GRC Program Lead || Hybrid in CA or Remote Job at DMS Vision Inc, Delaware, OH

WDRzNUhNVkFXcW5QVURrQnRFM042cGpicFE9PQ==
  • DMS Vision Inc
  • Delaware, OH

Job Description

Hi,
Hope you are doing well !!


I have an urgent position. Kindly go through the Job description and let me know if this would be of interest to you.



Job Title :GRC Program Lead



Location : Vernon \ Los Angeles, CA (Hybrid Preferred/Remote 100% ok)



Duration: 6+ Months Contract

Visa : GC or USC or H4 or TN Visas Preferred

Interview : 2-3 Zoom Video Interviews / Might be asked to go onsite in Vernon

Must Have:

LinkedIn with a picture

10 15+ years progressive experience in IT Audit/Controls, or Enterprise Risk

5+ years leading GRC programs in public companies.

End to end ISO 27001 implementation experience (ISMS design through certification). SOX 404 ITGC ownership experience, including scoping, control design, testing, and remediation across ERP (e.g., SAP/Oracle) and key business applications.

Must have Certification - ISO/IEC 27001 Lead Implementer and/or Lead Auditor

About the Role

Forgent is seeking a hands-on Program Lead for Governance, Risk & Compliance (GRC) to build, lead, and mature our enterprise GRC program. This role is accountable for ISO/IEC 27001 certification readiness and maintenance and Sarbanes Oxley (SOX) IT compliance, spanning IT general controls (ITGCs), application controls, and operational technology (OT) considerations in a manufacturing context. You will lead cross-functional teams of internal employees and external vendors, drive governance processes, operationalize risk management, coordinate audits, and ensure continuous compliance across our global footprint.

Key Responsibilities

Governance & Program Leadership:

  • Establish and mature the enterprise GRC program aligned to ISO 27001, SOX, NIST CSF, CIS Controls and relevant regulatory requirements.
  • Own the Information Security Management System (ISMS) lifecycle: scope definition, risk assessment, Statement of Applicability (SoA), control implementation, internal audit, management review, corrective actions, and surveillance/recertification readiness.
  • Define and maintain policies, standards, and procedures (e.g., access control, change management, vulnerability management, secure SDLC, incident response, supplier security).
  • Chair/coordinate governance forums (e.g., Risk & Compliance Steering Committee, Change Advisory Board, Management Review meetings).

Risk Management:

  • Implement enterprise risk management (ERM) for information and technology risks: risk identification, assessment (qualitative/quantitative), treatment plans, and risk acceptance with accountable owners.
  • Build third party/vendor risk management (TPRM) including due diligence, contractual controls, continuous monitoring, and remediation.
  • Integrate operational technology (OT) risk (ICS/SCADA, IIoT) into the enterprise risk register with pragmatic controls that do not disrupt production.

Compliance: ISO 27001 & SOX:

  • Lead ISO 27001 certification journey: gap analysis, roadmap, control implementation, training/awareness, internal audits, and liaison with external certification bodies.
  • Own SOX ITGCs and application controls: design, documentation, testing coordination, remediation tracking, and /Disclosure Committee reporting.
  • Align identity & access management, change management, computer operations, and IT service delivery to SOX and ISO control objectives; ensure evidence quality and audit readiness.
  • Coordinate with Finance/Accounting on financial reporting risks.

Audit & Assurance:

  • Plan and execute internal audits (ISO 27001, policy compliance, control effectiveness) and coordinate external audits (SOX, ISO surveillance/certification, PCI).
  • Build defensible control evidence repositories, ensure sampling precision, and drive timely remediation of findings.
  • Develop and maintain control libraries, test plans, and mapping across frameworks (ISO/NIST, SOX ITGC etc.).

Tooling, Automation & Metrics:

  • Select, implement, and administer GRC platforms (e.g., Archer/Drata/Vanta, ServiceNow GRC/IRM, OneTrust) and integrate with ticketing, IAM, CMDB, SIEM, and ERP (e.g., SAP/Oracle).
  • Operationalize continuous control monitoring (CCM) and control analytics (e.g., access outliers, change exceptions, segregation of duties conflicts).
  • Define and publish KPIs/KRIs and Board/C suite dashboards: audit status, control effectiveness, residual risk, TPRM posture, policy adoption, incident trends.

Team Leadership & Vendor Management:

  • Lead a hybrid, geographically distributed team of employees and vendor/consulting resources; set objectives, coach, and develop talent.
  • Build SOWs, manage budgets, and ensure vendor SLAs/KPIs and quality outcomes.
  • Foster a culture of accountability, transparency, and continuous improvement.

Training, Awareness & Change Management:

  • Lead assessment and management of training + phishing campaign platform and process (e.g., SOX for IT engineers, ISO control owners, plant operations staff).
  • Drive change management communications to embed controls into daily operations without impeding manufacturing throughput.

Incident, BCP/DR & Privacy Alignment:

  • Ensure incident response processes are governed, tested, and produce audit-ready evidence.
  • Oversee BCP/DR governance (business impact analysis, testing cadence, lessons learned).
  • Partner with Legal/Privacy on data protection, records retention, and supplier agreements (e.g. CCPA).

Qualifications

Education

Bachelor's degree in Information Systems, Computer Science, Engineering, Accounting/Finance, or related field preferred. Advanced degree (MBA, MS Information Assurance) is a plus.

Experience

10 15+ years progressive experience in IT Audit/Controls, or Enterprise Risk; 5+ years leading GRC programs in public companies. End to end ISO 27001 implementation experience (ISMS design through certification). SOX 404 ITGC ownership experience, including scoping, control design, testing, and remediation across ERP (e.g., SAP/Oracle) and key business applications. Demonstrated success in leading mixed teams of internal staff and vendor/consultants, including multi site and global operations. Manufacturing/OT exposure: ICS/SCADA risk management, plant floor realities (safety, uptime, maintenance windows). Hands on with GRC platforms, IAM, CMDB, SIEM/SOAR, vulnerability management, and evidence repositories. Strong familiarity with NIST CSF, CIS Controls, and control mapping across frameworks.

Certifications (Preferred)

  • ISO/IEC 27001 Lead Implementer and/or Lead Auditor (MUST HAVE THIS ONE)
  • CISA (Certified Information Systems Auditor)
  • CISM or CISSP
  • CRISC
  • CGEIT
  • ITIL Foundation

Skills & Competencies

  • Hands-on control design and evidence creation; comfort reading logs, configs, and ERP control parameters.

Job Tags

Contract work, Remote work,

Similar Jobs

Cathy Hobbs Design Recipes

Interior Designer/Home Stager (PT) Job at Cathy Hobbs Design Recipes

** DESIGN ROCK STARS PLEASE APPLY!** COVER LETTERS ARE REQUIRED FOR CONSIDERATION...  ...cover letters! Position: PART-TIME - Interior Designer / Home Stager HUDSON VALLEY HEADQUARTERED...  .... Design Center Duties: Working with our Hudson Valley clients relating... 

Job Bridge Global

Horse Groom - Relocation to Kentucky Job at Job Bridge Global

 ...Job Title: Horse Groom / Wrangler / Farm Hand Relocate to Kentucky, USA Looking for a physically rewarding job with growth and...  ...thoroughbred horse farms in the world. Whether youre a ranch hand, stable worker, horse rider, or just someone whos grown up around... 

Farm Job Search

Dairy Farm Herdsman Job at Farm Job Search

 ...Dairy Farm Herdsman (6192) Location: Iowa JobNumber: 6192 Dairy Farm Herdsman position immediately available on a 600-cow dairy in Northeastern Iowa. Must have dairy farm experience that includes A.I. breeding, herd health, record keeping and administering IV'... 

Cornerstone Building Brands

Inside Sales Representative Job at Cornerstone Building Brands

 ...Job Description Mueller, Inc., is looking for an Inside Sales Representative to join its Robstown, TX branch. The Inside Sales...  ...and sales of metal building systems, residential metal roofing and components Enter sales orders into software systems and coordinate... 

Anytime Fitness

Personal/Group Fitness Trainer Job at Anytime Fitness

 ...Anytime Fitness is considered to be a premier place to work within the industry, where...  ...fitness. This is a position to help grow our Personal Training department by working in a...  ...every day is different. CERTIFIED PERSONAL TRAINER The Personal Trainers focus is on...