Director of Governance, Risk & Compliance (Remote US)
Quick Summary
Financial Security & Growth: Competitive Salary: We offer competitive salaries commensurate with experience and skills.
The Director of Governance, Risk & Compliance (GRC) leads Atmosera's internal GRC program and Managed Governance, Risk & Compliance (MGRC) services.
This is a hands-on leadership role responsible for GRC program strategy, service delivery, team leadership, client engagements, and continuous improvement. The Director will establish scalable GRC processes while directly supporting complex client and internal compliance initiatives.
A key responsibility is hands-on management of federal security programs, including System Security Plans (SSPs), control implementation statements, evidence, POA&Ms, remediation activities, and responses to government and assessor findings.
The ideal candidate can operate at both the executive and practitioner levels, working effectively with CISOs and auditors while also working directly with engineers and control owners to validate how security controls are implemented.
Deliverables include...
Requirements
~1 min readWe measure success by results and alignment. Here is how we define a “win” for this role:
- Experience in an MSSP, MSP, consulting, professional services, federal program, or government contractor environment.
- Microsoft Azure and Microsoft 365 security experience strongly preferred.
- CISSP, CISM, CRISC, CISA, CGEIT, or similar certifications.
These 'Core Three' represent the heartbeat of Atmosera. They are the behaviors and attributes we align to every day, defining how we interact, solve problems, and celebrate our wins together. This is simply who we are at our best.
Complete onboarding, shadow active engagements, and produce a written audit of current MGRC workflows with three prioritized opportunities.
Independent ownership of Atmosera's GRC function, managing the SOC 2 Type 2 program, leading MGRC delivery, and directly managing complex federal SSP activities.
The Director should be able to take government or assessor findings, identify required stakeholders, drive accurate responses and remediation, validate supporting evidence, and maintain a defensible SSP while simultaneously building the team, processes, and automation necessary to scale the GRC practice.
- Talent Screen (30 mins) — A conversation about your background and the role mission.
- The Impact & Attributes Assessment (60 mins w/ our CISO) — The "How" — Cultural DNA and The Core Three.
- Collaborator Loop (45-60 mins w/ 2 peers) — The "What" — Required Skills and Core Capabilities. May include a presentation or work sample.
- Final Alignment w/ our Exec Team*
Location & Eligibility
Listing Details
- Posted
- October 1, 2026
- First seen
- October 1, 2026
- Last seen
- October 1, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 68%
- Scored at
- October 1, 2026
Signal breakdown
Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.