top of page

GRC Risk Manager

Houston, TX, USA

Job Type

Full Time/Contract

Workspace

Hybrid

About the Role

We are seeking a GRC Risk Manager to lead risk identification, control assessment, and governance initiatives across our client portfolio. This role operates at the intersection of traditional enterprise risk management and emerging AI governance — bridging frameworks like NIST CSF/RMF, CIS Controls, and NIST AI RMF to deliver actionable security posture improvements.

Requirements

Vervation LLC is a cybersecurity, AI automation, and enterprise architecture consultancy serving Fortune 500 clients. We are seeking a GRC Risk Manager to lead risk identification, control assessment, and governance initiatives across our client portfolio. This role operates at the intersection of traditional enterprise risk management and emerging AI governance — bridging frameworks like NIST CSF/RMF, CIS Controls, and NIST AI RMF to deliver actionable security posture improvements. The ideal candidate is equally comfortable presenting board-level risk briefings and conducting hands-on control gap analyses.

  • Risk & compliance program management

    • Lead enterprise risk assessments aligned to NIST CSF 2.0 and CIS Controls IG1–IG3

    • Develop and maintain risk registers, treatment plans, and KRI dashboards

    • Conduct CIS Critical Security Controls gap analyses for SMB and enterprise clients

    • Map control deficiencies to business impact and remediation roadmaps

  • AI governance & emerging risk

    • Apply NIST AI RMF (Govern, Map, Measure, Manage) to client AI deployments

    • Assess AI system risks including bias, explainability, data provenance, and model drift

    • Develop AI use policies, acceptable use frameworks, and third-party AI vendor risk reviews

    • Align AI governance posture to evolving regulatory guidance (EU AI Act, NIST)

  • vCISO advisory support

    • Support fractional CISO engagements with risk briefings and board-ready reporting

    • Facilitate tabletop exercises and cyber risk scenario planning

    • Advise on security architecture decisions with a risk-informed lens

  • Policy, audit & third-party risk

    • Author and maintain security policies, standards, and control narratives

    • Manage vendor risk assessments and supply chain security reviews

    • Support SOC 2, ISO 27001, HIPAA, or CMMC audit preparation as applicable

Experience

  • 5–8+ years in GRC, information security risk, or compliance roles

  • Demonstrated hands-on experience with NIST CSF, NIST RMF, and CIS Controls

  • Prior work in Fortune 500, regulated industries, or consulting environments

  • Experience leading or supporting vCISO/advisory engagements preferred

Education & certifications

  • B.S. or higher in Cybersecurity, Information Systems, or related field

  • CISSP, CISM, CRISC, or CGEIT (one or more required)

  • NIST AI RMF Practitioner designation or equivalent AI governance training a plus

  • CIS SecureSuite or CCISO certification valued

About the Company

Vervation LLC is a cybersecurity, AI automation, and enterprise architecture consultancy serving Fortune 500 clients.

bottom of page