Captechconsulting
GRC Team Lead
Richmond, VA, United States
No sponsorship$53k-$800kDetected 13 days ago
PythonPowerShellLLMsCybersecurityComplianceBusiness DevelopmentNegotiationVendor ManagementPerformance ManagementHIPAALeadershipProblem SolvingMentoringMicrosoft Office
About the role
- Today we work alongside clients that include Fortune 100 companies, mid-sized enterprises, and government agencies, a list that spans across the country.
- CapTech is an equal opportunity employer committed to fostering a culture of equality, inclusion and fairness - each foundational to our core values.
Responsibilities
- Lead, mentor, and develop a GRC analyst, setting priorities, coaching for growth, and serving as the escalation point for complex risk and compliance matters.
- Own and mature CapTech's compliance programs across SOC 2, NIST 800-53, and NIST AI RMF, ensuring controls are well-designed, operating effectively, and continuously monitored.
- Lead internal control assessments, gap analyses, and audit-readiness activities; manage external audits and coordinate evidence collection end to end.
- Develop, maintain, and enforce the information security policy suite, partnering with policy owners to keep documentation current and aligned to controls.
- Identify, assess, and prioritize information security risks; drive remediation to closure against SLAs, negotiating compensating controls with stakeholders where appropriate.
- Own and enhance the Third-Party Risk Management (TPRM) framework, policy, process, and supporting technology in alignment with SOC 2 requirements.
- Lead responses to inbound client and partner security questionnaires, and support business development and contract-negotiation teams to ensure security terms align with RFPs and agreed contracts.
- Own and administer CapTech's GRC / compliance-automation platform, driving continuous control monitoring and automated evidence collection.
- Design and build workflow automations and integrations across security, IT, and compliance tooling to reduce manual effort, improve data quality, and accelerate audit readiness.
- Leverage AI responsibly to accelerate GRC work, using large language models to draft and maintain policies, cross-walk controls across frameworks, and analyze and respond to security questionnaires.
Requirements
- 6+ years of experience in Information Security, Governance/Risk/Compliance, IT Audit, or a related field, including prior experience leading or mentoring team members or driving major security and compliance initiatives.
- Working understanding of SOC 2, NIST 800-53, and NIST AI RMF or similar frameworks required.
- Demonstrated ability to communicate technical risk in non-technical terms to executives and business stakeholders.
- Strong problem-solving, analytical, and critical-thinking skills, with the proven ability to set direction and make decisions independently.
- This position reports to the Head of Information Security and operates with a high degree of autonomy to make decisions and set direction with minimal oversight.
Nice to have
- Additional certifications such as Certified Information Systems Auditor (CISA), Certified in Governance, Risk and Compliance (CGRC), or equivalent risk/audit/compliance credentials.
- Hands-on experience owning or administering a GRC / compliance-automation platforms
- Experience automating GRC workflows through scripting or integration tooling (e.g., Python, PowerShell, APIs, or iPaaS / no-code automation platforms).
- Experience establishing or operating an AI governance program, with familiarity in the NIST AI RMF and ISO/IEC 42001.
- Experience with privacy and regulatory frameworks such as HIPAA and GDPR/CCPA.
- Prior experience in a consulting environment or supporting Fortune 100 and other regulated clients.
- Prior experience with vendor management and third-party risk assessments.
- Strong knowledge of the Microsoft Office suite of tools.
Compensation
- $53k-$800k
Benefits
- Instrument GRC metrics, dashboards, and reporting so that control health and risk posture are continuously visible to stakeholders.
Visa & Work Authorization
- At this time, CapTech cannot transfer nor sponsor a work visa for this position
Apply directly at Captechconsulting →Create a free account for alerts like thisView Captechconsulting immigration profile
This listing is sourced directly from Captechconsulting's careers page and normalized into a canonical job model.