CFGI Logo

CFGI

GRC and AI Governance - Senior Manager

Reposted 24 Days Ago
Remote or Hybrid
Hiring Remotely in United States
Senior level
Remote or Hybrid
Hiring Remotely in United States
Senior level
The role involves leading GRC and AI governance engagements, advising clients on risk management and compliance, and developing governance frameworks. Responsibilities include managing client engagements, enhancing privacy programs, and collaborating with stakeholders to drive compliance and security initiatives.
The summary above was generated by AI

CFGI is seeking a Cybersecurity GRC & AI Governance Subject Matter Expert to lead and deliver strategic advisory engagements that strengthen clients’ security governance, risk management, compliance posture, AI governance programs, and privacy programs. This role blends hands-on delivery, executive communication, and practice leadership. You will work directly with CISOs, CIOs, CFOs, General Counsel/Privacy Counsel, Risk Leaders, and PE deal teams to design pragmatic programs, build operating models, and drive measurable outcomes.

 

The ideal candidate brings deep expertise in GRC frameworks, regulatory compliance, privacy, and AI governance and compliance (e.g., NIST AI RMF, EU AI Act), strong consulting instincts, and a proven ability to lead teams and manage multiple client workstreams.

 

Key Responsibilities:

 

Client Advisory & Delivery:

 

  • Lead end-to-end GRC and privacy engagements, including scoping, planning, execution, and executive reporting.
  • Design and operationalize cybersecurity governance models (policies, standards, risk appetite, committees, reporting KPIs/KRIs).
  • Build and mature enterprise risk programs: risk assessments, risk registers, control libraries, and control testing approaches.
  • Lead AI governance and compliance engagements — design and operationalize AI governance frameworks, conduct AI risk and impact assessments, build model inventories, establish AI use-case classification and tiering, advise on responsible AI principles, and guide clients through compliance with the EU AI Act, NIST AI RMF, and ISO 42001.
  • Develop and implement security policies, standards, and procedures aligned to common frameworks (e.g., NIST CSF, ISO 27001/27002, CIS, SOC 2, CMMC, FedRAMP, NIST AI RMF, ISO 42001).
  • Support regulatory readiness and compliance initiatives (e.g., SEC cyber disclosure support, NYDFS 500, GDPR/UK GDPR, CCPA/CPRA, HIPAA, PCI DSS, SOX ITGC, EU AI Act, CMMC, FedRAMP alignment where applicable).
  • Stand up or enhance privacy programs: data mapping/inventories, DPIAs/PIAs, DSAR processes, retention, consent management, third-party privacy risk, and privacy by design.
  • Support CMMC readiness activities where applicable, including gap analyses and compliance alignment to NIST SP 800-171 (experience a plus, not required).
  • Perform vendor/third-party risk assessments and implement scalable TPRM operating models.
  • Coordinate cross-functional stakeholders (Legal, IT, Security, Compliance, Product, HR) to drive outcomes and adoption.

 

Executive Communication & Stakeholder Management:

 

  • Translate complex technical, regulatory, privacy, and AI governance requirements into business-oriented recommendations.
  • Help clients communicate AI risk posture and governance maturity to boards, regulators, and executive leadership, including EU AI Act compliance status and NIST AI RMF alignment.
  • Deliver executive-ready artifacts: board/audit committee materials, roadmaps, operating models, heatmaps, and risk dashboards.
  • Serve as a trusted advisor to senior leadership; confidently present findings and influence decisions.

 

Practice Development & Leadership:

 

  •  Support business development through proposal writing, SOW development, client presentations, and solution shaping.
  • Contribute to go-to-market development: offerings, templates, accelerators, methodologies, and points of view.
  • Mentor and develop consultants and managers; lead teams across multiple engagements while maintaining quality and delivery rigor.
  • Partner with other CFGI service lines (Accounting Advisory, CFO Advisory, Technology Enablement) to deliver integrated solutions.

 

Required Qualifications:

 

  • Eight plus years of relevant experience in cybersecurity GRC, privacy, governance, risk management, compliance, or consulting (level will map to experience).
  • Bachelor’s degree in a related field is required.
  • Demonstrated expertise implementing and operationalizing cybersecurity frameworks and control programs: NIST CSF / NIST 800-53, ISO 27001/27002, SOC 2, CIS, NIST AI RMF, ISO 42001; familiarity with CMMC and FedRAMP a plus.
  • Strong privacy fundamentals and experience with privacy program build-out and operations: GDPR/UK GDPR, CCPA/CPRA; experience with HIPAA/GLBA or other sectoral privacy standards is a plus.
  • Demonstrated expertise in AI governance and compliance frameworks (NIST AI RMF, EU AI Act, ISO 42001), including AI risk classification, algorithmic impact assessments, responsible AI principles, and practical application within enterprise or client-facing advisory engagements.
  • Exposure to CMMC or FedRAMP readiness activities is a plus but not required.
  • Experience performing or leading: enterprise/security risk assessments, control design/testing, policy and standards development, TPRM programs, compliance/regulatory readiness programs, AI governance program design and implementation.
  • Exceptional written and verbal communication skills with a track record of producing executive-level deliverables.
  • Proven ability to lead teams, manage timelines/budgets, and deliver in a client-facing environment.

 

Preferred Qualifications (Nice-to-Have):

 

  • Certifications: CISM, CISSP, CRISC, CISA, ISO 27001 Lead Implementer/Lead Auditor, CIPM/CIPP (E/US), CDPSE, AI/ML-related certifications (e.g., CAIAP, ISO 42001 Lead Implementer); CMMC RP or CCA a plus.
  • PE/portfolio company experience: rapid maturity uplift, integration, carve-out/stand-up, and pragmatic road mapping.
  • Exposure to incident readiness, tabletop exercises, and crisis communications coordination with Legal/Comms.
  • Experience supporting audits and assurance activities (SOC 2 readiness, ISO certification readiness, CMMC certification readiness, internal audit coordination).
  • Experience advising on AI governance strategy, responsible AI programs, or AI risk management within regulated industries (financial services, healthcare, energy, defense); familiarity with AI lifecycle management, model validation, and AI supply chain risk.

 

Why CFGI:

 

  • High-impact work with sophisticated clients and private equity portfolio companies.
  • Opportunity to shape and scale a fast-growing Cybersecurity practice.
  • Collaborative culture with autonomy, flexibility, and strong leadership support.
  • Competitive compensation, benefits, and career growth trajectory.

Similar Jobs

5 Hours Ago
Remote or Hybrid
3 Locations
97K-134K Annually
Mid level
97K-134K Annually
Mid level
Big Data • Food • Hardware • Machine Learning • Retail • Automation • Manufacturing
Lead shopper and category insights for Meijer, using syndicated, shopper, and retailer data to develop category strategies, planograms, and dashboards that drive assortment, promotion, and merchandising recommendations to grow sales and market share. Collaborate with sales, buyers, and cross-functional teams and support joint business planning and performance optimization.
Top Skills: ApolloDunnhumbyIri/CircanaJdaExcelMicrosoft PowerpointNielseniqNumeratorPower BIPower QueryShelfiqSpectraTableauVendornet
5 Hours Ago
Remote or Hybrid
7 Locations
130K-234K Annually
Senior level
130K-234K Annually
Senior level
eCommerce • Fintech • Hardware • Payments • Software • Financial Services
Outbound-focused senior account executive responsible for sourcing and closing new restaurant merchant logos. Duties include prospecting, discovery, demos, consultative selling of Square ecosystem, field relationship building, partnering with BD/Product/Marketing, managing the sales cycle and onboarding, and meeting monthly sales KPIs using Salesforce.
Top Skills: SalesforceSquare
5 Hours Ago
Remote or Hybrid
144K-216K Annually
Senior level
144K-216K Annually
Senior level
Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Lead and manage audit, review, and compilation engagements for construction clients. Oversee engagement planning, staffing, budgeting, fieldwork, risk assessment, and reporting. Advise on complex GAAP and FASB issues, support clients with accounting compliance and ASC updates, provide training, supervise teams, and participate in business development and community activities.

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account