Manager, Governance, Risk & Compliance

UMA Education
Tampa, FL
Remote
Job Description
Role Overview

The Manager, Governance, Risk & Compliance is responsible for leading and advancing the institution’s governance, risk management, compliance, and information security programs to support the achievement of organizational objectives and regulatory requirements. This role develops, implements, and monitors frameworks, policies, controls, and risk mitigation strategies that promote operational effectiveness, safeguard institutional assets, and ensure compliance with applicable laws, regulations, accreditation standards, and internal policies.

What You Will Do

Lead Governance, Risk, and Compliance Programs: Develop, implement, and continuously enhance the institution’s governance, risk management, and compliance framework to ensure alignment with organizational objectives, regulatory requirements, accreditation standards, and recognized industry practices. Conduct Cybersecurity and Technology Risk Management Activities: Lead the identification, assessment, monitoring, and mitigation of cybersecurity and technology risks.

Why It Might Be a Fit

The ideal candidate will have progressive experience in information security governance, cybersecurity risk management, regulatory compliance, security assurance, or a related discipline. Experience leading and developing team members or directing complex, cross-functional information security and GRC programs and initiatives is also required.

Requirements

  • Bachelor’s degree in cybersecurity, information security, information systems, computer science, risk management, business administration, or a related field, or an equivalent combination of education and relevant professional experience.
  • Progressive experience in information security governance, cybersecurity risk management, regulatory compliance, security assurance, or a related discipline.
  • Experience leading and developing team members or directing complex, cross-functional information security and GRC programs and initiatives.
  • Experience managing or supporting a vulnerability management program, including vulnerability assessments, patch and remediation coordination, risk-based prioritization, exception management, validation, and performance reporting.
  • Experience conducting third-party information security and privacy risk assessments and evaluating vendor controls, audit reports, certifications, contractual requirements, and remediation plans.
  • Working knowledge of recognized cybersecurity frameworks and standards, including the NIST Cybersecurity Framework, applicable NIST Special Publications, CIS Critical Security Controls, and other relevant risk and control frameworks.
  • Technical understanding of cloud environments, identity and access management, endpoint security, network security, vulnerability management, data protection, logging and monitoring, application security, and software-as-a-service platforms.
  • Experience developing meaningful information security and GRC metrics, key performance indicators, key risk indicators, dashboards, and executive-level reporting.
  • Experience creating, reviewing, maintaining, and implementing information security, privacy, risk-management, and technology policies, standards, and procedures.
  • Experience monitoring cybersecurity, privacy, breach-notification, and data-protection requirements and partnering with Legal and Compliance to translate applicable requirements into operational and technical controls.
  • Experience using one or more GRC, integrated risk-management, third-party risk, privacy, vulnerability-management, audit, or security platforms, such as ServiceNow IRM/GRC, OneTrust, LogicGate, Tenable, Qualys, Rapid7, or comparable technologies.

Benefits

  • Medical (including prescription), Dental, Vision (UMA subsidized)
  • FSA/HSA (Depending on Medical Plan chosen)
  • Basic Life Insurance (UMA paid)
  • Additional Voluntary Life Insurance (Team Member paid)
  • Employee Assistance Program – EAP (UMA paid)
  • Long Term Disability (UMA paid)
  • Short Term Disability (Team Member paid)
  • Supplemental Insurance such as Critical Illness, Accident, and Hospital (Team Member Paid)
  • Paid Time Off – 15 days accrued in year 1, 9 holidays, and 1 day of Volunteering Time Off
  • 401k (eligible upon completion of 90 days of employment and must be at least 18 years of age)
  • Pet Insurance
  • Identity Theft Protection
]]>