NorthwoodSpace
Governance, Risk & Compliance (GRC) Manager
Torrance, CA
No sponsorship$171k-$800kDetected 32 days ago
TypeScriptAWSCybersecuritySOC OperationsIncident ResponseComplianceNetwork EngineeringLeadershipCommunication
About the role
- You will serve as the primary point of contact for government customers, third-party assessors, and internal stakeholders on all matters related to compliance posture, risk management, and audit readiness.
- You will work across Northwood's full security stack - spanning on-premises infrastructure, AWS GovCloud, GCC, and corporate systems - to ensure controls are implemented, documented, and defensible.
- This role reports to the Head of Security.
Responsibilities
- Own Northwood's compliance program across CMMC Level 2, FedRAMP, SOC 2 Type II, and ITAR, including control mapping, gap assessment, remediation tracking, and audit preparation.
- Maintain Northwood's System Security Plan (SSP), Plan of Action and Milestones (POA&M), and associated compliance documentation in alignment with NIST 800-171 and applicable frameworks.
- Coordinate and manage third-party assessments, including C3PAO engagements for CMMC, FedRAMP 3PAO assessments, and SOC 2 audits, serving as the primary assessor liaison.
- Build and maintain Northwood's enterprise risk management program, including risk register development, risk scoring methodology, and executive-level risk reporting.
- Identify, track, and drive remediation of compliance gaps and security control deficiencies, working directly with technical teams to ensure timely closure.
- Develop and maintain risk acceptance processes, exception management workflows, and compensating control documentation.
- Develop, maintain, and enforce Northwood's security policy library, including acceptable use, access control, incident response, data classification, and CUI handling policies.
- Define and maintain the control evidence collection program, ensuring audit artifacts are continuously gathered, organized, and accessible for assessment cycles.
- Partner with the Security Engineering Lead, Security Operations Lead, and Product Security Lead to validate that technical controls are implemented in alignment with documented policies and compliance requirements.
- Own Northwood's CUI program, including data classification guidance, CUI handling procedures, marking standards, and employee training.
Requirements
- 5+ years in a governance, risk, and compliance role with demonstrated ownership of enterprise compliance programs in a regulated environment.
- Deep working knowledge of CMMC Level 2 and NIST SP 800-171, including SSP development, POA&M management, and C3PAO assessment preparation.
- Experience managing FedRAMP authorization processes, including boundary definition, control implementation documentation, and 3PAO coordination.
- Hands-on experience with SOC 2 Type II audits, including control mapping, evidence collection, and auditor engagement.
- Familiarity with ITAR compliance requirements, including technology control plans, export authorization processes, and CUI program management.
- Demonstrated ability to translate technical security controls into compliance documentation and audit evidence across multiple overlapping frameworks.
- Experience conducting risk assessments and maintaining enterprise risk registers with executive-level reporting.
- Strong technical fluency - this role works directly with security engineering and infrastructure teams and requires the ability to evaluate technical control implementations against compliance requirements.
- U.S. citizenship or status as a lawful permanent resident required to conform with ITAR export regulations.
- Your ability to secure the necessary clearance is essential for fulfilling key responsibilities of the role.
Nice to have
- Active TS clearance or higher.
- Experience working within the Defense Industrial Base, including prime or subcontractor compliance environments with DFARS flow-down obligations.
- Familiarity with eMASS or similar government assessment and authorization management tools.
- Experience with GRC platforms for control tracking, evidence management, and audit workflow automation.
- Knowledge of Northwood's core infrastructure environment, including AWS GovCloud, Microsoft GCC, and on-premises security tooling, and how these map to FedRAMP and CMMC control boundaries.
- Familiarity with DFARS 252.204-7012 incident reporting obligations and coordination with DIBCAC or DCSA.
- Professional certifications such as CISSP, CISM, CISA, CCSK, or equivalent GRC credentials.
- CMMC Registered Practitioner (RP) or Certified Professional (CP) designation.
Skills
- Northwood is a modern space infrastructure company bringing the benefits of space to the masses through advanced communications technology.
Compensation
- $171k-$800k
Company info
- Serve as the primary compliance point of contact for government customers, prime contractors, and subcontractors, including responding to security questionnaires, flow-down requirement reviews, and customer audit requests.
- If you need a reasonable accommodation as part of your application for employment or interviews with us, please let us know.
Visa & Work Authorization
- citizenship or status as a lawful permanent resident required to conform with ITAR export regulations
Apply directly at NorthwoodSpace →Create a free account for alerts like thisView NorthwoodSpace immigration profile
This listing is sourced directly from NorthwoodSpace's careers page and normalized into a canonical job model.