Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
ACM Global Laboratories

Manager, Governance, Risk & Compliance

ACM Global Laboratories

GRC Manager leading compliance and risk management programs for ACM Global Laboratories. Driving adherence to industry standards and regulations while fostering a culture of compliance.

Posted 8/1/2026full-timeRemote • 🇺🇸 United StatesMid-LevelSenior💰 $115,000 - $140,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in leading Governance, Risk, and Compliance (GRC) programs, with a strong focus on ISO 27001 compliance, risk management, and security frameworks. Capable of developing and implementing policies, managing third-party risk, and fostering cross-functional collaboration to enhance security and compliance culture.

Highest-signal resume keywords
Governance, Risk, And Compliance (GRC) LeadershipISO 27001 ProficiencyGRC Certifications (CGRC, CRISC)Risk Assessment And ManagementThird-Party Risk Management

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
ISO 27001SOC 2NIST CSFHIPAA RegulationsRisk Data AnalysisPolicy ManagementInternal AuditSecurity ComplianceRisk Register MaintenanceBusiness Continuity Planning
Soft Skills
Excellent Communication SkillsStakeholder InteractionTeam LeadershipCross-Functional CollaborationAnalytical Thinking
Certifications & Qualifications
CGRCCRISC
Industry Keywords
Third-Party RiskSecurity FrameworksCompliance StandardsRisk Mitigation StrategiesGRC Processes

Tech Stack

Tools & technologies
Cyber Security

About the role

Key responsibilities & impact
  • Leads the GRC program activities and a team of professionals related to third-party risk, security internal audit, security compliance, and ISMS program management.
  • Develop, document, and implement internal policies and procedures to ensure compliance with industry standards and legal requirements.
  • Facilitate regular risk assessments against security frameworks such as SOC 2, ISO 27001, and PCI-DSS, maintain a risk register, and collaborate on mitigation strategies for identified threats.
  • Manage CAPAs for non-compliance.
  • Define specific, assignable actions to mitigate the identified risks or exploit the opportunities.
  • Evaluate how to embed the planned actions directly into daily operational processes.
  • Manage security responses to client questions and questionnaires, including RFPs, RFIs, annual risk reviews, and ad-hoc communication requests.
  • Manage and update business continuity and disaster recovery documentation, including BIAs, plan revisions, team rosters, and dependencies.
  • Plan, coordinate, and document annual exercises, such as tests, tabletops, and other exercises.
  • Build and manage a security metrics (KPI’s) program.
  • Develop relationships with cross-functional teams, understanding their needs in relation to security standards, to drive risk-informed decision-making and build a culture of compliance.
  • Provide expert guidance and support in navigating complex regulatory environments in relation to the management of alignment to ISO-27001 and other applicable security frameworks.
  • Stay updated on applicable industry trends and regulations to ensure ISMS compliance.
  • Monitor and analyze GRC processes and systems, making recommendations for improvement.
  • Document risk reduction plan.
  • Annually, document “Opportunities” (potential positive improvements like adopting some technology for improved efficiency).
  • Other duties as assigned.

Requirements

What you’ll need
  • Minimum of 5 years of experience leading Governance, Risk, and Compliance (GRC) programs.
  • Proficiency in ISO 27001
  • GRC certifications (e.g. CGRC, CRISC, etc)
  • A bachelor’s degree in IT, cybersecurity, business, or law is preferred, or strong demonstrable background in GRC Management.
  • Previous experience in GRC, risk management, or internal audit, often with a mid-level leadership background.
  • Proficiency in frameworks like SOC2, NIST CSF, and HIPAA regulations.
  • Strong ability to analyze risk data and translate complex regulations into actionable controls.
  • Excellent communication skills to interact with stakeholders and lead team efforts.
  • Experience with 3rd party/vendor risk management processes.
  • Experience in working with sales teams to complete Requests for Proposals and security questionnaires.
  • Understanding of GRC processes such as policy management, risk assessment, and IT audits.
  • Exceptional verbal and written communication skills.

Benefits

Comp & perks
  • Health insurance
  • Retirement plans