THE TEAM YOU'LL BE JOINING
- Join a mission-driven technology organization focused on delivering innovative digital learning solutions that make a meaningful impact on millions of learners and educators.
- Become part of a collaborative Information Security team investing heavily in strengthening enterprise security, governance, and risk management capabilities.
- Partner directly with executive leadership, including the Chief Information Security Officer (CISO), to shape long-term cybersecurity strategy.
- Work in a greenfield environment where you'll help build foundational GRC processes rather than simply maintaining existing programs.
- Collaborate across Information Security, IT, Legal, Compliance, Privacy, and business leaders to establish enterprise-wide governance.
- Contribute to an organization that values innovation, continuous improvement, and scalable security practices as the business continues to grow.
WHAT THEY OFFER YOU
- Opportunity to build and influence an enterprise Governance, Risk & Compliance program from the ground up.
- Direct exposure to executive leadership with the ability to make a visible impact across the organization.
- Flexible work environment supporting professionals located in either the U.S. or UK.
- High level of autonomy with the ability to own initiatives from strategy through execution.
- Collaborative culture that encourages cross-functional partnership and continuous learning.
- Opportunity to work with modern security frameworks, governance practices, and enterprise risk management initiatives.
- Competitive contract engagement with the opportunity to leave a lasting organizational impact.
WHAT YOU WILL DO
- Build and operationalize the enterprise Governance, Risk & Compliance (GRC) program from the ground up.
- Establish, maintain, and manage the enterprise risk register, including risk identification, assessments, remediation tracking, and reporting.
- Coordinate governance forums and lead operational execution of monthly Security Steering Committee meetings.
- Develop executive dashboards, KPIs, KRIs, and reporting that provide leadership with meaningful visibility into enterprise risk.
- Support compliance initiatives aligned with SOC 2, ISO 27001, NIST, and other security frameworks while preparing for future maturity.
- Partner with internal stakeholders and external auditors to support audits, evidence collection, control mapping, and compliance activities.
- Create repeatable documentation, governance templates, and operational playbooks that enable long-term sustainability and knowledge transfer.
THE BACKGROUND THAT FITS
- 5+ years of experience in Governance, Risk & Compliance (GRC), Information Security, IT Risk, Audit, or Compliance.
- Demonstrated success building or maturing enterprise GRC, risk management, or governance programs.
- Strong knowledge of security frameworks including NIST, SOC 2, ISO 27001, and enterprise risk management methodologies.
- Experience managing enterprise risk registers, facilitating governance committees, and driving risk remediation activities.
- Ability to develop executive-level reporting, dashboards, metrics, and presentations for both technical and business leadership.
- Hands-on experience with GRC platforms such as ServiceNow GRC, Archer, AuditBoard, LogicGate, OneTrust, or similar solutions.
- Professional certifications such as CRISC, CISA, CISSP, or ISO 27001 Lead Implementer are highly valued, along with exceptional communication and stakeholder management skills.



