About the Role
We are seeking a GRC Risk Manager to lead risk identification, control assessment, and governance initiatives across our client portfolio. This role operates at the intersection of traditional enterprise risk management and emerging AI governance — bridging frameworks like NIST CSF/RMF, CIS Controls, and NIST AI RMF to deliver actionable security posture improvements.
Requirements
Vervation LLC is a cybersecurity, AI automation, and enterprise architecture consultancy serving Fortune 500 clients. We are seeking a GRC Risk Manager to lead risk identification, control assessment, and governance initiatives across our client portfolio. This role operates at the intersection of traditional enterprise risk management and emerging AI governance — bridging frameworks like NIST CSF/RMF, CIS Controls, and NIST AI RMF to deliver actionable security posture improvements. The ideal candidate is equally comfortable presenting board-level risk briefings and conducting hands-on control gap analyses.
Risk & compliance program management
Lead enterprise risk assessments aligned to NIST CSF 2.0 and CIS Controls IG1–IG3
Develop and maintain risk registers, treatment plans, and KRI dashboards
Conduct CIS Critical Security Controls gap analyses for SMB and enterprise clients
Map control deficiencies to business impact and remediation roadmaps
AI governance & emerging risk
Apply NIST AI RMF (Govern, Map, Measure, Manage) to client AI deployments
Assess AI system risks including bias, explainability, data provenance, and model drift
Develop AI use policies, acceptable use frameworks, and third-party AI vendor risk reviews
Align AI governance posture to evolving regulatory guidance (EU AI Act, NIST)
vCISO advisory support
Support fractional CISO engagements with risk briefings and board-ready reporting
Facilitate tabletop exercises and cyber risk scenario planning
Advise on security architecture decisions with a risk-informed lens
Policy, audit & third-party risk
Author and maintain security policies, standards, and control narratives
Manage vendor risk assessments and supply chain security reviews
Support SOC 2, ISO 27001, HIPAA, or CMMC audit preparation as applicable
Experience
5–8+ years in GRC, information security risk, or compliance roles
Demonstrated hands-on experience with NIST CSF, NIST RMF, and CIS Controls
Prior work in Fortune 500, regulated industries, or consulting environments
Experience leading or supporting vCISO/advisory engagements preferred
Education & certifications
B.S. or higher in Cybersecurity, Information Systems, or related field
CISSP, CISM, CRISC, or CGEIT (one or more required)
NIST AI RMF Practitioner designation or equivalent AI governance training a plus
CIS SecureSuite or CCISO certification valued
About the Company
Vervation LLC is a cybersecurity, AI automation, and enterprise architecture consultancy serving Fortune 500 clients.
