Senior GRC Officer

penlink

$100K — $120K *
Technical Services
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in governance, risk, compliance, or information security in a SaaS or regulated environment.
  • Hands-on experience supporting FedRAMP workstreams including SSP development and remediation tracking.
  • Strong knowledge of NIST SP 800-53 security controls and their application to both technical and non-technical audiences.
  • Proven experience managing compliance and certification workstreams with minimal supervision.
  • Experience coordinating with external auditors and internal stakeholders for compliance processes.
  • Expertise in developing and reviewing compliance documentation and management policies.
  • Exceptional communication skills, capable of articulating complex requirements clearly.

Responsibilities

  • Independently manage FedRAMP and CMMC compliance workstreams from planning through execution.
  • Lead development and quality assurance of core compliance documentation and manage assessor communications.
  • Coordinate NIST SP 800-53 security requirements implementation across various teams.
  • Own risk management, vendor assessments, and compliance policy governance processes.
  • Plan and support external audits and prepare responses to regulatory inquiries and security questionnaires.
  • Manage multiple concurrent workstreams, tracking progress and escalating risks as necessary.
  • Conduct internal compliance assessments and recommend remediation actions.

Benefits

  • Opportunity to be the sole GRC professional in the U.S., with direct impact on compliance strategies.
  • Integration into a global Security and Compliance team, enhancing cross-border collaboration.
  • Hands-on role providing significant ownership over compliance practices.
  • Dynamic working environment with continuous learning opportunities.
  • Room for professional growth and development within the compliance sector.
Full Job Description
Description

This role will independently manage substantial portions of Penlink's U.S. governance, risk, and compliance program, initially as our sole dedicated U.S.-based GRC professional while remaining fully integrated into the global Security and Compliance team. You'll personally drive the work rather than operate solely in an oversight capacity, taking hands-on, day-to-day ownership of assigned FedRAMP, CMMC, and other compliance workstreams - coordinating with technical teams, auditors, and business stakeholders from planning through evidence collection, assessment, remediation, and ongoing monitoring.

YOUR RESPONSIBILITIES

  • Independently manage assigned governance and compliance workstreams across FedRAMP, CMMC Level 2, SOC 2 Type 2, ISO 27001, TX-RAMP Level 2, and CJIS, including full FedRAMP workstreams from readiness through Agency ATO.
  • Lead development and quality review of core compliance documentation (SSP, POA&M, control narratives, policies, procedures, and readiness artifacts) and serve as the primary day-to-day contact for 3PAO/C3PAO assessors, consultants, and control owners.
  • Coordinate implementation and validation of NIST SP 800-53 and CMMC security requirements across engineering, cloud, IT, and product teams; build and maintain organized evidence repositories and continuous monitoring processes.
  • Own risk management, vendor risk assessment, policy governance, access review, and exception management, including leading the Cloud Vulnerability Task Force.
  • Plan and support external audits, assessments, and certification programs, and prepare responses to customer security questionnaires, RFIs/RFPs, and regulatory inquiries.
  • Prioritize multiple concurrent workstreams, track remediation progress, identify blockers, escalate risks, and provide clear status reporting to management and stakeholders.
  • Conduct internal compliance assessments and gap analyses, recommending and validating remediation actions.
  • Serve as a trusted security and compliance point of review, providing guidance and risk-based approval recommendations for business, technology, and operational processes to ensure security requirements, risks, and control expectations are considered before implementation.


Requirements

YOUR COMPETENCIES & EXPERIENCE

  • 5+ years of hands-on experience in governance, risk, compliance, or information security within a SaaS, cloud, technology, or regulated environment.
  • Direct practical experience supporting or managing substantial FedRAMP workstreams (SSP development, POA&M management, control implementation, evidence collection, assessment preparation, and remediation tracking).
  • Strong working knowledge of NIST SP 800-53 security controls and the ability to interpret requirements for both technical and business stakeholders.
  • Proven ability to independently manage compliance, audit, or certification workstreams with limited day-to-day supervision, including conducting risk assessments and internal compliance gap analyses.
  • Experience coordinating with external assessors, auditors, consultants, control owners, and senior business stakeholders.
  • Strong experience developing, maintaining, and quality-reviewing compliance documentation, policies, procedures, and evidence repositories.
  • Experience managing multiple concurrent workstreams, prioritizing competing requirements, identifying blockers, escalating risks, and providing clear status reporting to stakeholders.
  • Strong written and verbal communication skills, including the ability to explain complex security and compliance requirements clearly to both technical and non-technical audiences.
  • A proactive, hands-on, and delivery-focused working style, with demonstrated ability to identify required next steps, take ownership, follow through on commitments, and maintain momentum without continuous direction.
  • Ability to work effectively as part of a global team while initially operating as the sole dedicated GRC professional based in the United States.
  • Experience coordinating vulnerability remediation activities, including prioritization, assignment, tracking, escalation, and validation of remediation evidence.
  • U.S. citizenship required.
  • Experience with CMMC Level 2, SOC 2 Type 2, ISO 27001, TX-RAMP, or CJIS frameworks is nice to have.
  • Prior security operations or vulnerability management experience, including familiarity with AWS or Azure cloud security controls is preferred.
  • Experience with GRC platforms, compliance automation tools, and responding to customer security questionnaires or RFIs/RFPs.
  • Relevant certifications such as CISSP, CISM, CISA, CRISC, CCSP, PMP, CAP, or CMMC-related credentials is preferred but not required

Similar Jobs

More Jobs at penlink

  • Senior GRC Officer
    $100K — $120K *
    Lincoln, NE 68516 (Lancaster County)
    Technical Services
    In-Person

More Technical Services Jobs

Find similar Senior GRC Officer jobs: