Hiring.Camp

Governance, Risk & Compliance (GRC) Manager

Riverside Re

·

1 week ago

Salary
$145k – $170k
Location
Beavercreek, OH, US
Department
Operations
Seniority
Manager
Education
Bachelor
Closing date
Today
Source
iCIMS

Description

Riverside Overview

Riverside Research is an independent National Security Nonprofit dedicated to research and development in the national interest. We provide high-end technical services, research and development, and prototype solutions to some of the country’s most challenging technical problems.    All Riverside Research opportunities require U.S. Citizenship.  

Position Overview

The Manager, Governance, Risk & Compliance (GRC) leads Riverside Research's Governance, Risk, and Compliance program supporting the organization's unclassified enterprise and research information systems. Reporting to the Director of Information Security, this position is responsible for maintaining and continuously maturing Riverside's cybersecurity governance framework, enterprise risk management program, and regulatory compliance initiatives.

 

This role serves as both a people leader and technical contributor, providing leadership for a team of GRC professionals while partnering across Information Security, Information Technology, Contracts, Human Resources, Finance, Legal, and Business Operations to ensure cybersecurity and compliance objectives align with organizational and customer requirements.

 

The Manager owns Riverside's Cybersecurity Maturity Model Certification (CMMC) program, leading continuous readiness activities, regulatory assessments, governance initiatives, and enterprise risk management efforts to maintain the organization's strong cybersecurity posture and support Department of Defense mission requirements.

Responsibilities

  • Lead Riverside Research's Governance, Risk, and Compliance (GRC) program supporting the enterprise cybersecurity strategy, governance framework, and compliance objectives.
  • Own Riverside's Cybersecurity Maturity Model Certification (CMMC) program, ensuring continuous readiness for annual affirmations and Certified Third-Party Assessment Organization (C3PAO) assessments.
  • Lead and mentor a team of GRC Analysts, establishing priorities, developing staff, and fostering a culture of accountability, collaboration, and continuous improvement.
  • Develop, maintain, and govern enterprise cybersecurity policies, standards, procedures, and supporting documentation.
  • Lead Riverside's Enterprise Risk Management (ERM) program by facilitating risk identification, assessment, mitigation planning, and executive reporting.
  • Drive continuous monitoring activities through operational oversight, technical auditing, internal control assessments, and compliance reviews to ensure adherence to regulatory, contractual, and organizational security requirements.
  • Manage corrective action plans, findings, Plans of Action & Milestones (POA&Ms), and remediation activities through closure.
  • Provide governance oversight for cybersecurity programs including identity and access management, vulnerability management, configuration management, incident response, security awareness, external information sharing, third-party risk management, and data protection.
  • Partner with Information Technology and Information Security teams to ensure enterprise architecture and technology solutions align with cybersecurity strategy, regulatory requirements, and organizational risk tolerance.
  • Maintain awareness of evolving FAR, DFARS, CMMC, NIST, and Department of Defense cybersecurity requirements, advising leadership on regulatory changes and organizational impacts.
  • Develop executive dashboards, metrics, and reports that communicate cybersecurity posture, enterprise risk, and compliance status to senior leadership.
  • Collaborate with business stakeholders including Contracts, Human Resources, Finance, Legal, Marketing, and Business Operations to integrate cybersecurity governance into business processes.
  • Serve as a trusted advisor to leadership by translating cybersecurity, compliance, and enterprise risk into actionable business recommendations.

Qualifications

Required Qualifications

  • Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Information Assurance, Business, or a related discipline.
  • Twelve (12) years of progressively responsible experience in cybersecurity, information assurance, governance, risk, compliance, or related disciplines, including at least three (3) years of leadership experience managing technical teams or enterprise cybersecurity programs.
  • Demonstrated success leading external security assessments, regulatory audits, or certification efforts within a regulated industry such as the Defense Industrial Base, government contracting, financial services, healthcare, or telecommunications.
  • Strong knowledge of Cybersecurity Maturity Model Certification (CMMC), NIST SP 800-171, Department of Defense Controlled Unclassified Information (CUI) requirements, and applicable FAR and DFARS cybersecurity clauses.
  • Experience developing and maintaining cybersecurity governance programs, policies, standards, and enterprise compliance initiatives.
  • Strong understanding of enterprise information technology including Microsoft 365, Microsoft Entra ID, Microsoft Azure, Amazon Web Services (AWS), virtualization, and hybrid infrastructure.
  • Excellent written, verbal, and presentation skills with the ability to communicate complex technical concepts to executive leadership and non-technical stakeholders.
  • Demonstrated ability to lead cross-functional initiatives, influence organizational change, and build collaborative relationships across multiple business functions.
  • Must live or relocate to a commutable distance of Beavercreek, Ohio

Preferred Qualifications

  • Experience maintaining a certified CMMC Level 2 environment.
  • Experience leading Certified Third-Party Assessment Organization (C3PAO) assessments and/or DIBCAC assessments.
  • Experience leading Enterprise Risk Management (ERM) programs.
  • Experience with cloud security, Data Loss Prevention (DLP), Third-Party Risk Management, Cyber Supply Chain Risk Management (C-SCRM).
  • Industry certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), Certified in Governance, Risk and Compliance (CGRC), or Certified Cloud Security Professional (CCSP).

Global Comp

$140,000- $170,000 This represents the typical compensation range for this position based on experience, location and other factors.

Closing Statement

  Riverside Research Institute is a not-for-profit, technology-oriented defense company, where service to our customers and support of our staff is our overall mission. Riverside is an affirmative action-equal opportunity employer and complies with all applicable federal, state, and local laws regarding recruitment and hiring.  Riverside offers comprehensive compensation and benefit packages to our employees. Riverside bases its employment decisions solely on technical experience, qualifications and other job-related criteria related to our organizational purpose as a not-for-profit company, and without regard to race, color, religion, age, sex marital status, sexual orientation, national origin, physical or mental disability, veteran’s status or any other status legally protected by applicable federal, state, and local law.

Skills

AWSAzureCybersecurityRisk ManagementComplianceLoss PreventionCISSP

Similar Jobs

30

Governance, Risk, and Compliance Specialist, AWS Security

Amazon

Yesterday

Manager and Senior Manager: Governance, Risk, & Compliance (GRC)

Whoop · Boston, MA · Onsite

2 days ago

Specialist II, Governance, Risk and Compliance (TCF)

Cnx · PHL Quezon City - EXXA Tower, 8th Floor, Philippines

3 days ago

Product Manager - Governance, Risk Management and Compliance (GRC)

Chevron Corporation is one of · Houston 1400 Smith Street, United States of America

3 days ago

Cyber Risk Governance & Reporting Analyst

Fiserv is the global leader · Frisco, Texas, United States of America +1 · Onsite

3 days ago

Governance, Risk and Compliance Analyst

Babel Street · Reston, Virginia, United States; Somerville, Massachusetts, United States +1 · Hybrid

3 days ago

Group Company Secretary & Head of Global Risk, Governance and Compliance

TWE Global · 3000 Melbourne, VIC, Australia

4 days ago

Manager, Technology Risk Governance, Compliance & Reporting

Manulife and John Hancock Careers · CAN, Ontario, Toronto, 200 Bloor Street East, Canada

4 days ago

Operational Risk Governance Manager (VP)

Morgan Stanley · Budapest, HU · Hybrid

4 days ago

Managing Director, Group Governance, Risk & Compliance Office

Uobgroup · Central Region (City Area), Singapore · Hybrid

4 days ago

Specialist, NARP Risk Governance

Bmo · BMOPLACE, Canada

4 days ago

Customer Success Manager - GRC (Governance, Risk, and Compliance)

Workiva · Remote - IL, United States of America +2 · Remote

4 days ago

Operational Risk Governance Manager (VP)

Ms · Budapest Millennium Tower I, Hungary · Hybrid

4 days ago

Senior Manager, Governance Risk & Compliance

Sound Physicians · Remote · Remote

4 days ago

Governance & Risk Specialist

Standard Bank Group · Johannesburg, GP, South Africa

4 days ago

Manager - Governance Risk and Compliance

AD Ports Group · Abu Dhabi, United Arab Emirates, AE

4 days ago

Governance, Risk and Compliance Analyst

Carousell Group · Bengaluru, KA, India · Remote

5 days ago

Governance, Risk, and Compliance Intern (Fall 2026)

Notion · San Francisco, California · Hybrid

5 days ago

Senior Manager, Governance, Risk & Compliance

Circular Materials

5 days ago

Principal Security Analyst - Governance, Risk, and Compliance

Blackbaud · Remote - Anywhere - USA, United States of America · Remote

5 days ago

Cybersecurity Governance, Risk, and Compliance - Regulatory Associate

Pfizer · GRC - Thessaloniki, Chortiatis, Greece

5 days ago

Cybersecurity Governance, Risk, and Compliance - Regulatory Associate

Pfizer · GRC - Thessaloniki, Chortiatis, Greece

5 days ago

Engineer – InfoSec GRC (Governance, Risk, and Compliance)

Wynn Resorts · Las Vegas, NV, United States

5 days ago

Governance Risk and Compliance Analyst

Polsinelli · Kansas City, MO +26

5 days ago

Manager, Governance, Risk & Compliance

Accela · Remote Based - US · Remote

5 days ago

Governance & Risk Specialist

Standard Bank Group · Johannesburg, GP, South Africa

5 days ago

Associate Director, Governance Risk and Compliance for Data, Data Products and Digital Solutions

Msd · USA - Pennsylvania - North Wales (Upper Gwynedd), United States of America +1 · Hybrid

6 days ago

Manager of Risk & Governance

Reflectionai · New York +1 · Onsite

6 days ago

Sr. Information Security Governance, Risk and Compliance Analyst

BCBST · Chattanooga, TN, United States of America · Remote

6 days ago

Governance, Risk & Compliance Analyst, Specialist

Vanguard · Dallas, TX, United States of America +1

6 days ago