SummaryThe Enterprise Risk Management (ERM) Leader is responsible for developing and maturing the organization's enterprise risk framework, with strong integration into cybersecurity risk. This role focuses on holistic risk visibility, aggregation, and governance across the enterprise, ensuring risks are understood, prioritized, and communicated effectively to leadership.
This position does not own third-party risk management execution, but ensures third-party risks are appropriately incorporated into the enterprise risk posture in coordination with the Third-Party Risk Leader.
Your role in our mission- Own and mature the enterprise-wide ERM framework aligned to COSO, ISO 31000, and integrated with NIST-based cyber risk practices.
- Define and maintain enterprise risk appetite and tolerance statements.
- Establish governance structures for risk escalation, acceptance, and oversight.
- Partner with the CISO and security teams to integrate cyber risks into enterprise reporting.
- Translate technical cybersecurity risks into business impact and financial exposure.
- Ensure visibility into threat landscape, vulnerabilities, and control effectiveness.
- Consolidate risks across cybersecurity, operational, financial, regulatory, and third-party domains (via coordination).
- Maintain enterprise risk register and identify systemic and emerging risks.
- Lead enterprise-level risk assessments and scenario modeling, including cyber event simulations.
- Conduct stress testing and impact analysis tied to business continuity. Provide oversight and challenge to mitigation strategies across Security, IT, and business units.
- Ensure alignment with enterprise risk appetite and escalate gaps as needed.
- Partner with the Third-Party Risk Leader to incorporate vendor risks into enterprise reporting while avoiding duplication of execution activities.
- Develop executive dashboards and present to leadership, risk committees, and board stakeholders.
- Drive a risk-aware culture, lead workshops, and embed risk-based decision-making across the organization.
What we're looking for- Bachelor's degree in Risk Management, Cybersecurity, Business, or related field.
- 7-10+ years of experience in ERM, cybersecurity risk, or GRC.
- Strong knowledge of COSO, ISO 31000, and NIST frameworks.
- CRISC, CISM, CISSP, CRMA, FRM, or equivalent certification(s) preferred.
What you should expect in this role- This opportunity is 100% remote with the opportunity to travel for work up to 25% annually.
The deadline to submit applications for this posting is August 13, 2026.
The pay range for this position is $122,200.00 - $174,600.00 per year, however, the base pay offered may vary depending on geographic region, internal equity, job-related knowledge, skills, and experience among other factors. Put your passion to work at Gainwell. You'll have the opportunity to grow your career in a company that values work flexibility, learning, and career development. All salaried, full-time candidates are eligible for our generous, flexible vacation policy, a 401(k) employer match, comprehensive health benefits, and educational assistance. We also have a variety of leadership and technical development academies to help build your skills and capabilities.