CRC Group
• $120K — $150K *Qualifications
Responsibilities
Benefits
The position is described below. If you want to apply, click the Apply button at the top or bottom of this page. You'll be required to create an account or sign in to an existing one.
If you have a disability and need assistance with the application, you can request a reasonable accommodation. Send an email to (accommodation requests only; other inquiries won't receive a response).
Regular or Temporary:
RegularLanguage Fluency: English (Required)
Work Shift:
1st Shift (United States of America)Please review the following job description:
This role is for the Head of Cybersecurity Governance, Risk & Compliance (GRC) function within a nationally recognized insurance wholesale brokerage organization. The Cyber GRC program was built from the ground up and is now moving into a more mature, business-as-usual operating model, delivered by a hybrid team of full-time employees and strategic contract support spanning regulatory compliance, IT and cyber risk, third-party risk, AI governance, education and awareness, policy and standards, and disaster recovery governance.Key Responsibilities
Hands-On GRC Leadership: Serve as a hands-on, working leader who personally performs and owns key GRC deliverables — risk assessments, control reviews, regulatory analysis, and reporting — while leading the function across regulatory compliance, technology risk, cyber risk, third-party risk, AI governance, awareness, and policy and standards
Regulatory Obligations (CFIUS): Manage key regulatory obligations tied to CFIUS, including national security agreement and data security plan commitments
NYDFS Cybersecurity Compliance: Support NYDFS cybersecurity compliance in partnership with internal subject matter experts and broader risk and compliance stakeholders
IT & Cyber Risk Management: Oversee IT and cyber risk registers, risk assessments, remediation tracking, findings management, and governance reporting through Optro (formerly AuditBoard)
Third-Party Cyber Risk: Lead third-party cyber risk management, including vendor due diligence, supplier risk partnership, SOC/SIG review, and cyber-related audit response
AI Governance: Govern the AI risk management framework, including policy, standards, council activity, risk review, and governance maturity
Control Library & NIST Alignment: Manage and maintain a technology control library to support clear ownership and accountability and to report on the effectiveness of NIST-aligned controls across the organization
Education & Awareness: Oversee cybersecurity education, awareness, communications, phishing simulations, testing, metrics, and reporting
Disaster Recovery Governance: Provide governance oversight for disaster recovery, including plan readiness, testing expectations, and accountability tracking
Cross-Functional Partnership: Partner across Legal, Privacy, Compliance, Enterprise Risk, Internal Audit, IT, Cybersecurity, Supplier Risk, and business leadership to drive practical risk management
Education & Experience
The requirements listed below are representative of the knowledge, skill and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Senior cybersecurity GRC, technology risk, cyber risk, information security governance, or regulatory compliance leadership experience
Background in insurance, financial services, banking, brokerage, or another highly regulated enterprise environment
Prior experience working directly with a CISO, CIO, or senior information security executive
Strong understanding of cyber governance, IT and cyber risk registers, regulatory compliance, control environments, audit readiness, and remediation tracking
Experience with third-party cyber risk, vendor due diligence, supplier risk partnership, and customer/carrier audit response
Experience with GRC platforms such as AuditBoard/Optro, Archer, ServiceNow IRM/GRC, MetricStream, LogicGate, OneTrust, or similar tools
Certifications, Licenses, Registrations
Certifications such as CISM, CISSP, CRISC, CISA, GSLC, or similar are preferred
Functional Skills
Strong executive communication skills, with the ability to simplify complex cyber, technology, regulatory, and operational risk topics for senior leadership
Ability to lead emerging technology governance, particularly AI governance, policy, standards, risk review, and control development
Ability to manage executive stakeholders while providing the team clear direction, prioritization, and support
Proven ability to ensure cybersecurity, technology, and regulatory risks are identified, documented, escalated, remediated, and communicated across the enterprise
Preferred Attributes
NYDFS cybersecurity experience is strongly preferred
CFIUS experience is highly valuable
General Description of Available Benefits for Eligible Employees of CRC Group: At CRC Group, we're committed to supporting every aspect of teammates' well-being – physical, emotional, financial, social, and professional. Our best-in-class benefits program is designed to care for the whole you, offering a wide range of coverage and support. Eligible full-time teammates enjoy access to medical, dental, vision, life, disability, and AD&D insurance; tax-advantaged savings accounts; and a 401(k) plan with company match. CRC Group also offers generous paid time off programs, including company holidays, vacation and sick days, new parent leave, and more. Eligible positions may also qualify for restricted stock unitsand/or a deferred compensation plan.
Similar Jobs



More Jobs at CRC Group
More Finance & Insurance Jobs

