Hiring.Camp

Manager, Governance, Risk & Compliance

Rrhs

·

Yesterday

Salary
$115k – $140k
Location
ACM - Remote, United States of America
Workplace
Remote
Type
Full-time
Department
Legal
Seniority
Manager
Experience
5+ years
Source
Workday

Description

Job Title: Governance Risk & Compliance Manager

Department: Information Security

Location: Remote, United States

Schedule: Days, Monday - Friday

SUMMARY

The Governance, Risk & Compliance [GRC] Manager at ACM Global Laboratories translates strategic direction into actionable workflows, coordinates cross-functional teams, supports evidence lifecycle management, maps frameworks to control implementation, leads readiness activities, and ensures all ACM GRC processes operate smoothly and efficiently.  

RESPONSIBILITIES

  • Leads the GRC program activities and a team of professionals related to third-party risk, security internal audit, security compliance, and ISMS program management.

  • Develop, document, and implement internal policies and procedures to ensure compliance with industry standards and legal requirements.

  • Facilitate regular risk assessments against security frameworks such as SOC 2, ISO 27001, and PCI-DSS, maintain a risk register, and collaborate on mitigation strategies for identified threats. Manage CAPAs for non-compliance.

  • Define specific, assignable actions to mitigate the identified risks or exploit the opportunities. 

  • Evaluate how to embed the planned actions directly into daily operational processes.

  • Manage security responses to client questions and questionnaires, including RFPs, RFIs, annual risk reviews, and ad-hoc communication requests.

  • Manage and update business continuity and disaster recovery documentation, including BIAs, plan revisions, team rosters, and dependencies. Plan, coordinate, and document annual exercises, such as tests, tabletops, and other exercises.

  • Build and manage a security metrics (KPI’s) program.

  • Develop relationships with cross-functional teams, understanding their needs in relation to security standards, to drive risk-informed decision-making and build a culture of compliance.

  • Provide expert guidance and support in navigating complex regulatory environments in relation to the management of alignment to ISO-27001 and other applicable security frameworks.

  • Stay updated on applicable industry trends and regulations to ensure ISMS compliance.

  • Monitor and analyze GRC processes and systems, making recommendations for improvement.

  • Document risk reduction plan. Annually, document “Opportunities” (potential positive improvements like adopting some technology for improved efficiency).

  • Other duties as assigned.

REQUIRED QUALIFICATIONS

  • Minimum of 5 years of experience leading  Governance, Risk, and Compliance (GRC) programs.

  • Proficiency in ISO 27001

PREFERRED QUALIFICATIONS

  •  GRC certifications (e.g. CGRC, CRISC, etc)

  • A bachelor’s degree in IT, cybersecurity, business, or law is preferred, or strong demonstrable background in GRC Management.

  • Previous experience in GRC, risk management, or internal audit, often with a mid-level leadership background.

  • Proficiency in frameworks like SOC2, NIST CSF, and HIPAA regulations.

  • Strong ability to analyze risk data and translate complex regulations into actionable controls.

  • Excellent communication skills to interact with stakeholders and lead team efforts.

  • Experience with 3rd party/vendor risk management processes.

  • Experience in working with sales teams to complete Requests for Proposals and security questionnaires.

  • Understanding of GRC processes such as policy management, risk assessment, and IT audits.

  • Exceptional verbal and written communication skills.

EDUCATION:

LICENSES / CERTIFICATIONS: 

PHYSICAL REQUIREMENTS:

L - Light Work - Exerting up to 20 pounds of force occasionally, and/or up to 10 pounds of force frequently, and/or a negligible amount of force constantly; requires occasional walking, standing or squatting.

For disease specific care programs refer to the program specific requirements of the department for further specifications on experience and educational expectations, including continuing education requirements.

Any physical requirements reported by a prospective employee and/or employee’s physician or delegate will be considered for accommodations.

PAY RANGE:

$115,000.00 - $140,000.00

CITY:

Rochester

POSTAL CODE:

14624

The listed base pay range is a good faith representation of current potential base pay for a successful full time applicant. It may be modified in the future and eligible for additional pay components. Pay is determined by factors including experience, relevant qualifications, specialty, internal equity, location, and contracts.

Rochester Regional Health is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, creed, religion, sex (including pregnancy, childbirth, and related medical conditions), sexual orientation, gender identity or expression, national origin, age, disability, predisposing genetic characteristics, marital or familial status, military or veteran status, citizenship or immigration status, or any other characteristic protected by federal, state, or local law.

Skills

CybersecuritySOCRisk ManagementComplianceProgram ManagementSOC 2HIPAAISO 27001

Similar Jobs

30

Manager, Risk & Governance

Careers @ MUFG Pension & Market Services · Australia

1 month ago

Senior Manager, Governance, Risk, and Compliance

Virtahealth · Remote · Remote

Yesterday

Financial Crimes Risk & Governance Manager

Come Work With Us! · Virtual-Arizona, United States of America · Remote

2 days ago

Sr. Manager, Risk Governance & Assurance

Ebay · Austin, United States of America · Onsite

1 week ago

Senior Manager, Governance, Risk, & Control

Td · 310/320 Front Street West Corporate, Toronto, Ontario, Canada · Hybrid

1 week ago

Manager and Senior Manager: Governance, Risk, & Compliance (GRC)

Whoop · Boston, MA · Onsite

2 weeks ago

Product Manager - Governance, Risk Management and Compliance (GRC)

Chevron Corporation is one of · Houston 1400 Smith Street, United States of America

2 weeks ago

Operational Risk Governance Manager (VP)

Ms · Budapest Millennium Tower I, Hungary · Hybrid

2 weeks ago

Senior Manager, Governance Risk & Compliance

Sound Physicians · Remote · Remote

2 weeks ago

Senior Manager, Governance, Risk & Compliance

Circular Materials

2 weeks ago

Manager, Governance, Risk & Compliance

Accela · Remote Based - US · Remote

2 weeks ago

Security Manager - Governance, Risk and Compliance

BIP · Italy

3 weeks ago

Manager - Governance, Risk and Compliance Security Automation

Salesforce · Washington - Bellevue, United States of America +2 · Onsite

1 month ago

Compliance, Governance & Risk Manager

Edenpeople · Italy - Milano - Sede Milano

1 month ago

Senior Manager, Risk Governance & Reporting

Jj · US063 NJ Raritan - 920 US Hwy 202, United States of America +4 · Hybrid

1 month ago

Manager, Governance, Risk & Compliance

Plains · Houston, TX, United States of America

1 month ago

Pensions Manager - Governance & Risk

M&G · Reading, United Kingdom +6

1 month ago

Senior Manager, Risk Governance and Reporting

Standard Bank Group · Saint-Helier, St Helier, Jersey

1 month ago

Senior Manager, Risk Governance and Reporting

Standard Bank Group · Douglas, Douglas, Isle of Man

2 months ago

Senior Manager: Governance, Risk and Compliance

Reward Gateway · Sofia/Plovdiv

3 months ago

Sr Model Risk Governance Manager

Centennial Bank · AR

5 months ago

Senior Manager, Risk Governance and Assurance

AIA Careers · CN-Dong Bao Building, China

5 months ago

Senior Manager, Cybersecurity Governance, Risk & Compliance (GRC)

KBR Careers · GBR, Leatherhead, Hill Park Court, Springfield Dr, Surrey, United Kingdom

Yesterday

Senior Manager, Investment Risk Governance

AustralianSuper · Melbourne, Australia

2 days ago

Business Manager - Governance and Risk

Scottish Government Recruitment · Edinburgh, United Kingdom, GB · Hybrid

3 days ago

Manager, Model Risk Governance

FHL Bank Chicago · Chicago, United States of America · Remote, Onsite

4 days ago

Technology Risk Remediation Governance Manager, Vice President

Statestreet · Quincy, Massachusetts, United States of America +2

4 days ago

Technology Risk Remediation Governance Manager, Vice President

Statestreet · Quincy, Massachusetts, United States of America +2

4 days ago

IT Governance, Risk & Compliance Manager

ALKEGEN Career Opportunities · US - Tonawanda, United States of America +1

5 days ago

Manager, Cybersecurity Governance, Risk & Compliance (GRC)

Conagrabrands · 11 Omaha NE, United States of America

1 week ago