GRC Lead

Acuren Inspection, Inc.

$110K — $130K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Professional certifications such as CISA, CRISC, or CISSP required.
  • Experience with CMMC assessments and NIST SP 800-171 implementation.
  • Familiarity with GDPR compliance and privacy assessments.
  • Bachelor's degree in relevant fields such as cybersecurity or law; equivalent experience accepted.
  • Minimum three years in governance, risk, compliance, or information security roles.

Responsibilities

  • Lead and enhance the GRC program focusing on critical compliance standards.
  • Translate compliance requirements into actionable policies and procedures.
  • Coordinate and prepare for audits, assessments, and compliance reports.
  • Manage third-party vendor risk programs including due diligence and ongoing monitoring.
  • Oversee the lifecycle management of security and privacy policies.
  • Create executive reports and dashboards on compliance and risk metrics.
  • Collaborate with cross-functional teams to integrate GRC into organizational processes.

Benefits

  • Hybrid work environment (4 days in office)
  • Opportunity to lead and shape compliance programs
  • Collaborative work with executive leadership and cross-functional teams
  • Mentoring and leadership opportunities for GRC personnel
  • Focus on critical regulatory compliance initiatives like CMMC and GDPR.
Full Job Description
Position Summary

TIC Solutions are seeking an experienced, strategic, and hands-on GRC Lead to lead the organization's governance, risk, and compliance program. This role will own and mature key compliance, risk-management, policy-governance, audit, and third-party vendor management processes, while partnering across business units and executive leadership.

The GRC Lead will manage compliance initiatives including CMMC, GDPR, and other applicable regulatory, contractual, and customer assurance requirements. The ideal candidate combines strong knowledge of security and privacy frameworks with practical program-management, communication, and leadership skills.

Position Details:
  • Monday-Friday, full time position
  • Hybrid (Defined as 4 days a week in office)
  • Office location is Houston, TX (Galleria)


Responsibilities
• Lead and mature the organization's GRC program, including CMMC, GDPR, and other applicable regulatory, contractual, and customer requirements.
• Translate requirements into controls, policies, procedures, compliance roadmaps, and evidence-collection processes.
• Coordinate internal and external audits, assessments, certifications, customer questionnaires, remediation plans, and compliance reporting.
• Build and manage a third-party vendor-risk program, including vendor due diligence, risk assessments, security and privacy reviews, ongoing monitoring, and remediation tracking.
• Own the lifecycle of security, privacy, and compliance policies, including review, approval, publication, employee acknowledgment, training, and exception management.
• Develop executive dashboards and reports covering compliance posture, audit readiness, control effectiveness, vendor risk, and remediation progress.
• Partner with Legal, Privacy, Procurement, IT, Information Security, and business stakeholders to integrate GRC requirements into organizational processes.
• Support related programs such as security awareness, business continuity, incident-response governance, data protection, and customer security reviews.
• Lead or mentor GRC personnel and serve as the primary contact for auditors, assessors, vendors, customers, and internal stakeholders.

Requirements
• Professional certifications such as CISA, CRISC, CISSP, CISM, ISO 27001 Lead Implementer or Lead Auditor, CDPSE, CIPM, CIPP/US, CIPP/E, or similar.
• Experience supporting CMMC assessments or implementing controls aligned with NIST SP 800-171.
• Experience with privacy-impact assessments, data-protection impact assessments, or GDPR compliance programs.
• Familiarity with GRC, audit-management, vendor-risk-management, and workflow tools.
• Experience in a regulated industry, government contracting environment, SaaS organization, or other security-sensitive business environment.
• Experience leading or mentoring GRC analysts or cross-functional working groups.
• Bachelor's degree in cybersecurity, information systems, business, risk management, law, or a related field; equivalent relevant experience considered.
• Three years of experience in governance, risk, compliance, information security, audit, privacy, or third-party risk management.
• Demonstrated experience leading compliance programs, audits, risk assessments, or control implementation efforts.
• Working knowledge of CMMC, GDPR, and common security or privacy frameworks such as NIST CSF, NIST SP 800-171, NIST SP 800-53, ISO 27001, SOC 2, CIS Controls, PCI DSS, HIPAA, or similar standards as applicable.
• Experience designing or operating a third-party risk-management program.
• Experience managing policies, control documentation, audit evidence, and remediation activities.
• Strong project-management skills, including the ability to prioritize competing compliance initiatives and drive cross-functional accountability.
• Exceptional written, verbal, and stakeholder-management skills.
• Ability to communicate risk and compliance requirements effectively to both technical and non-technical audiences.
• High degree of integrity, judgment, discretion, and attention to detail.

Similar Jobs

More Jobs at Acuren Inspection, Inc.

More Information Technology Jobs

Find similar GRC Lead jobs: