A cybersecurity firm is hiring a senior GRC Operations Specialist on a permanent W2 basis to anchor the build-out of a new remediation and risk governance platform serving a regulated enterprise and public-sector client portfolio. This is a practitioner-first role — the person hired will personally author and manage POA&M lifecycles, design risk acceptance and exception workflows, map multi-framework control environments, and produce executive-ready governance reporting for CISOs, boards, and auditors. There is no pre-built GRC platform to inherit; the candidate will help architect the workflows, tooling integrations, and delivery methodology from scratch. Reporting directly to the CEO, this person will also represent the platform in investor and client-facing settings, including monthly on-site engagements in New York City (travel reimbursed). Compensation is $150,000–$180,000 base with potential equity. Candidates must be US citizens or lawful permanent residents; visa sponsorship is not available. Strong multi-framework fluency (NIST CSF, NIST 800-53, CIS Controls), hands-on POA&M experience, and comfort presenting to C-suite stakeholders are non-negotiable.
Mission
Client-facing cyber risk orchestration — converting technical security findings into governed, auditable remediation workflows including POA&Ms, risk acceptances, exception management, and executive reporting across regulated enterprise and public-sector clients
Required skills
- POA&M development and management
- GRC operations / cyber risk management
- NIST CSF / NIST 800-53 / CIS Controls framework mapping
- risk acceptance and exception workflow management
- audit evidence management and closure validation
- executive-level written reporting and briefing preparation
- translating technical findings into governance documentation
- cross-functional stakeholder communication