one of the fastest growing companies in their space Job Description This is the perfect role to really put your mark on something. This is a newly created position, tasked with building a team to support the security vision of an entire...

  • Archer Administrator

    2 weeks ago


    Saint Paul, MN, United States Javen Technologies Full time

    Title: Archer Administrator Increase your chances of an interview by reading the following overview of this role before making an application. Location: Maplewood, MN Duration: 12+ Months Hybrid Role (preferable Tuesday, Wednesday, Thursday) Skills: Archer, Integrated Risk Management (IRM), Governance, Risk and Compliance (GRC), JIRA, Service Manager,...