DescriptionThis role will independently manage substantial portions of Penlink's U.S. governance, risk, and compliance program, initially as our sole dedicated U.S.-based GRC professional while remaining fully integrated into the global Security and Compliance team. You'll personally drive the work rather than operate solely in an oversight capacity, taking hands-on, day-to-day ownership of assigned FedRAMP, CMMC, and other compliance workstreams - coordinating with technical teams, auditors, and business stakeholders from planning through evidence collection, assessment, remediation, and ongoing monitoring.
YOUR RESPONSIBILITIES- Independently manage assigned governance and compliance workstreams across FedRAMP, CMMC Level 2, SOC 2 Type 2, ISO 27001, TX-RAMP Level 2, and CJIS, including full FedRAMP workstreams from readiness through Agency ATO.
- Lead development and quality review of core compliance documentation (SSP, POA&M, control narratives, policies, procedures, and readiness artifacts) and serve as the primary day-to-day contact for 3PAO/C3PAO assessors, consultants, and control owners.
- Coordinate implementation and validation of NIST SP 800-53 and CMMC security requirements across engineering, cloud, IT, and product teams; build and maintain organized evidence repositories and continuous monitoring processes.
- Own risk management, vendor risk assessment, policy governance, access review, and exception management, including leading the Cloud Vulnerability Task Force.
- Plan and support external audits, assessments, and certification programs, and prepare responses to customer security questionnaires, RFIs/RFPs, and regulatory inquiries.
- Prioritize multiple concurrent workstreams, track remediation progress, identify blockers, escalate risks, and provide clear status reporting to management and stakeholders.
- Conduct internal compliance assessments and gap analyses, recommending and validating remediation actions.
- Serve as a trusted security and compliance point of review, providing guidance and risk-based approval recommendations for business, technology, and operational processes to ensure security requirements, risks, and control expectations are considered before implementation.
RequirementsYOUR COMPETENCIES & EXPERIENCE - 5+ years of hands-on experience in governance, risk, compliance, or information security within a SaaS, cloud, technology, or regulated environment.
- Direct practical experience supporting or managing substantial FedRAMP workstreams (SSP development, POA&M management, control implementation, evidence collection, assessment preparation, and remediation tracking).
- Strong working knowledge of NIST SP 800-53 security controls and the ability to interpret requirements for both technical and business stakeholders.
- Proven ability to independently manage compliance, audit, or certification workstreams with limited day-to-day supervision, including conducting risk assessments and internal compliance gap analyses.
- Experience coordinating with external assessors, auditors, consultants, control owners, and senior business stakeholders.
- Strong experience developing, maintaining, and quality-reviewing compliance documentation, policies, procedures, and evidence repositories.
- Experience managing multiple concurrent workstreams, prioritizing competing requirements, identifying blockers, escalating risks, and providing clear status reporting to stakeholders.
- Strong written and verbal communication skills, including the ability to explain complex security and compliance requirements clearly to both technical and non-technical audiences.
- A proactive, hands-on, and delivery-focused working style, with demonstrated ability to identify required next steps, take ownership, follow through on commitments, and maintain momentum without continuous direction.
- Ability to work effectively as part of a global team while initially operating as the sole dedicated GRC professional based in the United States.
- Experience coordinating vulnerability remediation activities, including prioritization, assignment, tracking, escalation, and validation of remediation evidence.
- U.S. citizenship required.
- Experience with CMMC Level 2, SOC 2 Type 2, ISO 27001, TX-RAMP, or CJIS frameworks is nice to have.
- Prior security operations or vulnerability management experience, including familiarity with AWS or Azure cloud security controls is preferred.
- Experience with GRC platforms, compliance automation tools, and responding to customer security questionnaires or RFIs/RFPs.
- Relevant certifications such as CISSP, CISM, CISA, CRISC, CCSP, PMP, CAP, or CMMC-related credentials is preferred but not required