Back to Jobs
Atmosera
Legal & HR 5d ago

Director of Governance, Risk & Compliance (GRC)

Atmosera
United StatesUnited States
Full-time
Not Disclosed
Senior-Level

Job Description

Key Skills Required

Master these to land this role

CRISCCISACISSPNIST SP 800-53CISM

Want to know if you're a match for this job?

Calculate My Match Score

The Director of Governance, Risk & Compliance (GRC) leads Atmosera's internal GRC program and Managed Governance, Risk & Compliance (MGRC) services.

This is a hands-on leadership role responsible for GRC program strategy, service delivery, team leadership, client engagements, and continuous improvement. The Director will establish scalable GRC processes while directly supporting complex client and internal compliance initiatives.

A key responsibility is hands-on management of federal security programs, including System Security Plans (SSPs), control implementation statements, evidence, POA&Ms, remediation activities, and responses to government and assessor findings.

The ideal candidate can operate at both the executive and practitioner levels, working effectively with CISOs and auditors while also working directly with engineers and control owners to validate how security controls are implemented.

Deliverables include:

  • Own Atmosera's internal GRC program and operational delivery of MGRC services.
  • Establish standardized methodologies, processes, templates, evidence requirements, and quality controls.
  • Lead risk assessments, control assessments, compliance readiness, policy governance, Managed Audit, Managed Questionnaires, and other GRC engagements.
  • Manage client commitments, priorities, capacity, deliverable quality, and service performance.
  • Identify opportunities for automation and AI to improve GRC delivery and scalability.
  • Partner with Sales and Client Success on service scoping, SOWs, pricing, and complex opportunities.

Federal Compliance & SSP Management

  • Lead and maintain System Security Plans for federal clients.
  • Develop and review control implementation statements and supporting evidence.
  • Coordinate with technical control owners to validate how controls are implemented.
  • Manage POA&Ms, control deficiencies, remediation activities, milestones, and dependencies.
  • Coordinate responses to government, assessor, and auditor findings and requests.
  • Facilitate SSP and control working sessions with clients, engineers, security teams, and other stakeholders.
  • Support continuous monitoring, security assessments, and authorization activities.
  • Maintain alignment between documented controls and the actual operating environment.
  • Support requirements involving NIST SP 800-53, NIST SP 800-171, FISMA, CMMC, FedRAMP concepts, and agency-specific requirements.

Risk, Compliance & Audit Management

  • Lead cybersecurity risk assessments, control gap assessments, risk registers, treatment plans, exceptions, and remediation tracking.
  • Support frameworks including SOC 2, NIST, CIS, ISO 27001, PCI DSS, HIPAA, CMMC, and Microsoft security benchmarks.
  • Own Atmosera's Managed Audit methodology, including audit readiness, evidence management, auditor coordination, findings, and remediation.
  • Oversee Managed Security Questionnaire delivery and development of reusable response and evidence libraries.
  • Ensure policies, standards, procedures, and control documentation accurately reflect operational practices.

Internal GRC

  • Partner with the CISO to operate and mature Atmosera's internal security and compliance program, including:
  • SOC 2 Type 2
  • Risk and control assessments
  • Policy and control governance
  • Audit coordination
  • Security questionnaires
  • Third-party risk
  • Customer security reviews
  • Evidence and remediation management

Client Advisory & Technical Alignment

  • Serve as a senior GRC advisor to client security, IT, risk, compliance, and executive leadership.
  • Translate regulatory and compliance requirements into actionable security improvements.
  • Partner with Security Operations, Managed Azure, Microsoft 365, and engineering teams to map control requirements to technical implementations.
  • Maintain working knowledge of Microsoft security technologies including Azure, Entra ID, Defender, Sentinel, Intune, Purview, and Azure Policy.
  • Support vCISO engagements where governance, risk, audit, or compliance expertise is required.

Team Leadership

  • Lead, mentor, and develop GRC Analysts and Consultants.
  • Manage workload, capacity, priorities, quality assurance, and escalations.
  • Build repeatable processes that allow the GRC practice to scale without depending on the Director for every engagement.

What Success Looks Like

We measure success by results and alignment. Here is how we define a “win” for this role:

After 90 Days

Complete onboarding, shadow active engagements, and produce a written audit of current MGRC workflows with three prioritized opportunities.

After 1 Year

Independent ownership of Atmosera's GRC function, managing the SOC 2 Type 2 program, leading MGRC delivery, and directly managing complex federal SSP activities.

The Director should be able to take government or assessor findings, identify required stakeholders, drive accurate responses and remediation, validate supporting evidence, and maintain a defensible SSP while simultaneously building the team, processes, and automation necessary to scale the GRC practice.

The Skill Matrix

Qualifications

  • 8+ years of cybersecurity, GRC, security assessment, audit, or related experience.
  • Demonstrated experience leading GRC programs or teams.
  • Hands-on experience with NIST SP 800-53, System Security Plans, POA&Ms, control implementation statements, and federal security requirements.
  • Experience managing audits, evidence, risk assessments, control gaps, policies, and remediation programs.
  • Ability to translate regulatory requirements into technical and operational security controls.
  • Strong client-facing, executive communication, and technical stakeholder management skills.

Preferred Qualifications (Bonus Points)

  • Experience in an MSSP, MSP, consulting, professional services, federal program, or government contractor environment.
  • Microsoft Azure and Microsoft 365 security experience strongly preferred.
  • CISSP, CISM, CRISC, CISA, CGEIT, or similar certifications.

How would you rate this job post?

See what other professionals think about this role.

banner

Atmosera (operating at atmosera.com) is a cloud transformation and managed services company engineered for enterprises seeking to modernize their IT infrastructure. Founded by an undisclosed team and headquartered in Lake Oswego, OR, Atmosera specializes in solving the challenges of legacy system migration, scalability bottlenecks, and operational inefficiencies by leveraging Microsoft Azure. Under the hood, the company combines advanced cloud architecture design with full lifecycle application development, enabling seamless deployment and operation of public, private, and hybrid Azure environments. This allows global businesses to achieve strategic business outcomes through optimized cloud performance, enhanced security, and cost-efficient scalability. Backed by a privately held structure, Atmosera focuses on delivering measurable value through human expertise and cutting-edge technology.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More
Director of Governance, Risk & Compliance (GRC) at Atmosera | HireSkys