Senior Governance Risk and Compliance Professional

4 days ago


Washington, United States ZipRecruiter Full time

We are seeking a seasoned Governance, Risk and Compliance (GRC) expert to join our team at Spire Global. As a leading space-to-cloud analytics company, we pride ourselves on delivering cutting-edge technology and innovative solutions. Our GRC Engineer will play a pivotal role in ensuring the security and compliance of our operations, while shaping the future of data analysis from space.

Key Responsibilities:

  1. Compliance Assurance: Conduct thorough assessments and audits to guarantee adherence to Export Administration Regulations (EAR), International Trafficking in Arms Regulations (ITAR), ISO 27001, NIST 800-171, and other relevant security frameworks.
  2. Information Security Management System: Operate Spire's Information Security Management System by outlining projects, executing workflows, and coordinating tasks with other teams as needed.
  3. GRC Tool Implementation: Design, implement, and manage GRC tools and technologies to streamline processes for risk assessment, compliance monitoring, and incident management, including automation tool development and auditing tasks.
  4. GRC Strategy Development: Develop and implement comprehensive GRC and cybersecurity strategies and policies aligned with regulatory and certification requirements.
  5. Staff Guidance: Provide expert guidance and training to staff on compliance matters related to export controls and security standards.
  6. Cross-Functional Collaboration: Collaborate with cross-functional teams to address compliance issues and develop corrective action plans.
  7. Regulatory Monitoring: Monitor applicable cybersecurity regulations for changes and incorporate new requirements into existing policies and procedures.
  8. Documentation Management: Generate new documentation and maintain existing documentation such as stakeholder analyses, scope statements, risk assessment and treatment procedures, performance monitoring and measurement plans, etc.
  9. Risk Assessment: Conduct risk assessments and develop risk mitigation strategies.
  10. Compliance Reporting: Prepare and submit compliance reports to regulatory agencies and internal stakeholders, including NIST SSPs and POAMs.
  11. Audit Participation: Participate in external and internal audits including gathering audit evidence both directly and indirectly through coordination with other teams.

Qualifications and Requirements:

  • Education: Bachelor's degree in Information Security, Cyber Security, Computer Science, Computer Engineering, Software Development, or a related field, or equivalent experience in a relevant area.
  • Experience: Minimum of 3-5 years of hands-on technical experience in an IT, engineering, GRC, or security role, preferably in the aerospace, satellite, or Government industries.
  • Technical Skills: In-depth knowledge of EAR, ITAR, ISO 27001, NIST 800-171, and NIST 800-53.
  • Certifications: Professional certifications such as CISSP, CISA, CRISC, or similar are highly desirable.
  • Automation Expertise: Ability to automate security control, compliance, and configuration audits utilizing scripting such as bash, Python, Go, or similar.
  • GRC Tool Experience: Experience implementing and managing GRC tools and technologies, such as GRC platforms, SIEM solutions, and vulnerability management systems.
  • Risk Analysis Review: Experience reviewing risk analyses, drafting corrective action plans, and driving the risk treatment process.
  • Communication Skills: Relevant experience working and communicating with internal and external systems and process auditors.
  • Security Framework Knowledge: In-depth knowledge of security framework controls as they apply to public cloud (AWS preferred), hybrid, self-hosted, and SaaS environments.
  • Project Management: Ability to transform and communicate organizational compliance requirements into internal engineering requirements for various teams including engineering and security.
  • Collaboration Skills: Ability to partner with colleagues, independently manage and run complex projects, and prioritize efforts for risk reduction.
  • Analytical Skills: Excellent analytical and problem-solving skills.
  • Written Communication: Develop clear and concise written content.
  • Task Management: Excellent project and task management skills, preferably using Jira.
  • Interpersonal Skills: Strong communication and interpersonal abilities.
  • Teamwork: Ability to work independently and as part of a team.

About Us:

Spire Global is a pioneering space-to-cloud analytics company that delivers advanced maritime, aviation, and weather tracking globally. We're committed to improving life on Earth with data from space and operate a hybrid work model requiring a minimum of three days per week in office.

Compensation and Benefits:

The anticipated base salary range for this position is $130,000 - $170,000 USD annually. In addition to base compensation, this role may be eligible for annual equity awards and our employee benefits program, including vacation, sick, and personal time off; optional medical, dental, vision, life, and coverage; a 401(K) plan; health and wellness reimbursement program; and participation in Spire's Employee Stock Purchase Plan.

Global Perks:

  • Name Your Satellite Program (NYSP)
  • Launch Attendance
  • Generous Time Off Policy
  • Education Assistance Program
  • Employee Assistance Program (EAP)
  • Employee Stock Purchase Program (ESPP)
  • Family Leave
  • Fitness Reimbursement
  • Employee Referral Program
  • Healthy snacks & beverages in every office

  • Governance, Risk,

    3 weeks ago


    Washington, United States Tik Tok Full time

    Responsibilities TikTok is the leading destination for short-form mobile video. Our mission is to inspire creativity and bring joy. TikTok has global offices including Los Angeles, New York, London, Paris, Berlin, Dubai, Singapore, Jakarta, Seoul and Tokyo. Why Join Us Creation is the core of TikTok's purpose. Our platform is built to help imaginations...


  • Washington, Washington, D.C., United States SiloSmashers Full time

    We are seeking a Senior IT Governance Professional to support our CIO team at SiloSmashers, supporting a federal government agency. This role involves driving IT transformation and operational efficiencies through PMO excellence.The ideal candidate will have extensive experience deploying ITIL within a Federal Government environment, conducting Risk...


  • Washington, Washington, D.C., United States Universal Service Administrative Company Full time

    Job OverviewThe Universal Service Administrative Company (USAC) is seeking a highly skilled Senior Fraud Risk Specialist - Program Compliance Expert to join its team. In this role, you will be responsible for analyzing fraud risk trends within the Universal Service Fund (USF) and appropriated fund programs.As a Senior Fraud Risk Specialist, you will conduct...

  • IS Governance Risk

    3 weeks ago


    Washington, DC, United States US Bank Full time

    At U.S. Bank, we’re on a journey to do our best. Helping the customers and businesses we serve to make better and smarter financial decisions and enabling the communities we support to grow and succeed. We believe it takes all of us to bring our shared ambition to life, and each person is unique in their potential. A career with U.S. Bank gives you a wide,...


  • Washington, Washington, D.C., United States international finance corporation Full time

    International Finance CorporationThe IFC is a member of the World Bank Group, which is the largest global development institution focused on the private sector in emerging markets. Our mission is to leverage the power of the private sector to end extreme poverty and boost shared prosperity on a livable planet.We are seeking an experienced Senior Manager of...


  • Washington, United States Ernst and Young Full time

    About the RoleWe are seeking an experienced Risk Management and Governance Specialist to lead our US Records and Information Management program. As a key member of our team, you will be responsible for supporting all aspects of the RIM program and achieving key performance indicators.The ideal candidate will have a strong understanding of risk management and...


  • Washington, United States MindPoint Group Full time

    About MindPoint GroupMindPoint Group is a dynamic organization that requires a Senior Cybersecurity Risk Manager to join our team in Washington, DC. This role will be responsible for providing advisory support to customer agency needs and challenges related to Governance, Risk, and Compliance (GRC) program maturation, ATO process improvement, government-wide...


  • Washington, Washington, D.C., United States Development InfoStructure Full time

    Job SummaryThe Senior Government Regulatory Compliance Specialist will play a crucial role in ensuring Development InfoStructure's adherence to USAID and federal regulations, particularly those related to Personal Services Contracts (PSCs). The ideal candidate will have extensive knowledge of the Code of Federal Regulations (CFR), Federal Acquisition...


  • Washington, United States Google Full time

    As a Senior Compliance and Risk Attorney, you will join Google's Americas-based team that leads the strategy for defending the company in responses to governments and regulators. This role involves defining a defense strategy, conducting investigations, collection and review of information, and representing the company in engagements.About the RoleThis...


  • Washington, Washington, D.C., United States Fannie Mae Full time

    About the JobAs a Compliance and Operational Risk Leader, you will be responsible for conducting comprehensive risk assessments and providing recommendations to senior management.About Our Company CultureFannie Mae is committed to fostering a diverse and inclusive workplace where employees can thrive and grow professionally. We believe in the importance of...


  • Washington, United States Cisco Full time

    Role OverviewCisco is seeking a seasoned Senior Corporate Counsel to lead compliance initiatives in the US public sector. This role requires a deep understanding of government regulations and laws, as well as exceptional problem-solving skills.Key ResponsibilitiesDevelop and implement compliance programs to mitigate risks and ensure regulatory...


  • washington, United States Capgemini Government Solutions Full time

    We are seeking a Senior Security Compliance Analyst DC Lead to join our team at Capgemini Government Solutions in Washington, D.C. The successful candidate will be responsible for leading our security compliance efforts and ensuring the highest level of security and compliance standards are met for our government clients.About the RoleThis senior-level...


  • Washington, Washington, D.C., United States Universal Service Administrative Company Full time

    Job OverviewThe Universal Service Administrative Company is seeking a highly skilled Senior Compliance and Fraud Risk Specialist to join our team. As a key member of the Office of General Counsel, this role will play a critical part in ensuring the integrity of our programs and protecting against potential fraud.About the JobWe are looking for an experienced...


  • Washington, United States Tik Tok Full time

    **Job Description**TikTok is the leading destination for short-form mobile video. Our mission is to inspire creativity and bring joy. We are seeking a Compliance and Risk Management Professional to join our Global Privacy & Regulatory Affairs team.**Responsibilities**Analyze and identify potential risks and develop strategies to mitigate them.Collaborate...


  • Washington, United States Microsoft Corporation Full time

    Job Title: Senior Compliance AttorneyAbout the Role:Microsoft is seeking an experienced attorney to join its Compliance & Ethics team in the Americas region. In this role, you will assist the company in meeting its responsibilities and continuing commitment to comply with laws, regulations, and policies governing business activities across the Americas...


  • Washington, Washington, D.C., United States Universal Service Administrative Company Full time

    About the OpportunityWe are seeking a highly skilled and experienced Compliance and Risk Specialist to join our Audit Division. This role requires a strong background in auditing, risk assessment, and leadership, with excellent communication and interpersonal skills. The ideal candidate will have a proven track record of success in managing complex audits...


  • Washington, United States Cisco Full time

    About the RoleWe are seeking a highly skilled and experienced Senior Corporate Counsel to advise on compliance matters, laws, and regulations governing U.S. federal (FED), state, local, and education (SLED) public sector business.This role requires a deep understanding of U.S. public sector compliance, strong problem-solving and analytical skills, and the...


  • Washington, United States The Fannie Mae Full time

    Full-timeTarget Hiring Range (1): 119000Target Hiring Range (2): 155000Company DescriptionAt Fannie Mae, futures are made. The inspiring work we do helps make a home a possibility for millions of homeowners and renters. Every day offers compelling opportunities to impact the future of the housing industry while being part of an inclusive team thriving in an...


  • Washington, United States The Fannie Mae Full time

    Full-timeTarget Hiring Range (1): 119000Target Hiring Range (2): 155000Company DescriptionAt Fannie Mae, futures are made. The inspiring work we do helps make a home a possibility for millions of homeowners and renters. Every day offers compelling opportunities to impact the future of the housing industry while being part of an inclusive team thriving in an...


  • Washington, Washington, D.C., United States SunPlus Data Group, Inc Full time

    We are looking for a highly experienced Senior ISSO to lead the establishment, implementation, and/or enhancement of Information Systems Security and Compliance efforts based on State/Agency Policy/Standards and Regulatory Guidance such as FISMA, NIST, CMS MARS-E, HIPAA, etc.The successful candidate will report to the Security Risk and Compliance Manager and...