GRC Lead

Voyager Technologies, Inc.

• $140K — $185K *
US-AnywhereRemote in United States
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's or Master's in information security or related field with significant experience in GRC and information security compliance.
  • Relevant certification (CISSP, CISA, CRISC, CISM, or CompTIA Security+).
  • Hands-on experience with CMMC Level 2 or Level 3 implementations and assessments.
  • Experience in managing a control framework and driving remediation efforts for security gaps.
  • Proficient in drafting and maintaining information security policies and procedures.
  • Proven record in supporting audits and third-party assessments, including evidence preparation.
  • Strong ability to work independently and manage multiple stakeholders effectively.

Responsibilities

  • Own and enhance the Governance, Risk, and Compliance (GRC) program.
  • Lead CMMC readiness efforts and coordinate assessments with C3PAOs.
  • Manage and execute the control framework while tracking compliance gaps.
  • Build an evidence library ensuring audit-ready documentation.
  • Facilitate internal and external audits as primary contact for auditors.
  • Maintain the organizational risk register and oversee risk assessments.
  • Collaborate cross-functionally with IT, legal, and operations to embed compliance into processes.

Benefits

  • Flexible Time Off (FTO) for work-life balance.
  • Comprehensive medical, dental, and vision coverage for employees and families.
  • Affordable gym memberships with 12,700+ options nationwide.
  • 401(k) retirement plan with 50% company match on contributions up to 8%.
  • Company wellness programs supporting physical and mental health.
  • Employee support resources and voluntary benefits.
  • Opportunity to work in an innovative, mission-driven team environment.
Full Job Description
The GRC Lead for cybersecurity is responsible for owning and maturing our Governance, Risk, and Compliance program, including CMMC. The position reports to the Senior Director of Cybersecurity and is part of the IT department. This role is remote. In this role, the essential functions are: - Own the end-to-end GRC program, including governance frameworks, risk management processes, and compliance activities across applicable regulatory and contractual requirements (CMMC, NIST 800-171, FAR/DFARS, and others as applicable) - Lead CMMC readiness efforts - including scoping, gap assessments, POA&M development, and coordination with the C3PAO through assessment - Manage the control framework - mapping controls to applicable standards, tracking control ownership, and driving remediation of gaps - Build and maintain the evidence library; define evidence collection processes and ensure artifacts are accurate, complete, and audit-ready - Plan and support internal and external audits, assessments, and third-party reviews; serve as the primary point of contact for auditors - Conduct and maintain the organizational risk register; facilitate risk assessments and track risk treatment decisions to closure - Partner with IT, engineering, legal, and operations to embed compliance requirements into processes, tools, and projects - Track the regulatory and compliance landscape for changes relevant to the business and advise leadership accordingly If your experience aligns with our basic qualifications and you are inspired by our mission, we'd like to connect. If you don't see the right role right now, Join Our Talent Community and stay connected as we continue to build what's next. Minimum Qualifications: - Bachelor's degree in information security or other related field with 8 years of experience in GRC, information security compliance, or other related field OR Master's degree in information security or other related field with 6 years of experience - Relevant certification such as CISSP, CISA, CRISC, CISM, or CompTIA Security+ - Direct, hands-on experience with CMMC (Level 2 or Level 3) or NIST SP 800-171 implementation and assessment preparation. - Demonstrated ability to manage a control framework - mapping, ownership assignment, evidence collection, and gap remediation. - Experience drafting and maintaining information security policies and procedures. - Proven track record supporting audits or third-party assessments, including evidence preparation and auditor coordination. - Ability to work independently, manage multiple workstreams, and drive cross-functional stakeholders without direct authority. - Excellent written and verbal communication skills, including the ability to translate technical compliance requirements for non-technical audiences. Preferred Qualifications: - CMMC assessor certification such as CCP, CCA, or LCCA. - Prior experience building or maturing a GRC program from an early stage. - Background coordinating with C3PAOs or DCSA assessors. Travel, Physical, and/or Government Mandated Requirements: - Travel may be required to Voyager facilities, operational sites, and partner locations. - Participation in security exercises, incident response, or time-sensitive remediation activities may occasionally be required outside normal business hours. - This position requires access to information governed by U.S. export-control laws and may require access to government-controlled systems or data. The good faith base salary rangefor this role is$140,000-$185,000at the time of this posting. Where you fall within the range depends on your experience, skills, and location. This range reflects base salary only and does not include benefits or bonus/incentive. This range may be adjusted in the future. Voyager offers a highly competitive total compensation package designed to support the well-being, growth, and success of our employees. Employees benefit from a flexible and comprehensive rewards program that supports both professional and personal well-being. - Flexible Time Off (FTO), empowering employees to take the time they need to recharge and maintain a healthy work-life balance - Comprehensive medical, dental, and vision coverage for employees and their families, with a significant portion of premiums covered by the company and many benefits paid at 100% for employees - Flexible, affordable gym memberships with 12,700+ options nationwide, including 24 Hour Fitness, EoS Fitness, Crunch Fitness, Anytime Fitness, Blink Fitness, Chuze Fitness, and more! No long-term contracts and FREE on-demand workout videos before you enroll - 401(k) retirement plan with a 50% company match on contributions up to 8%, supporting long-term financial security - Company wellness programs that support physical and mental well-being - Additional voluntary benefits and employee support resources - The opportunity to work alongside a highly talented team in an innovative, mission-driven environment Remote - United States pay range $140,000-$185,000 USD

Similar Jobs

More Jobs at Voyager Technologies, Inc.

More Information Technology Jobs

Find similar GRC Lead jobs: