GRC Manager at Fragomen overseeing governance, risk, and compliance for data privacy and security. Leading a team to develop risk management frameworks aligned with business objectives and regulatory requirements.
Responsibilities
Lead, mentor, and grow a team of compliance analysts and GRC professionals
Provide strategic direction, technical guidance, and foster a culture of continuous improvement
Develop and operationalize a risk management program that proactively identifies, assesses, and mitigates organizational and third-party risks, with clear alignment to business priorities
Design and manage a comprehensive GRC framework, including risk assessments, controls implementation, and governance practices
Partner with Information Security, IT, Privacy, Audit, and Legal to build a unified view of the firm’s security and data privacy posture and convey that view to clients and stakeholders
Establish KPIs and dashboards to monitor risk levels, compliance progress, and the effectiveness of controls; regularly report key risk insights to senior leadership and the Risk Committee
Conduct Data Privacy Impact Assessments (DPIAs), maintain a central risk register, and oversee the mitigation of identified gaps across people, process, and technology
Ensure ongoing adherence to industry standards (e.g., ISO 27001, SOC 2, PCI DSS, NIST) by maintaining audit-ready documentation and leading evidence-gathering activities
Requirements
7+ years of experience in governance, risk, and compliance (GRC), risk management, or information security
Demonstrated experience leading risk management initiatives and teams
Professional certifications such as CISA, CISSP, CIA, or similar strongly preferred
Deep knowledge of global security and privacy frameworks, including ISO 27001, SOC 2, PCI DSS, NIST 800 series, EU GDPR, and related regulatory regimes
Strong analytical and communication skills with the ability to translate complex risks into actionable strategies for business and technical stakeholders
Excellent organizational and project management skills, with attention to detail and an ability to manage multiple priorities
Experience working with cross-functional, global teams and third-party vendors
Benefits
22 PTO days + Federal holidays
Medical, Dental, and Vision plans + FSA & HSA Plans
Governance, Risk & Compliance Specialist at Quilter providing oversight on governance, risk, and compliance activities, strengthening Quilter Invest’s risk management culture across the organization.
Regulatory Specialist responsible for contributions in public consultations and regulatory studies. Engaging with institutional relations and ensuring adherence to energy regulations in Brazil.
Working Student supporting regulatory and compliance efforts at Paymenttools' e - money institution. Collaborating on risk management and compliance projects in a hybrid role based in Cologne.
Senior Consultant Regulatory Affairs participating in pharmaceutical projects focused on market access and regulatory compliance. Joining Deloitte's sector regulation team based in Madrid.
Trade Compliance Officer managing stakeholder compliance with UK and US export laws. Contributing to trade policies and documentation for international imports and exports in a hybrid role.
Expert HSE Compliance role focused on environmental regulations and safety in energy production at EniBioch4in. Overseeing compliance, audits, and promoting HSE culture across facilities.
Junior Regulatory Reporting Operations Specialist analyzing vast trade reporting data and ensuring regulatory reporting quality at SEB. Collaborating with teams to resolve reporting issues for regulatory compliance.
Risk & Compliance Advisory Practice Lead at Netwealth providing risk and compliance advice across investment and product governance. Leading advisory teams while ensuring regulatory compliance and risk management standards.
Director Compliance role at Manulife managing the Complaints & Regulatory Investigations team. Overseeing investigations and ensuring compliance with regulatory standards.
Regulatory Affairs Director overseeing activities in the Regulatory Affairs Department at CareSource. Focused on compliance, contracting, and leading the team in a hybrid work environment.