Search 1,378 Remote CRISC Jobs

1,378 remote jobs

Senior Director, Information Security and Compliance

Remote Canada

A NOTE ON HOW TO REACH US We're truly grateful that so many people have Foundant on their radar — it means a lot that our work resonates with others. That said due to the high volume of direct messages and emails we receive cold outreach isn't the preferred way to be considered for a role and we're not able to prioritize applications submitted this way. To apply for open positions please visit our careers page which is the fastest and most effective route to being considered. About Foundant At Foundant we build mission-critical software for the social good ecosystem — helping foundations grantmakers nonprofits and community organizations streamline their work strengthen relationships and maximize their impact. We serve the giving community worldwide with a comprehensive suite of solutions spanning grant management community foundation software and giving analytics. We're a unified company shaped by strong roots across our product portfolio and we operate with intention and purpose. Our team of ~350 people across six countries is connected by a shared North Star to be the trusted partner and strategic advisor to the communities we serve. Where You’ll Work As a remote-first workplace we believe in offering flexibility and the freedom to work where it suits you best while staying connected through technology. Our global network of talent is supported by physical office hubs and virtual collaboration fostering a dynamic environment where innovation and growth thrive. With office locations in Bozeman MT Toronto Canada and Dublin Ireland you'll be part of a globally connected team. Whether you're working remotely or from one of our office locations you'll be contributing to a vibrant collaborative culture focused on driving meaningful impact across the world. WhatYou’llDo You'll own and drive the maturity of Foundant's information security and GRC program end to end — setting the strategic roadmap that protects the trust our clients place in us across five products and every region we serve. You'll lead and develop our Head of Technical Security and Head of GRC aligning both teams around a shared vision for reducing risk and building a security-first culture across the organization. You'll serve as Foundant's executive voice during security incidents communicating clearly and confidently with clients leadership and regulators — because how we show up when things go wrong says as much about who we are as how we operate day to day. You'll build and mature Foundant's GRC program — policies risk registers control frameworks and audits (e.g. SOC 2 ISO 27001) — ensuring compliance across US Canadian European UK and Australian regulatory requirements. You'll partner closely with Product and Engineering leaders to embed security and privacy by design into all five product lines. You'll develop and present security and compliance metrics to executive leadership and the Board translating technical risk into business impact and clear priorities. You'll own third-party and vendor risk management ensuring our extended ecosystem meets the same standard of care we hold ourselves to. You'll represent Foundant's security posture to clients and prospects during enterprise sales cycles security reviews and due-diligence questionnaires. Other duties as assigned. WhatYou’llNeed 8+ years of progressive leadership experience in information security and/or governance risk and compliance (GRC) including experience leading both technical security and compliance functions. Demonstrated experience building or maturing a security and compliance program for a multi-product SaaS company. Experience navigating international regulatory and compliance frameworks (e.g. GDPR UK GDPR Australian Privacy Act SOC 2 ISO 27001). Experience leading security incident response programs including experience serving as a public-facing or client-facing spokesperson during incidents. Experience managing and developing senior technical and compliance leaders. CISSP CISM or CRISC preferred but not required. No specific degree requirement — equivalent professional experience is accepted. Must be legally eligible to work in the United States. WhatYou’llBring to our Team Dynamics Strategic Thinking Translates Foundant's North Star into a multi-year security and compliance roadmap that scales across five product lines and every region we operate in adapting the plan as regulatory and threat landscapes shift. Decision-Making Makes fast values-aligned calls under pressure — especially during security incidents — using evidence and risk data to protect clients and the business while keeping leadership clearly informed. Change Management Leads with calm direct communication during incidents and organizational change alike serving as a steady and credible voice for clients regulators and internal teams when it matters most. Staff Development Coaches the Head of Technical Security and Head of GRC to grow as leaders in their own right giving them the feedback autonomy and visibility to build strong teams beneath them. Collaboration and Learning Builds trusted partnerships with Product Engineering and Legal leaders across a global organization and stays ahead of an evolving threat and regulatory landscape by continually learning and sharing insight with the team. Why You’ll Love Working at Foundant At the heart of everything we do is a commitment to innovation and making a positive impact. Whether you’re working on projects that empower not-for-profits community foundations or corporations your contributions will help drive real-world change. We offer competitive salary and benefits including tuition and lifestyle reimbursements and bespoke mindfulness and fitness initiatives. With our Flexible PTO policy you’ll have the freedom to manage your time in a way that supports your personal well-being and professional success. We’re committed to your professional and personal development. With our merger you'll have the chance to collaborate across teams giving you exposure to diverse ideas expertise and projects that span multiple industries. As part of a larger organization you’ll have even more opportunities to grow your career. Whether it’s exploring new roles leadership opportunities or shifting to a different department we support internal mobility to help you achieve your career goals You’ll enjoy autonomy and responsibility empowering you to approach your work creatively and independently fostering innovation and independent thought. Employee recognition is a core part of our culture. When you do a great job we make sure everyone knows about it! Foundant is an equal opportunity employer committed to building a diverse workforce that represents the communities we serve. We welcome and encourage applications from all qualified candidates and will consider all applicants without regard to race color citizenship religion sex marital/family status sexual orientation gender identity Indigenous status age disability or individuals who may require accommodation. Foundant is also committed to providing accommodations throughout the interview and employment process. Accommodations are available upon request for candidates participating in all aspects of the selection process. If you have accessibility requirements during the recruitment process and require accommodation please contact hr@smartsimple.com.

Executive Advisor - Governance, Risk & Compliance

Remote Canada

About Malleum - Malleum is at the forefront of next-generation cyber defense partnering with marquee clients across space aerospace defense government financial services and critical infrastructure. We're experiencing exceptional growth as demand accelerates for trusted advisors capable of delivering at the intersection of national security allied intelligence cooperation and enterprise resilience. Our advisors shape the governance risk and compliance programs that underpin cutting-edge defensive technologies sovereign space capabilities and allied programs with national security impact – from satellite and launch operations to next-generation defense platforms. If you take pride in shaping how the most consequential organizations govern cyber risk and want your counsel to influence sovereign and allied missions Malleum is where your leadership meets purpose.The Opportunity - We're seeking a very senior governance risk and compliance specialist to lead our most strategic GRC engagements and to help scale our advisory practice across the space aerospace and defense sectors. In this role you'll serve as a trusted counsel to CISOs CIOs CROs and boards – translating regulatory complexity into pragmatic mission-aligned programs. This is a remote position with travel to client sites – typically Ontario-based – as required. This is a senior leadership role for a recognized GRC practitioner who has stood up enterprise-grade cyber resilience programs navigated the most demanding compliance regimes and can mentor the next generation of Malleum advisors.What You'll Do Lead executive-level GRC advisory engagements for clients across space aerospace defense government and critical infrastructure Stand up and mature Cyber Resilience Programs at large enterprises integrating governance risk management business continuity third-party risk and incident readiness into a cohesive operating model Advise C-suite and board stakeholders on cyber risk posture regulatory exposure and strategic investment priorities Lead client journeys to CMMC (Cybersecurity Maturity Model Certification) readiness and certification including scoping gap assessments SSP/POAM development and assessor coordination Lead client adoption of the Canadian Program for Cyber Security Certification (CPCSC) for organizations supporting the Government of Canada defense supply chain Develop operationalize and audit programs aligned with NIST CSF 2.0 NIST 800-53/171 ISO 27001/27005 ITSG-33 SOC 2 and sector-specific frameworks Advise space-sector clients on emerging requirements such as Space ISAC guidance NIST IR 8401 (Satellite Ground Segment) and allied space defense expectations Define and implement enterprise risk management frameworks KRIs/KPIs risk appetite statements and board reporting cadences Lead third-party / supply-chain risk programs aligned with defense industrial base (DIB) and allied requirements Shape Malleum's GRC service offerings methodologies accelerators and intellectual property Mentor and develop senior managers managers and consultants — building bench strength and a strong delivery culture Drive business development trusted-advisor relationships account growth proposals and thought leadership across the space aerospace and defense ecosystem Represent Malleum in industry forums regulator engagements client briefings and executive roundtables What You Bring 15+ years of progressive cybersecurity and GRC experience including senior leadership roles in consulting industry or government Demonstrated track record standing up and scaling Cyber Resilience Programs for large complex enterprises — including governance structures risk frameworks control libraries metrics and operating cadences Deep expertise across CMMC (Levels 1–3) and emerging CPCSC requirements including how each maps to NIST 800-171 / 800-172 and supplier obligations Hands-on experience advising clients in space aerospace and defense — familiarity with ITAR CGP controlled goods export controls and allied compliance regimes Strong command of NIST CSF 2.0 NIST 800-53/171/172 ISO 27001/27005 ITSG-33 SOC 2 PCI DSS and relevant privacy regimes (PIPEDA Quebec Law 25 GDPR) Executive presence — proven ability to advise CISOs CIOs CFOs GCs audit committees and boards Strong commercial acumen — practice building account growth proposal leadership and revenue accountability Demonstrated leadership in mentoring coaching and developing high-performing GRC teams Certifications such as CISSP CISM CRISC CGEIT CISA ISO 27001 Lead Auditor/Implementer or CMMC Registered Practitioner (RP) strongly preferred Eligibility for Government of Canada security clearance (Secret or higher) existing clearance highly valued French fluency is an asset Bachelor's degree required advanced degree (MBA MS in Cybersecurity) preferred Why Malleum - Lead GRC programs with genuine national and allied security impact across space aerospace and defense Shape the strategy and growth of a rapidly scaling advisory practice with direct partner-level visibility Work alongside seasoned IR offensive security engineering and program leaders on the most consequential client missions Highly competitive executive compensation performance incentives and equity-style participation in practice growth Continuous learning budget certification sponsorship and a platform to publish speak and shape industry dialogue A flat high-trust culture that rewards judgment ownership and mission focus Malleum is an equal opportunity employer. We welcome applications from all qualified candidates and are committed to building a team that reflects the communities and missions we serve. We are committed to providing accommodations for individuals with disabilities throughout the recruitment process. Please let us know if you require accommodation at any stage. Gm1VJfwdua

IT Security Analyst II

Careers at IT Security Analyst II VC3 an innovative and growing IT services solution provider headquartered in Columbia SC is seeking to fill a Senior Cybersecurity Analyst role. They will be responsible for helping organizations to protect their infrastructure data people and customers and will work with the existing management and technical teams to be successful. Our People Our team members are collaborative positive and dedicated to mutual success. Transparency isn't just a buzzword here it's a commitment to open communication ensuring every voice is heard and valued. Guided by our core values — Passionately Curious Own It Go Beyond and Serve as One — we’re here to create something extraordinary together. Our Core Focus Our team members play a pivotal role in our focus Serving those who serve with technologies for today and tomorrow that make life safe and simple. With nearly 30 years of specialized expertise our team goes beyond conventional boundaries delivering tailored managed services and cybersecurity solutions to our clients. Your Growth We are a growth minded organization that prioritizes development offering numerous opportunities for career advancement. Rooted in our core value of being Passionately Curious VC3 offers a dynamic learning environment emphasizing hands-on experiences and formal development programs that celebrate continuous learning to propel your career forward. Department Technology Operations Employment Type Full Time Location Canada - Remote Workplace type Fully remote Key Responsibilities Understand and follow “The VC3 Way”. This is our set of standards and processes that produce a predictable result for the client. You must be aware of and maintain our standards Translate complex Cyber Security concepts into actionable insights for clients ensuring alignment with their business priorities and enhancing their understanding of strategic security decisions. Oversee and prioritize security event monitoring and incident response queues ensuring swift and accurate triage to meet or exceed established SLAs/objectives. Develop and implement strategies to streamline incident response processes and improve resolution times. Conduct comprehensive analysis of system security and application logs to diagnose intricate faults identify subtle abnormal behaviors and refine false positive reduction techniques. Leverage advanced tools and techniques for sophisticated threat detection and analysis. Utilize and optimize a broad range of VC3 and client toolsets including advanced End Detection and Response (EDR) tools for in-depth investigation of alerts anomalies and building accurate timelines related to potential security compromises. Formulate and execute strategic approaches for investigating escalating containing and eradicating sophisticated malicious activities. Develop deliver and present detailed written and oral reports to clients teammates and management focusing on security trends metrics and strategic recommendations. Provide strategic input and recommendations for improving internal processes procedures and security practices based on industry trends and operational experience. Lead threat hunting activities and oversee special projects employing advanced methodologies to proactively identify and mitigate potential threats. Additional Responsibilities Advocate for and lead the adoption of innovative security solutions and methodologies within the organization. Collaborate with internal stakeholders to address changes in technologies practices and business activities that may impact security. Facilitate cross-departmental initiatives to enhance client security and mitigate threats. Maintain and update comprehensive documentation related to security operations threat analysis and incident management. Ensure timely and accurate communication with clients and internal teams reflecting changes and new findings effectively. Mentor and guide Security Analyst I team members providing support and sharing expertise to enhance their skills and knowledge. Lead by example in adhering to security best practices and take ownership of complex security issues leading escalation efforts to senior resources or specialized teams. Engage actively in team huddles L10 meetings and other collaboratively structured meetings. Review Tickets with Manager Attend company-based meetings as required Participate in the on-call rotation (1 week every ~ 1.5-2 months) Additional duties as required Skills Knowledge and Expertise Five or more years of work experience in information security risk management or related fields. One of the following certifications preferred CompTIA Security+ CompTIA CySA+ CCNA CEH SSCP or equivalent Advanced certifications such as Certified Information Systems Security Professional (CISSP) Certified Ethical Hacker (CEH) Certified Information Security Manager (CISM) Certified Information Systems Auditor (CISA) or Certified Risk & Information Security Controls (CRISC) are highly desirable. Practical knowledge of security technologies and tools including Firewalls IDS/IPS SIEM Identity and Access Management (IAM) remote working solutions and cloud technologies. Understanding of current and emerging threats countermeasures and organizational challenges in addressing these threats. Awareness of information security management frameworks and industry regulations (e.g. NIST ISO 27001 GDPR). Strong problem-solving and decision-making abilities with a capacity to analyze complex issues and develop effective solutions. Excellent verbal and written communication skills with the ability to present complex technical issues in a clear and simple format. Self-motivated detail orientated highly organized and able to handle a variety of tasks and responsibilities in an efficient manner with a high level of quality Demonstrates effective communication skills both written and verbal Shows the ability to adapt and thrive in ambiguous or uncertain situations quickly assessing and navigating challenges. Additional Information You Will Want To Know Applicant selected will be subject to a criminal and department of motor vehicles background checks and must meet Criminal Justice Information Systems (CJIS) requirements post-employment Minimal travel required VC3 offers a comprehensive benefit package and 401K/RRSP company matching Thank you for your interest in VC3. We appreciate all applications however only those candidates selected for an interview will be contacted. About VC3 Inc. VC3 offers Managed IT Services Private Cloud Services Hosted VoIP Custom Web Applications SharePoint Consulting and Website Design & Hosting. VC3 has more than 25 years of experience providing a full range of Information Technology Solutions and Services to hundreds of municipalities and organizations throughout the United States and Canada. The technologies needed by our customers have changed many times over the years but our focus has always stayed the same connect the best technologies with our experienced and talented engineers programmers web designers and support specialists to deliver solutions that take our customers to the next level of productivity and results. We pride ourselves on making IT personal making IT easy and getting IT right. And it all starts with our talented team that is committed to raising the bar. Apply Now Not quite right? Register your interest to be notified of any roles that come along that meet your criteria. Register Your Interest Apply Now Department Technology Operations Employment Type Full Time Location Canada - Remote Workplace type Fully remote View all opportunities at VC3 Inc. Apply Now

GRC – ITGC(General Control) SME

New York, NY

Cybersecurity Audit & Compliance Specialist About The Role As a Cybersecurity Audit & Compliance Specialist you will make an impact by supporting global cybersecurity audit compliance certification and governance initiatives across the organization. You will be a valued member of the Cybersecurity and Risk Management team and work collaboratively with Information Security Legal Vendor Management IT Internal Audit and business stakeholders to ensure compliance with industry standards regulatory requirements and corporate security policies. In this role you will help strengthen the organization's security posture through audit readiness certification management compliance monitoring and continuous improvement initiatives while supporting global information security frameworks and standards. In This Role You Will Support cybersecurity audit and compliance initiatives including ISO 27001 certification ENS certification and other global information security standards and regulatory requirements. Prepare the organization for internal and external security audits by coordinating audit activities tracking deliverables and ensuring timely completion of remediation efforts. Partner with cross-functional teams external auditors advisors and vendors to collect validate organize and present audit evidence and compliance documentation. Conduct compliance reviews gap assessments and remediation tracking to identify and address deficiencies against applicable security frameworks and policies. Review information security requirements within vendor and customer contracts and provide guidance to ensure alignment with corporate cybersecurity standards and controls. Work Model We strive to provide flexibility wherever possible. Based on this role's business requirements this is a remote position open to qualified applicants in the United States . Regardless of your working arrangement we are here to support a healthy work-life balance through our various wellbeing programs. The working arrangements for this role are accurate as of the date of posting. This may change based on the project you're engaged in as well as business and client requirements. Rest assured we will always be clear about role expectations. What You Need to Have to Be Considered Bachelor's degree in Cybersecurity Information Technology Information Systems Business Administration Risk Management or a related field or equivalent professional experience. Experience supporting cybersecurity audits compliance programs regulatory assessments or certification initiatives. Knowledge of ISO 27001 requirements controls risk management principles and certification processes. Experience conducting compliance assessments gap analyses evidence collection and remediation tracking activities. Strong understanding of information security governance policies standards and audit methodologies. Experience managing audit documentation compliance records and evidence repositories. Ability to coordinate multiple projects and compliance initiatives while meeting deadlines. Strong stakeholder management skills with experience collaborating across technical and business teams. Excellent written and verbal communication skills with exceptional attention to detail. Strong analytical organizational and problem-solving abilities. These Will Help You Stand Out Experience supporting ISO 27001 certification or recertification efforts. Knowledge of ENS (Esquema Nacional de Seguridad) requirements and other global cybersecurity compliance frameworks. Experience working with third-party risk management vendor security reviews and contract security assessments. Familiarity with NIST Cybersecurity Framework SOC 2 CIS Controls GDPR or other regulatory and security frameworks. Experience managing corrective action plans and compliance remediation programs. Professional certifications such as CISA CRISC CISM ISO 27001 Lead Implementer ISO 27001 Lead Auditor or similar credentials. Knowledge of cybersecurity risk assessments security governance and control testing methodologies. Experience supporting global audit and compliance programs within large enterprise environments. We're excited to meet people who share our mission and can make an impact in a variety of ways. Don't hesitate to apply even if you only meet the minimum requirements listed. Think about your transferable experiences and unique skills that make you stand out as someone who can bring new and exciting things to this role. Salary And Other Compensation The annual salary for this position is anticipated to be between $95000 and $135000 depending on experience qualifications geographic location skills and other job-related factors. This position is also eligible for Cognizant's discretionary annual incentive program based on performance and subject to the terms of Cognizant's applicable plans. Benefits Cognizant offers a comprehensive and competitive benefits package designed to support the health wellbeing and financial security of our associates and their families including Medical dental and vision insurance Health Savings Account (HSA) and Flexible Spending Accounts (FSA) where applicable Company-paid life insurance and disability coverage 401(k) retirement savings plan with company contributions subject to plan provisions Paid time off company holidays and leave programs Employee Assistance Program (EAP) Wellbeing and mental health resources Professional development training and certification opportunities Career growth and internal mobility programs Associate recognition and reward programs Benefits may vary by location and employment status and are subject to change. Application Deadline Applications will be accepted until September 30 2026 . Cognizant reserves the right to close this posting earlier based on application volume business needs or hiring timelines.

Analyst, IT Compliance & Controls

Ontario, Canada

Analyst IT Compliance & Controls Division IT Job location Remote (Canada) Hours 40 hours per week Monday to Friday Employment type Full Time Salary 85-95K A little about us Aurora is proud to be a global leader in the cannabis industry. With a smart strategy unmatched talent and focus on our long-term success we believe we have a bright future. At Aurora we’re passionate about helping patients improve their lives through high-quality premium medical cannabis under brands they can trust and rely on. Our products available across Canada Europe Australia and New Zealand include leading brands like Pedanios IndiMed San Raf Whistler Greybeard and CraftPlant. Our diverse team works passionately across various roles from manufacturing to corporate positions and many more united by our purpose Opening the World to Cannabis . Enabled by science and empowered by people for patients and consumers. We collaborate globally embrace change with courage stay agile and treat everyone with compassion. We live our values daily making a meaningful impact on patients communities and our A-Team. Job Summary The Analyst IT Compliance & Controls supports the organization’s IT compliance risk and control environment across Canada Europe and Australia. This role helps coordinate the design implementation documentation monitoring and continuous improvement of IT General Controls (ITGCs) and related technology controls. Working collaboratively across IT and business functions the Analyst partners with IT leadership application and control owners Information Security Internal Audit and external auditors to support SOX compliance regulatory requirements cybersecurity controls and operational risk management. The role also supports control governance across enterprise applications infrastructure cloud environments and ERP systems including control testing audit coordination remediation activities and ongoing improvements to the organization’s IT control framework. Sound Interesting? Here is a little more… As the Analyst IT Compliance & Controls you will… Partner with IT leadership and Business Application Owners to design implement document and operationalize IT General Controls (ITGCs). Serve as a key coordinator for IT control owner activities across multiple technology domains. Ensure assigned controls are executed consistently monitored regularly and supported by appropriate evidence. Develop compensating controls where control deficiencies or vendor assurance gaps exist. Maintain IT control documentation process narratives risk and control matrices and operating procedures. Support continuous improvement of the enterprise IT control framework. Coordinate execution of SOX IT General Controls across enterprise applications infrastructure cloud platforms and security operations. Manage control evidence collection and documentation within ServiceNow GRC. Monitor control performance and identify opportunities to improve effectiveness and efficiency. Partner with Internal Audit and external auditors during planning walkthroughs testing evidence requests and remediation activities. Track audit observations and coordinate remediation activities through successful closure. Collaborate with Business Application Owners to ensure ERP and critical business applications maintain effective security change management and operational controls. Review new applications enhancements system implementations and process changes to ensure compliance requirements are incorporated into solution design. Support ERP governance activities with particular emphasis on financial reporting controls segregation of duties user access management and change management. Experience supporting or administering Sage X3 or similar ERP platforms is highly desirable. You will be setup for success if you have… Bachelor’s degree in Computer Science Information Systems Business Accounting or a related discipline. 7–10 years of progressive experience in IT compliance IT risk SOX compliance IT audit internal controls or IT governance preferably within a publicly traded or highly regulated organization. Demonstrated experience serving as an IT Control Owner Control Coordinator ITGC Program Lead or in a comparable role with accountability for enterprise IT controls. Experience supporting SOX ITGC programs across enterprise applications infrastructure cloud platforms and security operations. Experience supporting enterprise ERP environments preferably Sage X3 experience with SAP Oracle Microsoft Dynamics or comparable platforms is also relevant. Experience using ServiceNow GRC or a comparable Governance Risk and Compliance platform to manage controls evidence testing issues and remediation activities. Experience working with internal and external auditors throughout audit planning walkthroughs testing evidence collection and remediation cycles. Experience supporting system implementations application enhancements or significant technology changes from a risk and controls perspective. Experience working within multi-jurisdictional or global technology environments is preferred. CISA CRISC CIA CISSP or a comparable professional certification is preferred. Big Four public accounting consulting or equivalent IT audit experience is considered an asset. Bonus Points if you have… . Knowledge of applicable regulatory privacy cybersecurity and control frameworks including SOX/C-SOX NIST Cybersecurity Framework CIS Controls ISO 27001 PCI-DSS GDPR/PIPEDA and other relevant regulatory requirements. Strong knowledge of IT General Controls (ITGCs) IT risk management internal control principles and technology governance practices Strong analytical and risk assessment skills with the ability to evaluate control design and effectiveness identify gaps and recommend appropriate remediation or compensating controls. Ability to interpret compliance and control requirements and translate them into practical sustainable IT processes and controls. Strong audit coordination skills including the ability to support walkthroughs testing evidence requests issue management and remediation activities. Strong technical writing and documentation skills including the development and maintenance of process narratives risk and control matrices procedures and control evidence. Strong problem-solving and professional judgment when assessing technology risks control deficiencies and remediation options. Ability to communicate complex risk and compliance requirements clearly to both technical and non-technical stakeholders. Strong collaboration and stakeholder management skills with the ability to work effectively across IT Information Security Finance Internal Audit and business functions. Strong organizational and prioritization skills with the ability to manage multiple compliance activities audit requests and remediation initiatives across competing deadlines. High attention to detail and accuracy in control execution documentation evidence management and compliance reporting. Why you’ll love working at Aurora Flexibility you will enjoy a flexible work environment that is the perfect blend of work and fun! You will be empowered to achieve work-life balance with flexible hours remote work options meeting-free-Friday-afternoons and more! Total Rewards we will motivate you to go above and beyond with a competitive salary professional development opportunities company SWAG team activities and modern technology. Team we are a diverse and global team of cannabis enthusiasts energetic innovators fitness gurus caring parents foodies and more with a collective passion to nurture an inclusive environment that helps you grow and provide people better days with cannabis. Next steps Apply today by submitting your resume through our website. Apply today by submitting your resume through our website. You can expect your application to be reviewed by our Talent Acquisition Team and not an AI software/system. We we will contact you if we see a fit via email. Think you’re the ideal candidate but you don’t meet all the requirements? Apply anyways. We would love to review your application to see if you’re the right fit or find you an alternative opportunity. Not the role for you? Share this posting with your network while subscribing to our Talent Community to learn more about upcoming opportunities (hot tip if you are an Aurora employee take advantage of the employee referral program by sharing this posting with someone in your network! If they are the successful candidate you may be eligible for a bonus!). Diversity Equity Inclusion Belonging and Accessibility At Aurora we are proud to foster and celebrate a diverse community of professionals! We take pride in nurturing an inclusive culture that empowers our people to be their authentic selves celebrate their differences and love where they work. Our diverse community combined with our inclusive culture is what sets us apart in the industry and equips our A-Team with superpowers – and this is why we encourage all candidates to apply for job opportunities regardless of race national origin colour religion age gender identity or expression sexual orientation marital and family status disability or any other identifying characteristic. We value the unique skills and experience each person brings to Aurora and are committed to creating and maintaining an accessible environment. We are committed to the requirements of the Accessibility for Ontarians with Disabilities Act so if you require accommodation during the hiring process please let our Human Resources team know by contacting us at hr.services@auroramj.com

Technical Security Risk Consultant

Senior Technical Security Risk Consultant Location Remote with occasional UK travel Contract Type Permanent & Full-time Security Clearance Active SC clearance required Salary Competitive + Benefits About the Role As a Technical Cyber Risk Consultant you will work closely with clients across government defence and regulated sectors. You will operate as a trusted advisor working alongside senior stakeholders and technical teams to deliver pragmatic risk-led outcomes. Key Responsibilities Provide expert advice on cyber risk management frameworks including ISO 27005 and NIST RMF Lead risk identification assessment and treatment across applications infrastructure and digital services Facilitate structured risk workshops and threat modelling sessions Assess solution architectures to identify security risks and control gaps Review and interpret IT Health Check outputs and define clear remediation plans Produce concise reporting on risks vulnerabilities and treatment options Maintain and manage risk registers including residual risk position Conduct gap analysis against recognised security frameworks Evaluate third party suppliers and assess control effectiveness Produce audit reports controls assessments and security briefings Work with delivery teams to ensure security is embedded throughout Experience Required This role is aligned to a technically credible and delivery focused consultant / cyber risk practioner with an emphasis on real world risk assessment not theory. Success will come from strong judgement hands-on experience and the ability to operate effectively in a clearance constrained stakeholder heavy environment. Proven experience as a technical cyber risk practitioner not purely advisory Strong technical background with hands-on delivery of system level risk assessments across infrastructure applications and cloud environments Demonstrable experience identifying assessing and treating risk within live systems not just framework alignment Experience operating in secure and regulated environments ideally government or defence Proven ability to engage senior stakeholders and influence decisions Ability to translate technical findings into clear actionable risk outcomes Confident leading risk workshops threat modelling and control assessments Experience working within Agile delivery environments Strong analytical capability and sound judgement Any candidates must have an active SC level of security clearance to be considered. Technical Knowledge Security frameworks including ISO 27001 NIST CSF CIS and NCSC guidance Regulatory landscape including GDPR and PCI DSS Familiarity with HMG and NCSC standards Modern technology environments Cloud platforms such as Azure AWS and Google Cloud Microsoft 365 Infrastructure and network security Zero Trust principles Understanding of security architecture concepts Certifications Relevant industry certifications such as CISSP CISM CRISC or equivalent. Candidates should either hold or be working towards Full Membership of CIISEC and professional registration with the UK Cyber Security Council at Chartered or Principal level in Cyber Security Governance and Risk Management. What’s in it for You Exposure to complex high impact work in high trust environments Direct engagement with senior client stakeholders Opportunity to shape risk led security decisions Ongoing professional development Flexible working / Remote first Interested? Submit your application to learn more about this exciting opportunity.

Information Security Consultant, VRA Assessor (IT SCRTY ANL 4 TX)

Davis, CA

Job Summary CA-PS Under the general direction of the Cyber Risk and Compliance Manager the Information Security Consultant (ISC) manages security and data protection solutions that support the mission of the university and protect the confidentiality integrity and availability of information assets owned or entrusted to UC Davis. The ISC evaluates and supports the documentation validation assessment and accreditation processes necessary to assure that new and existing information technology (IT) systems and services meet the University's information assurance (IA) and security requirements. The ISC prepares/maintains various security reports and dashboards participates in security assessments and audit activities prepares and reviews system security architecture designs actively participates with business and campus units throughout the university community. The ISC tracks and reports on security risks and control effectiveness to the CISO and other campus stakeholders such as the Chief Information Officer peers located on the Davis and Sacramento campuses as well as across the systems. The ISC Serves as an example and a peer to others on the team and on campus for the purpose of peer-to-peer knowledge transfer and to help develop a collaborative community of security professionals. The ISC must stay abreast of evolving campus needs technology capabilities and threat intelligence from a variety of sources to optimize data protection measures. The ISC will work with campus stakeholders to ensure data security needs and controls are aligned to support organizational goals and objectives and uses independent thinking to creatively solve problems and issues makes independent decisions and must maintain or preserve confidentiality when required to do so. To be considered for this position candidates must already have authorization to work in the United States. Unfortunately we are unable to provide visa sponsorship at this time. (In-State Only) To see IET job postings please visit https//iet.ucdavis.edu/jobs Apply By Date 9/9/2026 at 1159pm Qualifications Minimum Qualifications - For full consideration applicants are encouraged to upload license and/or certification if required of the position Bachelor's degree in related area or an equivalent experience/training Minimum of four years of experience reviewing and/or assessing information security reports advisories bulletins or other relevant intelligence and conduct risk assessments. Experience using information assurance (IA) principles and organizational requirements that are relevant to confidentiality integrity availability authentication and non-repudiation. Experience consulting with clients/customers. Experience working with information security frameworks and standards such as ISO NIST and regulations related to information security such as PCI HIPAA FISMA SB 1386 etc. Experience coordinating multiple simultaneous activities with strict deadlines complex scheduling requirements while effectively organizing and managing time to achieve project goals and provide project status reports to clients and management. Strong proficiency with common productivity software such as Microsoft Visio and Excel. Preferred Qualifications Information security certification (e.g. CRISC CISSP CISA GIAC or PCI). Experience working in higher education. Experience working with and/or developing AI assisted risk assessments. Experience with conducting numerical risk analysis. Incident handling and forensics experience. Knowledge of network security architecture concepts including topology protocols components and principles (e.g. application of defense-in-depth). Knowledge of local specialized system requirements (e.g. critical infrastructure systems that may not use standard information technology [IT]) for safety performance and reliability. Knowledge of computer network defense (CND) and vulnerability assessment tools including open-source tools and their capabilities. Familiarity with IT supply chain security/risk management policies requirements and procedures. Understanding of security requirements and strategies for “cloud hosted” environments. Key Responsibilities 50% - Risk Assessment 20% - Information Security Consulting 15% - Incident Response Vulnerability And Threat Management 15% - Documentation Department Overview The Information Security Office (ISO) a division of Information & Educational Technology (IET) helps protect the confidentiality availability and integrity of UC Davis' information assets through consultation services and programs. The ISO offers support assistance education and advice manages certain security processes and helps individuals and departments understand how they are responsible for information security at UC Davis as well as how to meet that responsibility. POSITION INFORMATION Salary or Pay Range $107511.12/yr. - $212516.64/yr. Salary Frequency Annual Salary Grade STEPS UC Job Title IT SCRTY ANL 4 TX UC Job Code 006365 Number of Positions 1 Appointment Type Staff Career Percentage of Time 100% Fixed Shift (Work Schedule) M-F 8-5pm. Other hours may be required. Location Davis/Hybrid In-State Only Union Representation TX-Technical Professionals Benefits Eligible Yes This position is hybrid (mix of on-site and remote work) Benefits Outstanding benefits and perks are among the many rewards of working for the University of California. UC Davis offers a full range of benefits resources and programs to help you bring your best self to work as well as to help you and your family achieve your health wellness financial and career goals. Learn more about the benefits below and eligibility by visiting UCnet Benefits Page or Benefits Summary for UC Davis Health Employees or Benefits Summary for UC Davis Employees. High quality and low-cost medical plans to choose from to fit your family's needs UC pays for dental and vision coverage for you and your family Retirement plans for eligible employees including Pension and other Retirement Saving Plans Supplemental insurance offered including additional life short/long term disability pet insurance legal coverage accident critical illness and hospital indemnity Pregnancy and Parental Leave Family & Medical Leave Adoption Assistance and Pay for Family Care and Bonding for eligible employees Lactation Support Program and Family Care discounts and resources Employee Well-being resources and programming to support thriving in all aspects of employee’s lives On-site Employee Assistance Program including access to free mental health services Generous amount of paid Holidays annually as outlined in the UC Policies or Collective Bargaining Agreements Paid Time Off/Vacation/Sick Time as outlined in the UC Policies or Collective Bargaining Agreements Continuing Education (CE) allowance and Staff Education Reimbursement Program for eligible employees Access to free professional development courses and learning opportunities for personal and professional growth Public Service Loan Forgiveness (PSLF) Qualified Employer and Student Loan Debt Counseling Program for eligible employees Physical Demands Standing - Occasional Up to 3 Hours Walking - Occasional Up to 3 Hours Sitting - Continuous 6 to 8+ Hours Lifting/Carrying 0-25 Lbs - Occasional Up to 3 Hours Lifting/Carrying 26-50 lbs - Never 0 Hours Lifting/Carrying over 50 lbs - Never 0 Hours Pushing/Pulling 0-25 Lbs - Never 0 Hours Pushing/Pulling 26-50 lbs - Never 0 Hours Pushing/Pulling over 50 lbs - Never 0 Hours Bending/Stooping - Never 0 Hours Squatting/Kneeling - Never 0 Hours Twisting - Never 0 Hours Climbing (e.g. stairs or ladders) - Never 0 Hours Reaching overhead - Never 0 Hours Keyboard use/repetitive motion - Continuous 6 to 8+ Hours Environmental Demands Chemicals dust gases or fumes - Never 0 Hours Loud noise levels - Never 0 Hours Marked changes in humidity or temperature - Never 0 Hours Microwave/Radiation - Never 0 Hours Operating motor vehicles and/or equipment - Never 0 Hours Extreme Temperatures - Never 0 Hours Uneven Surfaces or Elevations - Never 0 Hours Mental Demands Sustained attention and concentration - Continuous 6 to 8+ Hours Complex problem solving/reasoning - Continuous 6 to 8+ Hours Ability to organize & prioritize - Continuous 6 to 8+ Hours Communication skills - Continuous 6 to 8+ Hours Numerical skills - Frequent 3 to 6 Hours Constant Interaction - Continuous 6 to 8+ Hours Customer/Patient Contact - Continuous 6 to 8+ Hours Multiple Concurrent Tasks - Continuous 6 to 8+ Hours Work Environment Hire MUST be located in-state. (Out of state applicants will be considered but must relocate instate if hired). UC Davis is a smoke and tobacco free campus effective January 1 2014. Smoking the use of smokeless tobacco products and the use of unregulated nicotine products (e-cigarettes) will be strictly prohibited on any UC Davis owned or leased property indoors and outdoors including parking lots and residential space. Due to the mission-critical services provided by this department this position may work hours other than M-F 8-5 especially during system development hardware or software installation or in response to system problems or security incidents. Occasionally work alternate or extended hours on short notice. Vacation is restricted during peak work periods. Occasional travel is required to campus and off campus worksites. Adhere to workplace safety practices read information communicated about workplace safety complete required safety training on time and report any workplace safety issues promptly to their supervisor or the designated safety coordinator. Special Requirements – Please contact your recruiter with questions regarding which activities apply by position This is a critical position as defined by UC Policy and local procedures and as such employment is contingent upon clearing a criminal background check(s) and may include drug screening medical evaluation clearance and functional capacity assessment Misconduct Disclosure Requirement As a condition of employment the final candidate who accepts a conditional offer of employment will be required to disclose if they have been subject to any final administrative or judicial decisions within the last seven years determining that they committed any misconduct received notice of any allegations or are currently the subject of any administrative or disciplinary proceedings involving misconduct have left a position after receiving notice of allegations or while under investigation in an administrative or disciplinary proceeding involving misconduct or have filed an appeal of a finding of misconduct with a previous employer. A Culture of Opportunity and Belonging At UC Davis we’re committed to solving life’s most urgent challenges and building a healthier more resilient world. We believe in growing through every challenge continually striving to improve and welcoming new perspectives that strengthen our community. We recognize that a vibrant and innovative organization values both individual strengths and shared purpose. The best ideas often emerge when people with different experiences come together. As you consider joining UC Davis we invite you to explore our Principles of Community our Clinical Strategic Plan and strategic vision for research and education. We believe you belong here. The University of California Davis is an Equal Opportunity Employer. All qualified applicants will be considered for employment without regard to race color religion sex sexual orientation gender identity national origin disability age or protected veteran status. To view the University of California’s Anti-Discrimination Policy please visit https//policy.ucop.edu/doc/1001004/Anti-Discrimination Because we want you to feel seen and valued our recruitment process at UC Davis supports openness and authenticity. Research shows that some individuals hesitate to apply unless they meet every qualification. You may be an excellent fit for this role-or the next one. We encourage you to apply even if your experience doesn't match every listed requirement. YouBelongHere To learn more about our background check program please visit https//hr.ucdavis.edu/departments/recruitment/ucd/selection/background-checks

Client Assurance & TPRM Manager - Assistant Vice President

Greenwich, Connecticut, United States Stamford, Connecticut, United States

About the Role iCapital is seeking an experienced cybersecurity risk professional to serve as Assistant Vice President Third-Party Risk & Client Assurance Manager. This individual will lead a team of approximately five professionals across two complementary cybersecurity risk functions Third-Party Risk Management (TPRM) and Client Assurance. The ideal candidate will be a hands-on leader who can effectively manage mentor and develop team members while also possessing the technical knowledge and practical experience necessary to perform the work of either function when needed. This role requires strong cybersecurity risk assessment skills excellent written and verbal communication sound judgment and the ability to manage competing priorities and relationships with internal stakeholders third-party vendors clients and prospective clients. This individual will be responsible for supporting organization's clients and prospective clients by providing timely accurate and consistent responses to cybersecurity due diligence and assurance requests while also ensuring that third-party (vendor) cybersecurity risks are appropriately identified assessed documented and escalated. Responsibilities Lead manage and mentor a team of approximately five professionals supporting Third-Party Risk and Client Assurance activities. Provide day-to-day directions coaching technical guidance and professional development to team members. Establish clear expectations priorities and accountability across both functions. Review team deliverables to ensure assessments and client responses are accurate complete consistent and appropriately supported. Serve as an escalation point for complex cybersecurity risk assessments client inquiries vendor issues and competing business priorities. Maintain the ability to work directly on assessments and client assurance requests when workload complexity or business needs require additional support. Identify opportunities to improve team processes documentation quality efficiency and scalability. Develop and monitor appropriate metrics and reporting to communicate workload performance risk trends and program effectiveness to management. Qualifications 10 years of relevant professional experience with significant experience in cybersecurity information security risk management technology risk third-party risk management client assurance or related disciplines Demonstrated experience completing or reviewing cybersecurity due diligence questionnaires and responding to client or customer security inquiries Demonstrated experience performing cybersecurity risk assessments of third-party vendors Prior experience leading mentoring or managing cybersecurity risk or assurance professionals Able to manage multiple concurrent assessments client requests deadlines and priorities in a fast-paced environment Ability to operate effectively including independently managing responsibilities exercising sound judgment influencing stakeholders and escalating material issues appropriately Strong working knowledge of cybersecurity controls and concepts including identity and access management vulnerability and patch management security monitoring and incident response data protection and encryption network and infrastructure security cloud security secure software development business continuity and disaster recovery and security governance and risk management Experience reviewing cybersecurity assurance documentation such as SOC 1/SOC 2 reports ISO 27001 certifications penetration testing reports security policies and related control evidence Strong analytical skills and the ability to distinguish meaningful cybersecurity risks from lower-impact observations Excellent written communication skills including the ability to translate complex technical concepts into clear concise language appropriate for clients vendors business stakeholders and senior management Strong interpersonal skills and the ability to work effectively with both technical and non-technical stakeholders Bachelor's degree in cybersecurity information technology computer science risk management or related discipline or equivalent professional experience is preferred and master’s degree in the same is a plus Relevant professional certifications such as CISSP CISM CRISC CISA or equivalent is a plus Experience within financial services or another highly regulated industry is a plus Experience with third-party risk management GRC questionnaire automation or client assurance platforms is a plus Experience developing metrics reporting procedures and governance processes for cybersecurity risk or assurance programs is a plus Benefits The base salary range for this role is $100000 to $140000. iCapital offers a compensation package which includes salary equity for all full-time employees and an annual performance bonus. Employees also receive a comprehensive benefits package that includes an employer matched retirement plan generously subsidized healthcare with 100% employer paid dental vision telemedicine and virtual mental health counseling parental leave and unlimited paid time off (PTO). We believe the best ideas and innovation happen when we are together. Employees in this role will work in the office Monday-Thursday with the flexibility to work remotely on Friday. For additional information on iCapital please visit https//www.icapitalnetwork.com/about-us Twitter @icapitalnetwork LinkedIn https//www.linkedin.com/company/icapital-network-inc Awards Disclaimer https//www.icapitalnetwork.com/about-us/recognition/ iCapital is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race religion color national origin gender sexual orientation gender identity age status as a protected veteran status as an individual with a disability or other applicable legally protected characteristics.

Virtual CISO & Cybersecurity Practice Lead

Remote

WHO WE ARE The PR industry hasn't really changed in fifty years. Relationships lunches luck and a clip report at the end of the month. Interdependence is rebuilding it from the ground up. Interviewed our proprietary platform analyzes 300000+ stories every day across a network of 250000 journalists. We turn earned media into something measurable repeatable and worth paying for — and apply the same data and discipline across paid social content and brand. Integrated marketing run by one team on one system accountable to one result. Forbes named us one of America's Best PR Agencies. Our 100+ person team works with brands CMOs founders and entrepreneurs across consumer healthcare tech B2B travel and entertainment. We move fast. The best argument wins. We hire for sharp thinking real craft and ownership from day one. If you want comfortable this isn't the place. If you want to win build with us. THE ROLE You will serve as the senior cybersecurity practitioner and virtual CISO to a growing portfolio of mid-market clients (typically $25M–$150M in revenue 100–1000 employees). You will own the full client lifecycle from initial security risk assessments through ongoing advisory compliance management and incident response coordination. KEY RESPONSIBILITIES Serve as the outsourced CISO for 8–12 clients providing executive-level security leadership on a fractional basis Conduct security risk assessments gap analyses and penetration testing oversight for prospective and current clients Develop and maintain security programs policies and incident response plans tailored to each client's risk profile and regulatory environment Manage compliance frameworks including SOC 2 HIPAA PCI-DSS CCPA NIST CSF and CMMC Present security posture risk exposure and remediation roadmaps to boards of directors C-suites and audit committees in clear business-oriented language Oversee and leverage AI-driven security tooling for vulnerability scanning log analysis threat detection and compliance evidence collection Quarterback incident response when clients face active threats or breaches coordinating forensics legal communications and remediation Collaborate with RMC's reputation management team to deliver integrated crisis response when security events create reputational exposure Participate in business development — joining sales conversations scoping engagements and helping close new cybersecurity retainers Recruit manage and mentor junior analysts as the practice scales Build standardized methodologies reporting templates and delivery playbooks that allow the practice to scale without sacrificing quality QUALIFICATIONS 7-10+ years of hands-on cybersecurity experience spanning at least two of the following penetration testing incident response security architecture GRC (governance risk and compliance) 3+ years operating at the CISO Director of Security or senior consulting level you've sat in the room with boards and translated technical risk into business impact CISSP certification (active and in good standing) Deep working knowledge of SOC 2 HIPAA NIST CSF and at least one additional framework (PCI-DSS ISO 27001 CMMC CCPA) Experience building or significantly expanding a security program from early stages not just maintaining one someone else built Ability to manage multiple client engagements simultaneously without quality degradation Comfortable participating in sales and business development conversations — you understand that your credibility is what closes deals NICE TO HAVE CMMC Registered Practitioner (RP) or Certified CMMC Assessor (CCA) — the Southern California defense industrial base is a priority vertical Additional certifications CISM CRISC OSCP GPEN or SANS GIAC credentials Experience running a cybersecurity consulting practice MSSP or vCISO firm — either as founder or practice lead Background in incident response or digital forensics Familiarity with AI-driven security platforms and willingness to integrate emerging AI tooling into service delivery Experience with cyber insurance underwriting requirements and risk assessment frameworks Existing professional network in the Southern California cybersecurity community WHAT WILL SET YOU APART You've built something before a practice a team a firm and you want to do it again with resources and infrastructure behind you You can explain a zero-day exploit to a board member and a budget justification to a CFO in the same meeting You're not just a technician who moved into management you genuinely enjoy the client relationship and advisory aspects of the work You see AI as a force multiplier for your expertise not a threat to it WHY THIS ROLE You'll have an existing client base to cross-sell into from day one. You'll have AI-powered tooling that handles the repetitive analytical work so you can focus on the high-value advisory that clients actually pay for. And you'll have a leadership team that understands professional services client management and scaling consulting practices. because that's what we've done for over two decades. If you want to build a cybersecurity practice with the autonomy of a founder and the support system of an established firm this is it. COMPENSATION & STRUCTURE Base salary $200000 – $300000 depending on experience and credentials Performance bonus Up to 25% of base tied to client acquisition retention and practice revenue targets Revenue participation Structured incentive on new business you source and close designed to reward you as a practice builder not just a practitioner WHY YOU'LL LOVE WORKING AT INTERDEPENDENCE 100% Remote Forever - Work from anywhere in the U.S. while enjoying the flexibility of a fully remote workplace. Skip the commute create a workspace that works for you and collaborate with teammates across the country all without sacrificing connection or career growth. Comprehensive Health Benefits - Choose from three Anthem Blue Cross PPO medical plans plus dental and vision coverage to support your health and well-being. Retirement Savings - Save for the future with our 401(k) program including a company match that is increasing to 3% by 2027 Work-Life Balance - Enjoy paid vacation sick time 11 company holidays a floating holiday and Summer Fridays to recharge and spend more time doing what you love. Paid Maternity Leave - We support growing families with paid maternity leave giving new moms dedicated time to recover bond with their baby and return to work with confidence. Career Growth - As one of the nation's fastest-growing PR and strategic communications firms we're committed to helping ambitious people grow. Take on meaningful challenges develop new skills lead from every level and build a career with real impact. Supportive Collaborative Culture - We set high standards celebrate big wins and work together to achieve exceptional results. You'll join a team that's collaborative entrepreneurial and committed to helping one another succeed.

GRC Manager

United States

Mattermost is the leading collaborative workflow platform for defense intelligence security and critical infrastructure. Trusted by the U.S. Department of War and Fortune 500s our platform runs on-premises and in private clouds delivering secure messaging file sharing workflow automation audio/screenshare and project management—all with full data and operational control. Mattermost powers high-stakes workflows across mission planning real-time real-world operations DevSecOps incident response and cyber defense—enabling secure collaboration from tactical edge and DDIL environments to enterprise HQ. Teams operate across web desktop and mobile with embedded interoperability for Microsoft Teams Outlook and Microsoft 365. To learn more visit www.mattermost.com Mattermost is hiring a GRC Manager to own and modernize our governance risk and compliance program across both federal and commercial markets. This is a program-ownership role for someone who brings a modern engineering-led approach to compliance — harnessing GRC engineering and AI to reduce manual effort and scale our programs. You will own Mattermost's compliance posture end to end accountable for our federal readiness and commercial certifications and you will modernize how we run them automated continuously monitored and AI-native. You will do the hands-on compliance work while coordinating across internal stakeholders in engineering infrastructure and IT who implement controls the external auditors who assess them and the customers whose trust rests on the outcome. As the program scales you will grow and lead the team behind it. What You'll Do Own and modernize Mattermost's compliance programs across federal and commercial markets Lead readiness certification and surveillance cycles across both programs Operate the risk management program end to end — from identification and assessment through treatment and acceptance Own the third-party and vendor risk management program including security assessments and supply chain risk Apply GRC engineering and automation to replace manual evidence collection with continuous controls monitoring Build AI-native workflows to accelerate and improve the quality of recurring compliance work Maintain the control library system security plans POA&Ms and policies Coordinate external audits from scoping through remediation Accelerate deal cycles by owning customer security questionnaires trust center content and reusable compliance artifacts Grow and lead the GRC team as the program scales What We're Looking For Bachelor's degree in computer science information security or related field — or significant professional GRC and compliance experience Proven senior-level experience in governance risk and compliance security compliance or IT audit including direct ownership of a certification or authorization program Experience with U.S. Federal standards including CMMC and NIST series (800-171 / 800-53) Experience with ISO 27001 and SOC 2 Type II Experience operating a formal risk management program Experience running a third-party and vendor risk management program Experience owning customer-facing security assurance including security questionnaires and trust center content Working knowledge of security controls for cloud environments (AWS GCP and/or Azure) Excellent written and verbal communication skills Nice to Have Professional GRC certifications such as CISA CRISC CISM CISSP or CIPP Experience working with AI platforms such as Claude OpenAI or Gemini Experience with compliance automation tooling such as Vanta or Drata and continuous controls monitoring Direct experience applying AI or LLM-based workflows to GRC tasks Proficiency in no-code automation or scripting languages Past success in critical infrastructure industries including defense cybersecurity communications or manufacturing How Success Is Measured CMMC Level 2 gap assessment and readiness roadmap delivered within first 90 days SOC 2 Type II and ISO 27001 audit cycles completed on time without slippage Manual evidence collection replaced with automated continuously monitored controls Customer security questionnaires and trust center content maintained to unblock deal cycles GRC team grown and operating as a scalable program-driven function Why Mattermost Mission-driven work Your contributions directly support the organizations and missions that depend on secure reliable collaboration Remote-first culture Work from anywhere with a globally distributed high-trust team built for autonomy and ownership Open source at the core Be part of a vibrant developer community shaping the future of secure collaboration AI-forward environment We actively adopt and build AI-enabled workflows — you'll work with and on cutting-edge tooling Unique scope Own the compliance program end to end across both federal and commercial markets at a high-growth Series B company Compensation Mattermost takes a market-based approach to pay. Actual compensation may vary based on location skills experience qualifications and market conditions. Target Salary Range $139254-$168318 U.S. Eligibility & Compliance This role requires U.S. citizenship. Candidates must be located in the United States and eligible to obtain and maintain a U.S. government security clearance. For more information visit Security Clearances — United States Department of State Applicants must meet eligibility requirements for access to export-controlled information as defined by U.S. export control laws including EAR and ITAR. For more information visit the Bureau of Industry and Security and the Directorate of Defense Trade Controls Mattermost is an EEO Employer we are a remote-first open-source company. We are continually working to expand our hiring in more countries and regions ensuring compliance with local laws and regulations which takes time. Mattermost values your unique perspective—we welcome all applicants. We encourage individuals from all backgrounds to apply and are committed to assessing candidates based on their skills and qualifications. We do not tolerate discrimination against staff or applicants based on race religion national origin age disability pregnancy status veteran status or other personal characteristics. If you require accommodations during the interview process please let us know—we’re happy to assist.

unlock: sign-up for free / login and use the searches from your home page
🔥 job listings updated in real time

For 19 similar CRISC position(s) we've listed yesterday we've checked the salary ranges, as posted, and the resulting overall range is: 113K - 432K USD.

For 609 similar CRISC position(s) we've listed in the previous 30 days we've processed the salary ranges data as posted by employers in job descriptions and the resulting overall range is: 58K - 650K USD.

View highest-paying job

Note: If any discrepancies or 'wild' numbers appear this could be because of: typos in job postings, data source errors, ghost jobs, etc. We do not modify salary data inserted in JDs by employers nor use estimates.


Login & search by other job titles, a specific location or any keyword.
Additional custom search filters are available once you login.