Director of Governance, Risk & Compliance (Remote US)
Apply for this position → Go ad-free with PremiumAtmosera empowers businesses to redefine what's possible with modern technology and human expertise. Our exceptional experience across Applications, Data & AI, DevOps, Security, and the Microsoft Azure platform enables organizations to accelerate innovation, enhance security, and optimize operational agility. As a Microsoft Partner with seven specializations, GitHub AI Partner of the Year, a member of the GitHub Advisory Board, and a member of the prestigious Microsoft Intelligent Security Association (MISA), Atmosera expertly delivers cutting-edge, integrated solutions that deliver business value.
Your Impact
The Director of Governance, Risk & Compliance (GRC) leads Atmosera's internal GRC program and Managed Governance, Risk & Compliance (MGRC) services.
This is a hands-on leadership role responsible for GRC program strategy, service delivery, team leadership, client engagements, and continuous improvement. The Director will establish scalable GRC processes while directly supporting complex client and internal compliance initiatives.
A key responsibility is hands-on management of federal security programs, including System Security Plans (SSPs), control implementation statements, evidence, POA&Ms, remediation activities, and responses to government and assessor findings.
The ideal candidate can operate at both the executive and practitioner levels, working effectively with CISOs and auditors while also working directly with engineers and control owners to validate how security controls are implemented.
Deliverables include...
GRC Program & MGRC Service Leadership
- Own Atmosera's internal GRC program and operational delivery of MGRC services.
- Establish standardized methodologies, processes, templates, evidence requirements, and quality controls.
- Lead risk assessments, control assessments, compliance readiness, policy governance, Managed Audit, Managed Questionnaires, and other GRC engagements.
- Manage client commitments, priorities, capacity, deliverable quality, and service performance.
- Identify opportunities for automation and AI to improve GRC delivery and scalability.
- Partner with Sales and Client Success on service scoping, SOWs, pricing, and complex opportunities.
Federal Compliance & SSP Management
- Lead and maintain System Security Plans for federal clients.
- Develop and review control implementation statements and supporting evidence.
- Coordinate with technical control owners to validate how controls are implemented.
- Manage POA&Ms, control deficiencies, remediation activities, milestones, and dependencies.
- Coordinate responses to government, assessor, and auditor findings and requests.
- Facilitate SSP and control working sessions with clients, engineers, security teams, and other stakeholders.
- Support continuous monitoring, security assessments, and authorization activities.
- Maintain alignment between documented controls and the actual operating environment.
- Support requirements involving NIST SP 800-53, NIST SP 800-171, FISMA, CMMC, FedRAMP concepts, and agency-specific requirements.
Risk, Compliance & Audit Management
- Lead cybersecurity risk assessments, control gap assessments, risk registers, treatment plans, exceptions, and remediation tracking.
- Support frameworks including SOC 2, NIST, CIS, ISO 27001, PCI DSS, HIPAA, CMMC, and Microsoft security benchmarks.
- Own Atmosera's Managed Audit methodology, including audit readiness, evidence management, auditor coordination, findings, and remediation.
- Oversee Managed Security Questionnaire delivery and development of reusable response and evidence libraries.
- Ensure policies, standards, procedures, and control documentation accurately reflect operational practices.
Internal GRC
Partner with the CISO to operate and mature Atmosera's internal security and compliance program, including:
- SOC 2 Type 2
- Risk and control assessments
- Policy and control governance
- Audit coordination
- Security questionnaires
- Third-party risk
- Customer security reviews
- Evidence and remediation management
- Serve as a senior GRC advisor to client security, IT, risk, compliance, and executive leadership.
- Translate regulatory and compliance requirements into actionable security improvements.
- Partner with Security Operations, Managed Azure, Microsoft 365, and engineering teams to map control requirements to technical implementations.
- Maintain working knowledge of Microsoft security technologies including Azure, Entra ID, Defender, Sentinel, Intune, Purview, and Azure Policy.
- Support vCISO engagements where governance, risk, audit, or compliance expertise is required.
Team Leadership
- Lead, mentor, and develop GRC Analysts and Consultants.
- Manage workload, capacity, priorities, quality assurance, and escalations.
- Build repeatable processes that allow the GRC practice to scale without depending on the Director for every engagement.
We measure success by results and alignment. Here is how we define a “win” for this role:
After 90 Days
Complete onboarding, shadow active engagements, and produce a written audit of current MGRC workflows with three prioritized opportunities.
After 1 Year
Independent ownership of Atmosera's GRC function, managing the SOC 2 Type 2 program, leading MGRC delivery, and directly managing complex federal SSP activities.
The Director should be able to take government or assessor findings, identify required stakeholders, drive accurate responses and remediation, validate supporting evidence, and maintain a defensible SSP while simultaneously building the team, processes, and automation necessary to scale the GRC practice.
Qualifications
- 8+ years of cybersecurity, GRC, security assessment, audit, or related experience.
- Demonstrated experience leading GRC programs or teams.
- Hands-on experience with NIST SP 800-53, System Security Plans, POA&Ms, control implementation statements, and federal security requirements.
- Experience managing audits, evidence, risk assessments, control gaps, policies, and remediation programs.
- Ability to translate regulatory requirements into technical and operational security controls.
- Strong client-facing, executive communication, and technical stakeholder management skills.
Preferred Qualifications (Bonus Points)
- Experience in an MSSP, MSP, consulting, professional services, federal program, or government contractor environment.
- Microsoft Azure and Microsoft 365 security experience strongly preferred.
- CISSP, CISM, CRISC, CISA, CGEIT, or similar certifications.
These 'Core Three' represent the heartbeat of Atmosera. They are the behaviors and attributes we align to every day, defining how we interact, solve problems, and celebrate our wins together. This is simply who we are at our best.
Humble
- Low Ego, High Impact
- We share credit easily, admit when we're wrong, and view every mistake as a data point for growth.
Hungry
- Internal Drive
- We have a natural bias for action. We don't wait for permission to solve a problem or find a better way to do things.
Mindful
- Intentional Awareness
- We are conscious of our impact on the team. We listen more than we speak and respond to challenges with empathy and situational awareness.
- Talent Screen (30 mins) — A conversation about your background and the role mission.
- The Impact & Attributes Assessment (60 mins w/ our CISO) — The 'How' — Cultural DNA and The Core Three.
- Collaborator Loop (45-60 mins w/ 2 peers) — The 'What' — Required Skills and Core Capabilities. May include a presentation or work sample.
- Final Alignment w/ our Exec Team*
We value our employees and are committed to providing a comprehensive and competitive benefits package designed to support your well-being and financial security. Here's what you can look forward to:
Financial Security & Growth:
Competitive Salary: We offer competitive salaries commensurate with experience and skills.
Generous 401(k) Plan: Secure your financial future with our generous 401(k) plan, featuring a 100% company match on your contributions up to 4% of your salary! This is a fantastic opportunity to build your retirement savings with our support.
Performance-Based Compensation: Your hard work and dedication will be recognized and rewarded through our performance-based compensation program, which includes bonus potential in addition to your base salary.
Health & Well-being:
100% Employer-Paid Health, Vision, and Dental Insurance for employees: Say goodbye to expensive premiums! We cover 100% of the cost of your health, vision, and dental insurance premiums, saving you potentially thousands of dollars each year. Focus on your health, not your healthcare costs.
Company-Paid Life, AD&D, Short and Long-Term Disability Insurance: We provide company-paid life, accidental death & dismemberment, and short- and long-term disability insurance to protect you and your family.
Time Off & Work-Life Balance:
Generous Paid Time Off (PTO): Enjoy a healthy work-life balance with three weeks of paid time off, allowing you to relax, recharge, and pursue your personal interests. This flexible PTO can be used for vacation, personal time, or sick leave.
11 Paid Holidays: We observe 11 paid holidays throughout the year, giving you additional time to spend with family and friends.
Community Service Leave: We believe in giving back to the community and offer paid time off for you to volunteer with organizations that are meaningful to you.
Additional Perks & Recognition:
Employee Recognition and Reward Program: We celebrate and reward outstanding performance and contributions through our employee recognition program. We value your dedication and are committed to showing our appreciation.
This is a full-time position in the United States with the ability to work from home, or from one of our many US offices if local.
Atmosera is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. All employment is decided on the basis of qualifications, merit, and business need.
Similar Jobs
Manager, Engineering - Sales Planning
CaptivateIQ · Canada,USA
Technical Program Manager
Paula's Choice Skincare · USA
Senior Director of Product | Mid-Cycle and Backend RCM Platform
Infinx · USA
Vice President, Banking & Financial Services Industry Leader
Quantum Metric · USA
Senior Technical Program Manager - Security
OpenAI · USA
Director of Governance, Risk & Compliance (Remote US)
Atmosera empowers businesses to redefine what's possible with modern technology and human expertise. Our exceptional experience across Applications, Data & AI, DevOps, Security, and the Microsoft Azure platform enables organizations to accelerate innovation, enhance security, and optimize operational agility. As a Microsoft Partner with seven specializations, GitHub AI Partner of the Year, a member of the GitHub Advisory Board, and a member of the prestigious Microsoft Intelligent Security Association (MISA), Atmosera expertly delivers cutting-edge, integrated solutions that deliver business value.
Your Impact
The Director of Governance, Risk & Compliance (GRC) leads Atmosera's internal GRC program and Managed Governance, Risk & Compliance (MGRC) services.
This is a hands-on leadership role responsible for GRC program strategy, service delivery, team leadership, client engagements, and continuous improvement. The Director will establish scalable GRC processes while directly supporting complex client and internal compliance initiatives.
A key responsibility is hands-on management of federal security programs, including System Security Plans (SSPs), control implementation statements, evidence, POA&Ms, remediation activities, and responses to government and assessor findings.
The ideal candidate can operate at both the executive and practitioner levels, working effectively with CISOs and auditors while also working directly with engineers and control owners to validate how security controls are implemented.
Deliverables include...
GRC Program & MGRC Service Leadership
- Own Atmosera's internal GRC program and operational delivery of MGRC services.
- Establish standardized methodologies, processes, templates, evidence requirements, and quality controls.
- Lead risk assessments, control assessments, compliance readiness, policy governance, Managed Audit, Managed Questionnaires, and other GRC engagements.
- Manage client commitments, priorities, capacity, deliverable quality, and service performance.
- Identify opportunities for automation and AI to improve GRC delivery and scalability.
- Partner with Sales and Client Success on service scoping, SOWs, pricing, and complex opportunities.
Federal Compliance & SSP Management
- Lead and maintain System Security Plans for federal clients.
- Develop and review control implementation statements and supporting evidence.
- Coordinate with technical control owners to validate how controls are implemented.
- Manage POA&Ms, control deficiencies, remediation activities, milestones, and dependencies.
- Coordinate responses to government, assessor, and auditor findings and requests.
- Facilitate SSP and control working sessions with clients, engineers, security teams, and other stakeholders.
- Support continuous monitoring, security assessments, and authorization activities.
- Maintain alignment between documented controls and the actual operating environment.
- Support requirements involving NIST SP 800-53, NIST SP 800-171, FISMA, CMMC, FedRAMP concepts, and agency-specific requirements.
Risk, Compliance & Audit Management
- Lead cybersecurity risk assessments, control gap assessments, risk registers, treatment plans, exceptions, and remediation tracking.
- Support frameworks including SOC 2, NIST, CIS, ISO 27001, PCI DSS, HIPAA, CMMC, and Microsoft security benchmarks.
- Own Atmosera's Managed Audit methodology, including audit readiness, evidence management, auditor coordination, findings, and remediation.
- Oversee Managed Security Questionnaire delivery and development of reusable response and evidence libraries.
- Ensure policies, standards, procedures, and control documentation accurately reflect operational practices.
Internal GRC
Partner with the CISO to operate and mature Atmosera's internal security and compliance program, including:
- SOC 2 Type 2
- Risk and control assessments
- Policy and control governance
- Audit coordination
- Security questionnaires
- Third-party risk
- Customer security reviews
- Evidence and remediation management
- Serve as a senior GRC advisor to client security, IT, risk, compliance, and executive leadership.
- Translate regulatory and compliance requirements into actionable security improvements.
- Partner with Security Operations, Managed Azure, Microsoft 365, and engineering teams to map control requirements to technical implementations.
- Maintain working knowledge of Microsoft security technologies including Azure, Entra ID, Defender, Sentinel, Intune, Purview, and Azure Policy.
- Support vCISO engagements where governance, risk, audit, or compliance expertise is required.
Team Leadership
- Lead, mentor, and develop GRC Analysts and Consultants.
- Manage workload, capacity, priorities, quality assurance, and escalations.
- Build repeatable processes that allow the GRC practice to scale without depending on the Director for every engagement.
We measure success by results and alignment. Here is how we define a “win” for this role:
After 90 Days
Complete onboarding, shadow active engagements, and produce a written audit of current MGRC workflows with three prioritized opportunities.
After 1 Year
Independent ownership of Atmosera's GRC function, managing the SOC 2 Type 2 program, leading MGRC delivery, and directly managing complex federal SSP activities.
The Director should be able to take government or assessor findings, identify required stakeholders, drive accurate responses and remediation, validate supporting evidence, and maintain a defensible SSP while simultaneously building the team, processes, and automation necessary to scale the GRC practice.
Qualifications
- 8+ years of cybersecurity, GRC, security assessment, audit, or related experience.
- Demonstrated experience leading GRC programs or teams.
- Hands-on experience with NIST SP 800-53, System Security Plans, POA&Ms, control implementation statements, and federal security requirements.
- Experience managing audits, evidence, risk assessments, control gaps, policies, and remediation programs.
- Ability to translate regulatory requirements into technical and operational security controls.
- Strong client-facing, executive communication, and technical stakeholder management skills.
Preferred Qualifications (Bonus Points)
- Experience in an MSSP, MSP, consulting, professional services, federal program, or government contractor environment.
- Microsoft Azure and Microsoft 365 security experience strongly preferred.
- CISSP, CISM, CRISC, CISA, CGEIT, or similar certifications.
These 'Core Three' represent the heartbeat of Atmosera. They are the behaviors and attributes we align to every day, defining how we interact, solve problems, and celebrate our wins together. This is simply who we are at our best.
Humble
- Low Ego, High Impact
- We share credit easily, admit when we're wrong, and view every mistake as a data point for growth.
Hungry
- Internal Drive
- We have a natural bias for action. We don't wait for permission to solve a problem or find a better way to do things.
Mindful
- Intentional Awareness
- We are conscious of our impact on the team. We listen more than we speak and respond to challenges with empathy and situational awareness.
- Talent Screen (30 mins) — A conversation about your background and the role mission.
- The Impact & Attributes Assessment (60 mins w/ our CISO) — The 'How' — Cultural DNA and The Core Three.
- Collaborator Loop (45-60 mins w/ 2 peers) — The 'What' — Required Skills and Core Capabilities. May include a presentation or work sample.
- Final Alignment w/ our Exec Team*
We value our employees and are committed to providing a comprehensive and competitive benefits package designed to support your well-being and financial security. Here's what you can look forward to:
Financial Security & Growth:
Competitive Salary: We offer competitive salaries commensurate with experience and skills.
Generous 401(k) Plan: Secure your financial future with our generous 401(k) plan, featuring a 100% company match on your contributions up to 4% of your salary! This is a fantastic opportunity to build your retirement savings with our support.
Performance-Based Compensation: Your hard work and dedication will be recognized and rewarded through our performance-based compensation program, which includes bonus potential in addition to your base salary.
Health & Well-being:
100% Employer-Paid Health, Vision, and Dental Insurance for employees: Say goodbye to expensive premiums! We cover 100% of the cost of your health, vision, and dental insurance premiums, saving you potentially thousands of dollars each year. Focus on your health, not your healthcare costs.
Company-Paid Life, AD&D, Short and Long-Term Disability Insurance: We provide company-paid life, accidental death & dismemberment, and short- and long-term disability insurance to protect you and your family.
Time Off & Work-Life Balance:
Generous Paid Time Off (PTO): Enjoy a healthy work-life balance with three weeks of paid time off, allowing you to relax, recharge, and pursue your personal interests. This flexible PTO can be used for vacation, personal time, or sick leave.
11 Paid Holidays: We observe 11 paid holidays throughout the year, giving you additional time to spend with family and friends.
Community Service Leave: We believe in giving back to the community and offer paid time off for you to volunteer with organizations that are meaningful to you.
Additional Perks & Recognition:
Employee Recognition and Reward Program: We celebrate and reward outstanding performance and contributions through our employee recognition program. We value your dedication and are committed to showing our appreciation.
This is a full-time position in the United States with the ability to work from home, or from one of our many US offices if local.
Atmosera is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. All employment is decided on the basis of qualifications, merit, and business need.
Similar Jobs
Manager, Engineering - Sales Planning
CaptivateIQ · Canada,USA
Technical Program Manager
Paula's Choice Skincare · USA
Senior Director of Product | Mid-Cycle and Backend RCM Platform
Infinx · USA
Vice President, Banking & Financial Services Industry Leader
Quantum Metric · USA
Senior Technical Program Manager - Security
OpenAI · USA