$ cat jobs/manager-governance-risk-compliance-acm-global-laboratories-9dd7725bf2da.json
Manager, Governance, Risk & Compliance
Job Title: Governance Risk & Compliance Manager Department: Information Security Location: Remote, United States Schedule: Days, Monday - Friday SUMMARY The Governance, Risk & Compliance [GRC] Manager at ACM Global Laboratories translates strategic direction into actionable workflows, coordinates cross-functional teams, supports evidence lifecycle management, maps frameworks to control implementation, leads readiness activities, and ensures all ACM GRC processes operate smoothly and efficiently. RESPONSIBILITIES Leads the GRC program activities and a team of professionals related to third-party risk, security internal audit, security compliance, and ISMS program management. Develop, document, and implement internal policies and procedures to ensure compliance with industry standards and legal requirements. Facilitate regular risk assessments against security frameworks such as SOC 2, ISO 27001, and PCI-DSS, maintain a risk register, and collaborate on mitigation strategies for identified threats. Manage CAPAs for non-compliance. Define specific, assignable actions to mitigate the identified risks or exploit the opportunities. Evaluate how to embed the planned actions directly into daily operational processes. Manage security responses to client questions and questionnaires, including RFPs, RFIs, annual risk reviews, and ad-hoc communication requests. Manage and update business continuity and disaster recovery documentation, including BIAs, plan revisions, team rosters, and dependencies. Plan, coordinate, and document annual exercises, such as tests, tabletops, and other exercises. Build and manage a security metrics (KPI’s) program. Develop relationships with cross-functional teams, understanding their needs in relation to security standards, to drive risk-informed decision-making and build a culture of compliance. Provide expert guidance and support in navigating complex regulatory environments in relation to the management of alignment to ISO-27001 and other appli