Affinity

4534 GRC Lead

Affinity$125K — $150K *
Aerospace & Defense
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Business Administration, Information Systems, Cybersecurity, or related field.
  • 12 years of relevant experience in program management, risk management, or cybersecurity governance.
  • 5 years managing enterprise-level governance programs or cybersecurity risk management initiatives.
  • Experience coordinating cross-directorate stakeholders in complex environments.
  • Expert knowledge of cybersecurity and enterprise risk management frameworks.
  • Strong written and verbal communication skills, particularly with executive audiences.

Responsibilities

  • Lead the implementation of the CERMS WG Charter and cybersecurity risk governance framework.
  • Provide strategic oversight for enterprise cybersecurity risk management initiatives.
  • Coordinate with CIO-5 on risk management priorities and activities.
  • Develop and maintain project plans and implementation schedules.
  • Prepare program status, risk, and performance reports for CIO-4 leadership.
  • Facilitate meetings and discussions among executive and cross-directorate stakeholders.
  • Establish governance documentation and standard operating procedures for risk management.

Benefits

  • Flexible work arrangements depending on project needs.
  • Professional development opportunities including training and certification support.
  • Access to industry conferences and workshops.
  • Comprehensive health and wellness programs.
  • Retirement savings plan with agency matching.
Full Job Description
4534 GRC Lead
4534 | Top Secret

Job Description:

OVERVIEW:

We are seeking a Governance, Risk, and Compliance (GRC) Lead to be responsible for providing strategic oversight and coordination for implementation of the enterprise cybersecurity risk management framework. This position leads the CIO Enterprise Risk Management Working Group (CERMS WG) and provides senior-level program management, governance, policy development, and stakeholder coordination supporting enterprise and system-level cybersecurity risk decisions.

The GRC Lead works closely with CIO-4 leadership, CIO-5 Strategy & Programs Office (SPO), the Chief Risk Officer (CRO), CIO Risk Owners, and stakeholders across the Agency to establish risk tolerance matrices, decision frameworks, escalation protocols, governance processes, and executive reporting mechanisms. The position facilitates enterprise consensus on cybersecurity risk management methodologies and ensures the Agency has repeatable, defensible processes for evaluating, accepting, escalating, and communicating cybersecurity risk.

GENERAL DUTIES:

  • Lead implementation and maturation of the CERMS WG Charter and associated enterprise cybersecurity risk governance framework.
  • Provide strategic program management and oversight for enterprise cybersecurity risk management initiatives.
  • Coordinate with CIO-5 Strategy & Programs Office on strategic risk management priorities and activities.
  • Develop and maintain comprehensive project plans, milestones, action items, and implementation schedules.
  • Provide recurring program status, risk, and performance reporting to CIO-4 leadership.
  • Coordinate stakeholder engagement across CIO organizations, SPP/DDI, Deputy Directors, J2s, Director-level leadership, and other Agency stakeholders.
  • Lead development of CIO-level Administrative Instructions, governance documentation, and supporting enterprise risk management policies.
  • Develop CIO-4 Standard Operating Procedures (SOPs) governing cybersecurity risk tolerance decisions and supporting processes.
  • Define and document escalation protocols, decision authorities, and organizational responsibilities for enterprise and system-level risk decisions.
  • Coordinate policy review, adjudication, concurrence, and approval processes across Agency stakeholders.
  • Guide CERMS WG meetings and facilitate executive and cross-directorate stakeholder discussions.
  • Establish working group agendas in coordination with the CRO, Risk Leads, and other key stakeholders.
  • Coordinate with CIO Risk Owners across divisions to ensure effective participation and execution of risk management activities.
  • Facilitate consensus on enterprise cybersecurity risk methodologies, thresholds, decision processes, and reporting requirements.
  • Oversee development and maintenance of enterprise risk tolerance matrices and decision-support frameworks.
  • Direct development and maintenance of risk management dashboards and executive reporting mechanisms.
  • Ensure effective configuration management, version control, storage, and accessibility of program artifacts.
  • Maintain or oversee meeting minutes, decision records, action tracking, and governance documentation.
  • Identify program risks, barriers, and competing priorities and develop strategies to maintain implementation momentum.
  • Program Management: Demonstrated ability to lead and manage complex
  • federal programs supporting national security, defense, or intelligence missions
  • while ensuring successful contract execution, customer satisfaction, and mission
  • delivery.
  • Enterprise Risk Management: Expert knowledge of enterprise cybersecurity risk management principles, governance structures, risk tolerance methodologies, and decision frameworks.
  • Cybersecurity Governance: Deep understanding of NIST RMF, OMB A-123, DoDI 5010.40, DoDI 8510.01, ICD 503, and related federal and Intelligence Community cybersecurity governance requirements.
  • Program Management: Advanced ability to plan, execute, monitor, and manage complex enterprise initiatives involving multiple organizations and executive stakeholders.
  • Executive Working Group Facilitation: Expert ability to lead working groups, facilitate complex discussions, build consensus, resolve competing viewpoints, and drive decisions.
  • Policy Development: Advanced experience developing Administrative Instructions, SOPs, governance frameworks, decision authorities, and other formal policy artifacts.
  • Risk Tolerance and Decision Frameworks: Experience developing risk tolerance matrices, escalation criteria, decision models, and repeatable risk acceptance processes.
  • Stakeholder Management: Proven ability to coordinate across directorates, senior leadership organizations, technical teams, Risk Owners, and other mission stakeholders.
  • Cybersecurity Authorization: Strong understanding of Authorization to Operate (ATO) processes, cybersecurity authorization frameworks, and system-level risk.
  • Executive Reporting: Experience developing dashboards, performance measures, decision-support products, and executive-level reporting mechanisms. Strategic Communication: Ability to translate complex cybersecurity and risk concepts into concise, actionable information for technical and non-technical executive audiences.
  • Artifact Management: Experience establishing and maintaining controlled repositories, version management, decision records, meeting documentation, and audit trails.
  • Organizational Change Management: Ability to implement new governance processes across complex organizations while managing stakeholder expectations and organizational change.


REQUIRED QUALIFICATIONS:

  • Bachelor's degree from an accredited college or university in Business Administration, Information Systems, Cybersecurity, or a related field.
  • Twelve (12) years of relevant experience in program management, risk management, cybersecurity governance, or related disciplines.
  • Minimum five (5) years of experience managing enterprise-level governance programs or cybersecurity risk management initiatives.
  • Demonstrated experience coordinating cross-directorate or cross-functional stakeholders in complex organizational environments.
  • Experience developing and implementing policy or governance frameworks within Government, Department of Defense, Intelligence Community, or similarly regulated environments.
  • Expert knowledge of cybersecurity and enterprise risk management frameworks.
  • Demonstrated experience facilitating senior or executive-level working groups.
  • Strong written and verbal communication skills with experience communicating to executive audiences.


DESIRED QUALIFICATIONS:

  • Preferred certifications include one or more of the following:
  • Project Management Professional (PMP)
  • Certified in Risk and Information Systems Control (CRISC)
  • Certified in Governance, Risk and Compliance (CGRC)
  • Certified Information Systems Security Professional (CISSP)
  • Certified Information Security Manager (CISM)
  • Other relevant cybersecurity, risk management, or program management certification
  • Experience supporting Intelligence Community organizations.
  • Experience supporting Department of Defense cybersecurity or enterprise risk management programs.
  • Familiarity with IC/DoD organizational structure, CIO organizations, and Agency decision-making processes.
  • Experience implementing or supporting Governance, Risk, and Compliance (GRC) platforms or enterprise risk management systems.
  • Experience establishing risk tolerance models for large portfolios of information systems and ATOs.
  • Experience developing cybersecurity governance processes for senior executive decision-making.
  • Experience leading organizational change associated with implementation of new governance or risk management frameworks.
  • Technical background in cybersecurity


CLEARANCE:

  • Active Top Secret clearance minimum required


Job Details

City : Mclean

State : Virginia

About Affinity

Affinity’s patented technology structures and analyzes millions of data points across emails, calendars, and third-party sources to offer users the tools they need to automatically manage their most valuable relationships, prioritize important connections, and discover untapped opportunities. Affinity uses artificial intelligence to analyze relationship strength and illuminate the best paths to warm introductions. The platform also offers a holistic view of users’ networks in a centralized, automatically updated database without any manual upkeep. Founded in 2014, Affinity is headquartered in San Francisco, California. Affinity has raised $120M to date and is backed by leading investors including Menlo Ventures, Advance Venture Partners, 8VC and MassMutual Ventures. It has over 2,700 customers in 70 countries, including venture capital firms such as Bain Capital Ventures and Kleiner Perkins, private equity firms such as SoftBank Group, investment bankers such as Woodside Capital Partners, financial services firms such as Fidelity Investments, real estate companies such as Tishman Speyer, insurers such as American Family Insurance and enterprises such as Nike, Qualcomm and Twilio. Affinity has been named in Fortune Magazine's Best Workplaces, Inc. Magazine's Best Workplaces and editor's number one pick, the Data Breakthrough Award, BIG Innovation Award and others.
Learn more about Affinity
Size
1,000 employees
Industry
Founded
2014

Similar Jobs

More Jobs at Affinity

More Aerospace & Defense Jobs

Find similar 4534 GRC Lead jobs: