NorthwoodSpace

NorthwoodSpace

Governance, Risk & Compliance (GRC) Manager

Torrance, CA

No sponsorship$171k-$800kDetected 32 days ago
TypeScriptAWSCybersecuritySOC OperationsIncident ResponseComplianceNetwork EngineeringLeadershipCommunication

About the role

  • You will serve as the primary point of contact for government customers, third-party assessors, and internal stakeholders on all matters related to compliance posture, risk management, and audit readiness.
  • You will work across Northwood's full security stack - spanning on-premises infrastructure, AWS GovCloud, GCC, and corporate systems - to ensure controls are implemented, documented, and defensible.
  • This role reports to the Head of Security.

Responsibilities

  • Own Northwood's compliance program across CMMC Level 2, FedRAMP, SOC 2 Type II, and ITAR, including control mapping, gap assessment, remediation tracking, and audit preparation.
  • Maintain Northwood's System Security Plan (SSP), Plan of Action and Milestones (POA&M), and associated compliance documentation in alignment with NIST 800-171 and applicable frameworks.
  • Coordinate and manage third-party assessments, including C3PAO engagements for CMMC, FedRAMP 3PAO assessments, and SOC 2 audits, serving as the primary assessor liaison.
  • Build and maintain Northwood's enterprise risk management program, including risk register development, risk scoring methodology, and executive-level risk reporting.
  • Identify, track, and drive remediation of compliance gaps and security control deficiencies, working directly with technical teams to ensure timely closure.
  • Develop and maintain risk acceptance processes, exception management workflows, and compensating control documentation.
  • Develop, maintain, and enforce Northwood's security policy library, including acceptable use, access control, incident response, data classification, and CUI handling policies.
  • Define and maintain the control evidence collection program, ensuring audit artifacts are continuously gathered, organized, and accessible for assessment cycles.
  • Partner with the Security Engineering Lead, Security Operations Lead, and Product Security Lead to validate that technical controls are implemented in alignment with documented policies and compliance requirements.
  • Own Northwood's CUI program, including data classification guidance, CUI handling procedures, marking standards, and employee training.

Requirements

  • 5+ years in a governance, risk, and compliance role with demonstrated ownership of enterprise compliance programs in a regulated environment.
  • Deep working knowledge of CMMC Level 2 and NIST SP 800-171, including SSP development, POA&M management, and C3PAO assessment preparation.
  • Experience managing FedRAMP authorization processes, including boundary definition, control implementation documentation, and 3PAO coordination.
  • Hands-on experience with SOC 2 Type II audits, including control mapping, evidence collection, and auditor engagement.
  • Familiarity with ITAR compliance requirements, including technology control plans, export authorization processes, and CUI program management.
  • Demonstrated ability to translate technical security controls into compliance documentation and audit evidence across multiple overlapping frameworks.
  • Experience conducting risk assessments and maintaining enterprise risk registers with executive-level reporting.
  • Strong technical fluency - this role works directly with security engineering and infrastructure teams and requires the ability to evaluate technical control implementations against compliance requirements.
  • U.S. citizenship or status as a lawful permanent resident required to conform with ITAR export regulations.
  • Your ability to secure the necessary clearance is essential for fulfilling key responsibilities of the role.

Nice to have

  • Active TS clearance or higher.
  • Experience working within the Defense Industrial Base, including prime or subcontractor compliance environments with DFARS flow-down obligations.
  • Familiarity with eMASS or similar government assessment and authorization management tools.
  • Experience with GRC platforms for control tracking, evidence management, and audit workflow automation.
  • Knowledge of Northwood's core infrastructure environment, including AWS GovCloud, Microsoft GCC, and on-premises security tooling, and how these map to FedRAMP and CMMC control boundaries.
  • Familiarity with DFARS 252.204-7012 incident reporting obligations and coordination with DIBCAC or DCSA.
  • Professional certifications such as CISSP, CISM, CISA, CCSK, or equivalent GRC credentials.
  • CMMC Registered Practitioner (RP) or Certified Professional (CP) designation.

Skills

  • Northwood is a modern space infrastructure company bringing the benefits of space to the masses through advanced communications technology.

Compensation

  • $171k-$800k

Company info

  • Serve as the primary compliance point of contact for government customers, prime contractors, and subcontractors, including responding to security questionnaires, flow-down requirement reviews, and customer audit requests.
  • If you need a reasonable accommodation as part of your application for employment or interviews with us, please let us know.

Visa & Work Authorization

  • citizenship or status as a lawful permanent resident required to conform with ITAR export regulations

This listing is sourced directly from NorthwoodSpace's careers page and normalized into a canonical job model.