IT Security Governance, Risk, and Compliance

2 weeks ago


Washington, United States iTech AG Full time
Description

OVERVIEW

We are seeking a highly skilled and motivated IT Security Governance, Risk, and Compliance (GRC) Project Manager to join our team. The ideal candidate will lead the GRC initiatives, working closely with federal clients and internal teams to ensure effective governance, risk management, and compliance across all IT projects and services. This role requires a strategic thinker with strong project management skills and a deep understanding of IT security policies and regulations.

They should be familiar with managing a team and have experience in coaching and mentoring team members. They should be familiar with policy and compliance requirements for IT departments (federal government preferred) including policy documentation and system requirements to successfully respond to potential audits.

RESPONSIBILITIES

  • Lead the Governance Office team by managing the team's workload, assigning tasks, reviewing deliverables, meeting the goals of the Governance Office, and serving as the main POC for the team to federal clients.
  • Serve as the Governance POC for a portfolio of projects by assisting project teams in identifying governance or compliance requirements, assessing risks, reviewing required forms, and liaising between the project team and other subject matter experts.
  • Assist project teams with their response to regular audits and assessments to ensure compliance with IT security policies and regulations.
  • Design and implement standards and best practices in governance, risk, and compliance.
  • Maintain a working knowledge and guide the current Governance Office forms, processes, and documentation to internal and external project management teams.
  • Lead risk management activities, including identification and recommended mitigations; track and manage risks and issues from identification through closure.
  • Drive adoption of program management tools and techniques to improve reporting and compliance of IT projects and services.
  • Collaborate with senior leaders to ensure mission and business needs are met.
  • Communicate regularly with project or service teams.
  • Provide training and guidance to team members on GRC best practices and regulatory requirements.
  • Perform other duties as assigned
QUALIFICATIONS
  • At least seven (7) years of experience in Program Management.
  • Experience with IT enterprise services, processes, and/or requirements with a focus on developing roadmaps, establishing governance, and ensuring compliance.
  • Strong knowledge of GRC frameworks, methodologies, and best practices.
  • Strong problem-solving and decision-making abilities.
  • Experience assessing project and technical documentation to ensure compliance with established policies, processes, and procedures.
  • Ability to provide excellent written and oral communications by email, presentations, and mobile communication platforms (including experience facilitating discussions, briefing senior managers, and conducting project meetings).
  • Experience supervising or managing an Agile project team.
  • Experience defining project scope and objectives, developing detailed work products (schedules, status reports, etc.), conducting project meetings, and owning responsibility for project tracking and analysis.
  • Experience with continuous monitoring and Plans of Actions and Milestones (POA&Ms)
  • Able to work in hybrid posture; on-site (Washington DC) for 3 days and remote for 2 days.
  • Experience with SharePoint, O365 products, and Adobe products.
PREFERRED QUALIFICATIONS
  • Certification in IT Security or GRC (CISSP, CISM, CRISC, or equivalent) is preferred.
  • General understanding or awareness of the nuances relative to the federal government workspace (collaboration with specialized and functional teams/areas, approval chains for work review and acceptance) and formalities that impact governance - e.g., NIST Risk Management Framework (RMF) Authorization and Assessment (A&A) process
  • Project Management Professional (PMP)
  • Primary related work experience is within the Federal workspace.
  • Experience managing projects in JIRA.
  • Experience with federal IT security policies and regulations (preferred).
EDUCATION & CERTIFICATIONS
  • Bachelor's degree in information security, Information Technology, Business Administration, or a related field.
CLEARANCE
  • Must be able to obtain and maintain a Public Trust (DOJ)
  • Pursuant to a government contract, U.S. Citizenship is required.


Equal Opportunity Employer, including disability and veterans.

  • Washington, United States Dine Development Corporation Full time

    Job Summary: NOVA-Dine is seeking a Governance Risk Compliance Analyst to join their growing team! The candidate will proactively review, update, and maintain cybersecurity policy, guidance documents, directives, templates, and materials to ensure all documentation reflects and incorporates the most recent version of all Government cybersecurity program...


  • Washington, United States Dine Development Corporation Full time

    Job Summary: NOVA-Dine is seeking a Governance Risk Compliance Analyst to join their growing team! The candidate will proactively review, update, and maintain cybersecurity policy, guidance documents, directives, templates, and materials to ensure all documentation reflects and incorporates the most recent version of all Government cybersecurity program...


  • Washington, United States Sirius XM Radio Inc Full time

    Who We Are: SiriusXM and its brands (Pandora, SiriusXM Media, AdsWizz, Simplecast, and SiriusXM Connect) are leading a new era of audio entertainment and services by delivering the most compelling subscription and ad-supported audio entertainment experience for listeners -- in the car, at home, and anywhere on the go with connected devices. Our vision is to...


  • Washington, United States AE Strategies Full time

    About UsAE Strategies is a Mclean, VA based consulting firm, founded in 2003, providing people and project management solutions to federal customers. We are a proven small business with an established reputation and a track record of sustained success, having delivered on over 100 contracts across the federal government. Employees will work on challenging...


  • Washington, United States AE Strategies Full time

    About UsAE Strategies is a Mclean, VA based consulting firm, founded in 2003, providing people and project management solutions to federal customers. We are a proven small business with an established reputation and a track record of sustained success, having delivered on over 100 contracts across the federal government. Employees will work on challenging...


  • Washington, Washington, D.C., United States Washington Metropolitan Area Transit Authority Full time

    General Hybrid Work Statement: This opportunity is a hybrid opportunity allowing for flexibility between virtual and in-person work subject to the Authority's telework policy. Marketing Statement: Audit and Compliances mandate is to provide independent and objective internal auditing, risk assurance and risk advisory services to Metro management that add...


  • Washington, Washington, D.C., United States Spire Full time

    About the RoleWe are seeking a highly skilled Governance, Risk, and Compliance (GRC) Engineer to join our team at Spire. As a GRC Engineer, you will play a crucial role in ensuring our compliance with various regulations and standards, including Export Administration Regulations (EAR), International Trafficking in Arms Regulations (ITAR), ISO 27001, and...


  • Washington D.C., United States Washington Metropolitan Area Transit Authority Full time

    General Hybrid Work Statement: This opportunity is a hybrid opportunity allowing for flexibility between virtual and in-person work subject to the Authority's telework policy. Marketing Statement: Audit and Compliances mandate is to provide independent and objective internal auditing, risk assurance and risk advisory services to Metro management that add...


  • Washington, Washington, D.C., United States Convergenz Full time

    We are looking for an accomplished and driven IT Security Governance, Risk, and Compliance (GRC) Project Manager to oversee our GRC initiatives. The successful candidate will collaborate with federal clients and internal teams to ensure robust governance, risk management, and compliance across all IT projects and services. This position demands a strategic...


  • Washington, United States COMPLIANCE WEEK Full time

    Location: Remote Position Title: Principal Compliance Auditor Role Overview Elevate your career as a Principal Compliance Auditor within the Compliance division at Compliance Week. Our compliance team drives the organization’s Enterprise Risk Management initiatives, utilizing the Institute of Internal Auditors' Three Lines model. We ensure that our...


  • Washington, Washington, D.C., United States Convergenz Full time

    We are looking for a proficient and driven IT Security Governance, Risk, and Compliance (GRC) Project Manager to oversee critical GRC initiatives. The successful candidate will collaborate with federal clients and internal stakeholders to ensure robust governance, risk management, and compliance across all IT endeavors. This position demands a strategic...


  • Washington, Washington, D.C., United States Convergenz Full time

    We are looking for an accomplished and driven IT Security Governance, Risk, and Compliance (GRC) Project Manager to oversee our initiatives in this critical area. The successful candidate will spearhead GRC projects, collaborating with federal clients and internal stakeholders to ensure robust governance, risk management, and compliance across all IT...


  • Washington, United States Booz Allen Hamilton Full time

    Naval Governance, Risk, and Compliance Support SpecialistThe Opportunity:Cyber threats are everywhere, and the constantly evolving nature of these threats can make understanding them seem overwhelming to Department of Navy (DoN). In all of this “cyber noise,” how can these organizations understand their risks and how to mitigate them? The answer is...


  • Washington, United States BOOZ, ALLEN & HAMILTON, INC. Full time

    Naval Governance, Risk, and Compliance Support SpecialistThe Opportunity:Cyber threats are everywhere, and the constantly evolving nature of these threats can make understanding them seem overwhelming to Department of Navy ( DoN ) . In all of this "cyber noise," how can these organizations understand their risks and how to mitigate them? The answer is you-an...


  • Washington, United States COMPLIANCE WEEK Full time

    Location: Remote/Hybrid Position Overview Elevate your career as a Senior Compliance Auditor within Compliance Week's auditing division. Our team is dedicated to enhancing the organization's Enterprise Risk Management initiatives, utilizing the Institute of Internal Auditors' Three Lines model. In this role, you will be instrumental in adapting to evolving...


  • Washington, United States Dine Development Corporation Full time

    Job Overview: Diné Development Corporation (DDC) is on the lookout for a Cybersecurity Governance and Compliance Specialist to enhance our dedicated team. The selected candidate will take the initiative to assess, revise, and uphold cybersecurity policies, guidance documents, directives, templates, and related materials, ensuring that all documentation...


  • Washington, United States COMPLIANCE WEEK Full time

    Location: Washington, DC (Hybrid) Position Overview Elevate your career as a Senior Compliance Auditor within the Compliance division. This unit is integral to the organization’s Enterprise Risk Management framework, employing the Institute of Internal Auditors' Three Lines model. Our mission is to adapt to evolving practices, business processes, and the...


  • Washington, United States COMPLIANCE WEEK Full time

    Location: Washington, DC (Hybrid) Position Overview Elevate your career as a Senior Compliance Auditor within the Compliance division at Compliance Week. Our compliance team is dedicated to enhancing the organization’s Enterprise Risk Management framework by applying the Institute of Internal Auditors' Three Lines model. In this capacity, we stay aligned...


  • Washington, United States Booz Allen Hamilton Full time

    Naval Governance, Risk, and Compliance Support SpecialistThe Opportunity:Cyber threats are everywhere, and the constantly evolving nature of these threats can make understanding them seem overwhelming to Department of Navy (DoN). In all of this “cyber noise,” how can these organizations understand their risks and how to mitigate them? The answer is...


  • Washington, United States Booz Allen Hamilton Full time

    Naval Governance, Risk, and Compliance Support SpecialistThe Opportunity:Cyber threats are everywhere, and the constantly evolving nature of these threats can make understanding them seem overwhelming to Department of Navy (DoN). In all of this “cyber noise,” how can these organizations understand their risks and how to mitigate them? The answer is...