GRC Manager at Fragomen overseeing governance, risk, and compliance for data privacy and security. Leading a team to develop risk management frameworks aligned with business objectives and regulatory requirements.
Responsibilities
Lead, mentor, and grow a team of compliance analysts and GRC professionals
Provide strategic direction, technical guidance, and foster a culture of continuous improvement
Develop and operationalize a risk management program that proactively identifies, assesses, and mitigates organizational and third-party risks, with clear alignment to business priorities
Design and manage a comprehensive GRC framework, including risk assessments, controls implementation, and governance practices
Partner with Information Security, IT, Privacy, Audit, and Legal to build a unified view of the firm’s security and data privacy posture and convey that view to clients and stakeholders
Establish KPIs and dashboards to monitor risk levels, compliance progress, and the effectiveness of controls; regularly report key risk insights to senior leadership and the Risk Committee
Conduct Data Privacy Impact Assessments (DPIAs), maintain a central risk register, and oversee the mitigation of identified gaps across people, process, and technology
Ensure ongoing adherence to industry standards (e.g., ISO 27001, SOC 2, PCI DSS, NIST) by maintaining audit-ready documentation and leading evidence-gathering activities
Requirements
7+ years of experience in governance, risk, and compliance (GRC), risk management, or information security
Demonstrated experience leading risk management initiatives and teams
Professional certifications such as CISA, CISSP, CIA, or similar strongly preferred
Deep knowledge of global security and privacy frameworks, including ISO 27001, SOC 2, PCI DSS, NIST 800 series, EU GDPR, and related regulatory regimes
Strong analytical and communication skills with the ability to translate complex risks into actionable strategies for business and technical stakeholders
Excellent organizational and project management skills, with attention to detail and an ability to manage multiple priorities
Experience working with cross-functional, global teams and third-party vendors
Benefits
22 PTO days + Federal holidays
Medical, Dental, and Vision plans + FSA & HSA Plans
Senior Analyst at Theo Müller Group developing SAP authorization concepts in various SAP systems. Involves implementation, auditing, and license management tasks within a collaborative environment.
Compliance Analyst ensuring adherence to internal policies and compliance regulations for Eldorado Institute. Engaging in integrity programs and handling internal investigations.
Responsible for ensuring compliance with French and international regulations at Liebherr - Aerospace Toulouse. Overseeing regulatory monitoring and authorizations related to export control.
Intern in Regulatory Affairs at Teva Pharmaceuticals in Germany. Engaging in drug approval processes and regulatory documentation with a focus on collaboration.
Specialist in Regulatory Compliance supporting sustainability initiatives at FERI Group. Responsible for analysis, reporting, and development of sustainable finance products.
Graduate role in Internal Audit & GRC services at PwC, supporting organisations in regulatory compliance and risk management. Assisting with data analysis, process mapping, and client engagements.
Export Control / Trade Compliance Officer ensuring customs compliance with Australian and U.S. laws. Advising on trade compliance issues and solutions across various projects and teams.
Vice President of Compliance & Regulatory Affairs leading compliance strategy for Cotulla Education. Supporting growth and regulatory compliance across multiple institutions and campuses.
Compliance Officer with focus on AML and compliance tasks at Schulz & Cie. Consulting. Conducting audits, transaction monitoring, and managing regulatory issues in financial services.
Lead compliance and risk management at Thndr Securities Brokerage, ensuring regulatory adherence and overseeing compliance operations. Collaborate with teams to mitigate risks and educate on compliance programs.