Jobs and Careers
CR

Head of Cybersecurity Governance, Risk & Compliance

CRC Group
United Statesfull_timeVerifiedPosted 23 Jul 2026

About the role

The position is described below. If you want to apply, click the Apply button at the top or bottom of this page. You'll be required to create an account or sign in to an existing one.

If you have a disability and need assistance with the application, you can request a reasonable accommodation. Send an email to Accessibility (accommodation requests only; other inquiries won't receive a response).

Regular or Temporary:

Regular

Language Fluency:  English (Required)

Work Shift:

1st Shift (United States of America)

Please review the following job description:

This role is for the Head of Cybersecurity Governance, Risk & Compliance (GRC) function within a nationally recognized insurance wholesale brokerage organization. The Cyber GRC program was built from the ground up and is now moving into a more mature, business-as-usual operating model, delivered by a hybrid team of full-time employees and strategic contract support spanning regulatory compliance, IT and cyber risk, third-party risk, AI governance, education and awareness, policy and standards, and disaster recovery governance.

As Head of Cyber GRC, this leader will carry the program forward, owning critical governance across Cyber risk, IT risk, regulatory compliance, Third-Party Vendor risk, AI governance, and disaster recovery governance. The role ensures cybersecurity, technology, and regulatory risks are identified, documented, escalated, remediated, and communicated effectively across the enterprise, and is central to translating complex risk and compliance topics into clear, business-ready language for senior leadership.

The position offers broad ownership and enterprise visibility, with high-trust partnership across the CISO, CIO, Legal, Privacy, Compliance, Enterprise Risk, Supplier Risk, Internal Audit, IT, Cybersecurity, and business leaders. It also provides exposure to a unique Cybersecurity regulatory environment, including Committee on Foreign Investment in the United States (CFIUS)-related obligations, NYDFS cybersecurity compliance, and insurance-sector governance requirements.

Key Responsibilities

  • Hands-On GRC Leadership: Serve as a hands-on, working leader who personally performs and owns key GRC deliverables — risk assessments, control reviews, regulatory analysis, and reporting — while leading the function across regulatory compliance, technology risk, cyber risk, third-party risk, AI governance, awareness, and policy and standards

  • Regulatory Obligations (CFIUS): Manage key regulatory obligations tied to CFIUS, including national security agreement and data security plan commitments

  • NYDFS Cybersecurity Compliance: Support NYDFS cybersecurity compliance in partnership with internal subject matter experts and broader risk and compliance stakeholders

  • IT & Cyber Risk Management: Oversee IT and cyber risk registers, risk assessments, remediation tracking, findings management, and governance reporting through Optro (formerly AuditBoard)

  • Third-Party Cyber Risk: Lead third-party cyber risk management, including vendor due diligence, supplier risk partnership, SOC/SIG review, and cyber-related audit response

  • AI Governance: Govern the AI risk management framework, including policy, standards, council activity, risk review, and governance maturity

  • Control Library & NIST Alignment: Manage and maintain a technology control library to support clear ownership and accountability and to report on the effectiveness of NIST-aligned controls across the organization

  • Education & Awareness: Oversee cybersecurity education, awareness, communications, phishing simulations, testing, metrics, and reporting

  • Disaster Recovery Governance: Provide governance oversight for disaster recovery, including plan readiness, testing expectations, and accountability tracking

  • Cross-Functional Partnership: Partner across Legal, Privacy, Compliance, Enterprise Risk, Internal Audit, IT, Cybersecurity, Supplier Risk, and business leadership to drive practical risk management

Education & Experience

The requirements listed below are representative of the knowledge, skill and/or ability required.  Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

  • Senior cybersecurity GRC, technology risk, cyber risk, information security governance, or regulatory compliance leadership experience

  • Background in insurance, financial services, banking, brokerage, or another highly regulated enterprise environment<

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

CRC Group

View company profile →