is seeking a
Senior Information Security Manager - GRC & Risk Register to design, build, and operationalize an end-to-end Enterprise Cybersecurity Risk Register for our client in
Austin, Texas (Fully Remote role). This position is ideal for a hands-on risk strategist who has personally architected and implemented enterprise risk frameworks from scratch rather than simply maintaining pre-existing GRC programs.The ideal candidate will drive the end-to-end governance lifecycle, establish clear risk ownership, and lead cross-functional stakeholder engagement across business, technology, and security functions to ensure long-term sustainability and audit readiness.
Key Responsibilities & Deliverables:- Governance & Workflow Design: Define end-to-end governance workflows covering risk identification/intake, review/validation, risk acceptance/mitigation/transfer, ongoing reassessments, and defined escalation pathways.
- Enterprise Risk Register Framework: Design and deliver a standardized risk register template, data taxonomy, structure, and data definitions.
- Risk Scoring & Prioritization Model: Build and document a custom scoring model featuring defined likelihood and impact scales alongside prioritization logic.
- Risk Governance Model & Decision Authorities: Establish explicit roles and responsibilities for risk owners, reviewers, and governance bodies, packaged into a formal governance model and RACI matrix.
- Stakeholder Facilitation & Alignment: Engage key business, technology, and security leaders through interactive workshops to validate requirements and socialize governance processes.
- Initial Risk Register Population: Support the initial intake and onboarding of risks to deliver a baseline document reflecting the current organizational cybersecurity and technology risk posture.
- Final Documentation & Knowledge Transfer: Deliver a consolidated package of audit-ready standard operating procedures (SOPs) and execute structured knowledge transfer to internal security teams to ensure post-contract sustainability.
Experience Requirements:- 8+ years of experience with Risk Register Design and Framework development.
- 8+ years designing Risk Scoring Models and Prioritization logic.
- 8+ years establishing Governance Processes, Workflows, and Escalation structures.
- 8+ years leading Stakeholder Engagement, Workshops, and Business Alignment.
- 8+ years creating Audit-Ready Documentation and executing structured Knowledge Transfers.