Jobs and Careers
NO

Manager of Cybersecurity Governance, Risk, and Compliance 03946 NWSOL

North Wind Group
United Statesfull_timeVerifiedPosted 4 Sept 2025

About the role

Location: Richland, Washington
Title: Manager of Cybersecurity Governance, Risk, and Compliance
Schedule (FT/PT): Regular Full Time
Travel Required: No
Clearance: Ability to Obtain

North Wind Solutions is a Government contracting small business with operations at military and civilian installations across the United States. The company’s focus is on facilities operation and maintenance, waste management and radiological services, security control and force protection, and environmental services.

North Wind Solutions is seeking a Manager of Cybersecurity Governance, Risk, and Compliance (GRC) to lead a critical function within our cybersecurity program. This leadership role is pivotal in ensuring the robust security posture of customer sites by overseeing all aspects of cybersecurity governance, risk management, and compliance with federal mandates and best practices. The successful candidate will be a visionary leader, an exceptional mentor, and a skilled program manager with a deep understanding of the federal cybersecurity landscape. This role is a hybrid work-from-home position. Approximately 50% of work will be remote and 50% will be performed in-person at the office or customer locations in Richland, Washington.
ESSENTIAL DUTIES AND RESPONSIBILITIES:

Team Leadership & Mentorship (40%):

  • Lead, mentor, and develop a high-performing team of 15-20 experienced cybersecurity analysts specializing in GRC functions (e.g., policy development, risk assessment, internal audit, issues management, security awareness).
  • Foster a collaborative and engaging work environment that promotes professional growth, knowledge sharing, and continuous improvement.
  • Conduct performance reviews, provide regular feedback, and develop individual development plans for team members.
  • Delegate tasks effectively, ensuring equitable distribution of workload and leveraging individual strengths.
  • Promote a culture of accountability, proactivity, and excellence within the GRC team.

Program Management (30%):

  • Oversee the development, implementation, and maintenance of the cybersecurity GRC program in alignment with federal regulations (e.g., FISMA, NIST RMF, FedRAMP), site policies, and industry best practices.
  • Manage and prioritize multiple GRC initiatives and projects, ensuring timely completion and adherence to scope and budget.
  • Develop and implement strategic plans for enhancing the cybersecurity GRC posture of customer sites.
  • Establish and track key performance indicators (KPIs) and metrics to measure the effectiveness of GRC activities.
  • Identify and implement automation and process improvements to enhance GRC efficiency and effectiveness.
  • Contract Performance Monitoring & Reporting (15%):
  • Monitor and ensure the organization's adherence to the performance requirements and deliverables outlined in its contracts with customers.
  • Develop, track, and report on key performance indicators (KPIs) and service level agreements (SLAs) related to cybersecurity GRC activities as required by customer contracts.
  • Identify potential deviations or risks to contractual obligations and develop mitigation strategies in collaboration with relevant stakeholders.
  • Prepare and present regular performance reports to internal leadership and external customer representatives, demonstrating compliance and program effectiveness.
  • Facilitate and support customer-initiated reviews and audits related to cybersecurity contract performance.

Contract Performance Monitoring & Reporting (15%):

  • Serve as the primary point of contact for cybersecurity GRC matters with internal and external stakeholders, including senior leadership, federal auditors, agency officials, and other site departments.
  • Effectively communicate complex cybersecurity concepts and risks to non-technical audiences.
  • Represent the organization in various forums, committees, and working groups related to cybersecurity GRC.
  • Build and maintain strong relationships with key stakeholders to foster a collaborative approach to cybersecurity.

ADDITIONAL DUTIES AND RESPONSIBILITIES:

  • Perform other duties as assigned.

MINIMUM QUALIFICATIONS:
Education and Experience:

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Management Information Systems, Business Administration, or similar.
  • 8+ years of relevant work experience, including:

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

North Wind Group

View company profile →