Captechconsulting

Captechconsulting

GRC Team Lead

Richmond, VA, United States

No sponsorship$53k-$800kDetected 13 days ago
PythonPowerShellLLMsCybersecurityComplianceBusiness DevelopmentNegotiationVendor ManagementPerformance ManagementHIPAALeadershipProblem SolvingMentoringMicrosoft Office

About the role

  • Today we work alongside clients that include Fortune 100 companies, mid-sized enterprises, and government agencies, a list that spans across the country.
  • CapTech is an equal opportunity employer committed to fostering a culture of equality, inclusion and fairness - each foundational to our core values.

Responsibilities

  • Lead, mentor, and develop a GRC analyst, setting priorities, coaching for growth, and serving as the escalation point for complex risk and compliance matters.
  • Own and mature CapTech's compliance programs across SOC 2, NIST 800-53, and NIST AI RMF, ensuring controls are well-designed, operating effectively, and continuously monitored.
  • Lead internal control assessments, gap analyses, and audit-readiness activities; manage external audits and coordinate evidence collection end to end.
  • Develop, maintain, and enforce the information security policy suite, partnering with policy owners to keep documentation current and aligned to controls.
  • Identify, assess, and prioritize information security risks; drive remediation to closure against SLAs, negotiating compensating controls with stakeholders where appropriate.
  • Own and enhance the Third-Party Risk Management (TPRM) framework, policy, process, and supporting technology in alignment with SOC 2 requirements.
  • Lead responses to inbound client and partner security questionnaires, and support business development and contract-negotiation teams to ensure security terms align with RFPs and agreed contracts.
  • Own and administer CapTech's GRC / compliance-automation platform, driving continuous control monitoring and automated evidence collection.
  • Design and build workflow automations and integrations across security, IT, and compliance tooling to reduce manual effort, improve data quality, and accelerate audit readiness.
  • Leverage AI responsibly to accelerate GRC work, using large language models to draft and maintain policies, cross-walk controls across frameworks, and analyze and respond to security questionnaires.

Requirements

  • 6+ years of experience in Information Security, Governance/Risk/Compliance, IT Audit, or a related field, including prior experience leading or mentoring team members or driving major security and compliance initiatives.
  • Working understanding of SOC 2, NIST 800-53, and NIST AI RMF or similar frameworks required.
  • Demonstrated ability to communicate technical risk in non-technical terms to executives and business stakeholders.
  • Strong problem-solving, analytical, and critical-thinking skills, with the proven ability to set direction and make decisions independently.
  • This position reports to the Head of Information Security and operates with a high degree of autonomy to make decisions and set direction with minimal oversight.

Nice to have

  • Additional certifications such as Certified Information Systems Auditor (CISA), Certified in Governance, Risk and Compliance (CGRC), or equivalent risk/audit/compliance credentials.
  • Hands-on experience owning or administering a GRC / compliance-automation platforms
  • Experience automating GRC workflows through scripting or integration tooling (e.g., Python, PowerShell, APIs, or iPaaS / no-code automation platforms).
  • Experience establishing or operating an AI governance program, with familiarity in the NIST AI RMF and ISO/IEC 42001.
  • Experience with privacy and regulatory frameworks such as HIPAA and GDPR/CCPA.
  • Prior experience in a consulting environment or supporting Fortune 100 and other regulated clients.
  • Prior experience with vendor management and third-party risk assessments.
  • Strong knowledge of the Microsoft Office suite of tools.

Compensation

  • $53k-$800k

Benefits

  • Instrument GRC metrics, dashboards, and reporting so that control health and risk posture are continuously visible to stakeholders.

Visa & Work Authorization

  • At this time, CapTech cannot transfer nor sponsor a work visa for this position

This listing is sourced directly from Captechconsulting's careers page and normalized into a canonical job model.