Job Description We are seeking a Senior Consultant, Governance, Risk & Compliance (GRC) who will be responsible for leading and executing cybersecurity governance, risk management, compliance, security assurance, and third-party risk management initiatives. This position partners closely with business, technology, and executive stakeholders to drive a risk-based cybersecurity program that protects organizational assets while enabling business objectives.
This role combines strategic leadership with hands-on execution and provides oversight of a small team of GRC professionals. The ideal candidate will serve as a trusted advisor to senior leadership, translating cybersecurity risks into business terms and supporting informed risk-based decision-making.
Key ResponsibilitiesCybersecurity GovernanceDevelop, implement, and maintain cybersecurity policies, standards, procedures, and governance frameworks.
Lead governance committees, policy exception processes, and cross-functional accountability for cybersecurity risk management.
Enterprise Risk ManagementManage cybersecurity risk assessments, risk registers, risk treatment plans, and risk reporting activities.
Drive a risk-based approach to cybersecurity priorities, investments, and business decisions.
Third-Party Risk ManagementOversee vendor security assessments, due diligence reviews, contract security requirements, and remediation efforts.
Partner with Procurement, Legal, Privacy, and business stakeholders to manage risk throughout the vendor lifecycle.
Compliance, Audit & Security AssuranceLead cybersecurity compliance initiatives, control assessments, audit readiness activities, and regulatory alignment efforts.
Manage remediation of audit findings, control gaps, compliance issues, and regulatory commitments.
Metrics, Reporting & Executive CommunicationsDevelop and maintain cybersecurity metrics, dashboards, KRIs, KPIs, and reporting processes.
Prepare and present cybersecurity updates, risk assessments, and strategic recommendations to executive leadership and governance bodies.
Security Awareness & CultureLead cybersecurity awareness, training, and culture-building initiatives.
Measure program effectiveness and drive continuous improvement through communications and education campaigns.
Cross-Functional CollaborationAct as a trusted cybersecurity advisor to business and technology leaders.
Facilitate cross-functional discussions and drive resolution of cybersecurity, compliance, and third-party risk issues.
Team LeadershipLead, mentor, and develop a small team of GRC professionals.
Establish priorities, performance expectations, and career development plans.
Foster a collaborative, customer-focused, and results-oriented culture.
Hands-On ExecutionConduct cybersecurity risk assessments, vendor assessments, policy development, compliance reviews, audit support, executive reporting, and board-level presentation development.
Manage day-to-day GRC operations and ensure timely execution of governance, risk, compliance, and reporting activities. Skills and Requirements
- 15+ years of experience in cybersecurity, governance, risk management, compliance, audit, or related disciplines, including leadership experience.
- Demonstrated experience building and operating cybersecurity GRC programs, developing executive and Board-level communications, and partnering effectively with senior executives and business leaders.
- Strong knowledge of cybersecurity frameworks, risk management methodologies, third-party risk management, regulatory compliance, and security governance practices.
- Relevant certifications such as CISSP, CISM, CRISC, CISA, or CGEIT preferred.
- Experience in the pharmaceutical, biotechnology, healthcare, or other highly regulated industries preferred.
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal employment opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment without regard to race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or the recruiting process, please send a request to HR@insightglobal.com.