- Company Name
- Lila Sciences
- Job Title
- Director, Governance, Risk and Compliance
- Job Description
-
**Job Title:** Director, Governance Risk and Compliance
**Role Summary:**
Lead the design, implementation, and continuous improvement of enterprise-wide Governance, Risk, and Compliance (GRC) programs for a high‑growth technology organization. Own full lifecycle compliance for SOC2, ISO, GDPR, FedRAMP, DoD Cloud SRG (IL5/IL6), and CMMC. Partner with engineering, security, product, legal, and executive teams to ensure compliance is integrated as a growth enabler.
**Expectations:**
- Deliver end‑to‑end GRC strategy, policies, and operating cadence.
- Serve as primary liaison for FedRAMP, DoD, CMMC, and third‑party risk processes.
- Provide executive‑level dashboards and risk reporting.
- Operate at both strategy and execution levels, driving remediation and risk acceptance decisions.
- Maintain U.S. citizenship; active or eligible security clearance preferred.
**Key Responsibilities:**
- Design and maintain enterprise GRC framework, standards, and risk management processes.
- Translate regulatory requirements into actionable controls for software, engineering, and operations.
- Lead the FedRAMP authorization lifecycle: readiness, SSPs, POA&Ms, SARs, CMPs, continuous monitoring, and liaison with 3PAOs and Authorizing Officials.
- Develop and execute DoD Cloud SRG IL5/IL6 compliance strategy; support security reviews and audits.
- Define and implement CMMC readiness roadmap; align NIST SP 800‑171/SP 800‑53 controls across teams.
- Oversee third‑party risk program: due diligence, assessment, monitoring, and remediation.
- Automate evidence collection and validation, enabling lightweight reporting.
- Serve as trusted advisor to the CISO and executive leadership on compliance risks and customer engagement.
**Required Skills:**
- 10–15+ years of cybersecurity GRC experience, including federal and DoD environments.
- Hands‑on ownership of FedRAMP authorization, DoD Cloud SRG IL5/IL6, and CMMC program management.
- Deep knowledge of NIST frameworks (RMF, SP 800‑171, SP 800‑53).
- Proven ability to build compliance programs in high‑growth or defense‑focused SaaS environments.
- Strong communication and stakeholder management across technical and executive audiences.
- Ability to balance speed, risk, and revenue considerations.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Security, Business Administration, or related field (advanced degree preferred).
- Relevant certifications: CISSP, CISM, CISA, CRISC (or equivalent).
- U.S. citizenship; active or eligible security clearance preferred.