CFGI Logo

CFGI

GRC and AI Governance - Senior Manager

Posted Yesterday
Be an Early Applicant
Remote or Hybrid
Hiring Remotely in United States
Senior level
Remote or Hybrid
Hiring Remotely in United States
Senior level
Lead cybersecurity GRC, privacy, and AI governance advisory engagements for enterprise and private equity clients. Design governance models, risk programs, control frameworks, privacy operations, third-party risk programs, and AI compliance frameworks aligned with NIST AI RMF, EU AI Act, and ISO 42001. Advise executives, develop board-ready deliverables, manage client workstreams, support business development, and mentor consulting teams.
The summary above was generated by AI

Cybersecurity: GRC & AI Governance – Senior Manager

 

CFGI is a leading advisory firm that partners with private equity sponsors, portfolio companies, and public companies to solve complex challenges across finance, technology, compliance, and business transformation. Our Cybersecurity practice is rapidly growing and supports clients through cybersecurity governance, risk and compliance (GRC), data privacy, AI governance and compliance, regulatory readiness, and operational resilience programs.

 

Role Overview

CFGI is seeking a Cybersecurity GRC & AI Governance Subject Matter Expert to lead and deliver strategic advisory engagements that strengthen clients’ security governance, risk management, compliance posture, AI governance programs, and privacy programs. This role blends hands-on delivery, executive communication, and practice leadership. You will work directly with CISOs, CIOs, CFOs, General Counsel/Privacy Counsel, Risk Leaders, and PE deal teams to design pragmatic programs, build operating models, and drive measurable outcomes.

 

The ideal candidate brings deep expertise in GRC frameworks, regulatory compliance, privacy, and AI governance and compliance (e.g., NIST AI RMF, EU AI Act), strong consulting instincts, and a proven ability to lead teams and manage multiple client workstreams.

 

Key Responsibilities

 

Client Advisory & Delivery

  • Lead end-to-end GRC and privacy engagements, including scoping, planning, execution, and executive reporting.
  • Design and operationalize cybersecurity governance models, including policies, standards, risk appetite, committees, and reporting KPIs/KRIs.
  • Build and mature enterprise risk programs, including risk assessments, risk registers, control libraries, and control testing approaches.
  • Lead AI governance and compliance engagements — design and operationalize AI governance frameworks, conduct AI risk and impact assessments, build model inventories, establish AI use-case classification and tiering, advise on responsible AI principles, and guide clients through compliance with the EU AI Act, NIST AI RMF, and ISO 42001.
  • Develop and implement security policies, standards, and procedures aligned to common frameworks, including NIST CSF, ISO 27001/27002, CIS, SOC 2, CMMC, FedRAMP, NIST AI RMF, and ISO 42001.
  • Support regulatory readiness and compliance initiatives, including SEC cyber disclosure support, NYDFS 500, GDPR/UK GDPR, CCPA/CPRA, HIPAA, PCI DSS, SOX ITGC, EU AI Act, CMMC, and FedRAMP alignment where applicable.
  • Stand up or enhance privacy programs, including data mapping/inventories, DPIAs/PIAs, DSAR processes, retention, consent management, third-party privacy risk, and privacy by design.
  • Support CMMC readiness activities where applicable, including gap analyses and compliance alignment to NIST SP 800-171.
  • Perform vendor/third-party risk assessments and implement scalable TPRM operating models.
  • Coordinate cross-functional stakeholders, including Legal, IT, Security, Compliance, Product, and HR, to drive outcomes and adoption.

 

Executive Communication & Stakeholder Management

  • Translate complex technical, regulatory, privacy, and AI governance requirements into business-oriented recommendations.
  • Help clients communicate AI risk posture and governance maturity to boards, regulators, and executive leadership, including EU AI Act compliance status and NIST AI RMF alignment.
  • Deliver executive-ready artifacts, including board/audit committee materials, roadmaps, operating models, heatmaps, and risk dashboards.
  • Serve as a trusted advisor to senior leadership; confidently present findings and influence decisions.

 

Practice Development & Leadership

  • Contribute to go-to-market development, including offerings, templates, accelerators, methodologies, and points of view.
  • Support business development through proposal writing, SOW development, client presentations, and solution shaping.
  • Mentor and develop consultants and managers; lead teams across multiple engagements while maintaining quality and delivery rigor.
  • Partner with other CFGI service lines, including Accounting Advisory, CFO Advisory, and Technology Enablement, to deliver integrated solutions.

 

What You Must Have

  • 8+ years of relevant experience in cybersecurity GRC, privacy, governance, risk management, compliance, or consulting.
  • Demonstrated expertise implementing and operationalizing cybersecurity frameworks and control programs, including NIST CSF/NIST 800-53, ISO 27001/27002, SOC 2, CIS, or comparable frameworks, with strong privacy fundamentals and experience with privacy program build-out and operations.
  • Demonstrated expertise in AI governance and compliance frameworks, including NIST AI RMF, EU AI Act, and ISO 42001, with experience in AI risk classification, algorithmic impact assessments, responsible AI principles, and practical application within enterprise or client-facing advisory engagements.

 

What Sets You Apart

  • Experience performing or leading enterprise/security risk assessments, control design and testing, policy and standards development, TPRM programs, compliance/regulatory readiness programs, and AI governance program design and implementation.
  • Experience with GDPR/UK GDPR and CCPA/CPRA, with exposure to HIPAA, GLBA, or other sectoral privacy standards.
  • Proven ability to lead teams, manage timelines and budgets, and deliver effectively in a client-facing environment.
  • Exceptional written and verbal communication skills with a track record of producing executive-level deliverables.
  • Experience advising on AI governance strategy, responsible AI programs, or AI risk management within regulated industries such as financial services, healthcare, energy, or defense.
  • Familiarity with AI lifecycle management, model validation, and AI supply chain risk.

 

Nice to Have

  • Certifications such as CISM, CISSP, CRISC, CISA, ISO 27001 Lead Implementer/Lead Auditor, CIPM/CIPP (E/US), CDPSE, AI/ML-related certifications such as CAIAP or ISO 42001 Lead Implementer, or CMMC RP/CCA.
  • Exposure to CMMC or FedRAMP readiness activities.
  • Private equity or portfolio company experience, including rapid maturity uplift, integration, carve-out/stand-up, and pragmatic road mapping.
  • Exposure to incident readiness, tabletop exercises, and crisis communications coordination with Legal/Communications.
  • Experience supporting audits and assurance activities, including SOC 2 readiness, ISO certification readiness, CMMC certification readiness, or internal audit coordination.

 

Why CFGI

  • High-impact work with sophisticated clients and private equity portfolio companies.
  • Opportunity to shape and scale a fast-growing Cybersecurity practice.
  • Collaborative culture with autonomy, flexibility, and strong leadership support.
  • Competitive compensation, benefits, and career growth trajectory.

Similar Jobs

9 Minutes Ago
In-Office or Remote
124K-195K Annually
Expert/Leader
124K-195K Annually
Expert/Leader
Cloud • Information Technology • Productivity • Security • Software • App development • Automation
Enterprise solution seller responsible for driving new business and expansion across AMER and APAC. Develops strategic plans, exceeds bookings and OKR targets, closes complex six- and seven-figure SaaS transactions, builds CXO-level relationships, generates pipeline with sales and channel partners, presents forecasts, and monitors market and competitive shifts. Requires extensive enterprise cloud software sales experience and expertise in Strategic Portfolio Management, PPM, ERP, or CRM solutions.
Top Skills: Cloud-Based SoftwareCRMErpPpmSaaSStrategic Portfolio Management
9 Minutes Ago
In-Office or Remote
81K-128K Annually
Entry level
81K-128K Annually
Entry level
Cloud • Information Technology • Productivity • Security • Software • App development • Automation
Manage the full customer lifecycle for DX customers, including implementation, adoption, success planning, renewals, expansion, and executive engagement. Track account metrics, forecast renewals, resolve retention risks, identify growth opportunities, and align customer use cases with business goals. The role requires proactive collaboration across internal teams and four days per week onsite in Salt Lake City.
Top Skills: AtlassianDx Platform
9 Minutes Ago
In-Office or Remote
180K-283K Annually
Senior level
180K-283K Annually
Senior level
Cloud • Information Technology • Productivity • Security • Software • App development • Automation
Lead a team of 6–10 enterprise account executives, develop sales strategies, achieve revenue targets, manage key customer relationships, and drive high-performance culture. Responsibilities include coaching, recruiting, performance management, pipeline analysis, executive negotiations, cross-functional collaboration, and reporting to senior leadership.
Top Skills: Analytics ToolsCRMPipeline ManagementSaaS

What you need to know about the Seattle Tech Scene

Home to tech titans like Microsoft and Amazon, Seattle punches far above its weight in innovation. But its surrounding mountains, sprinkled with world-famous hiking trails and climbing routes, make the city a destination for outdoorsy types as well. Established as a logging town before shifting to shipbuilding and logistics, the Emerald City is now known for its contributions to aerospace, software, biotech and cloud computing. And its status as a thriving tech ecosystem is attracting out-of-town companies looking to establish new tech and engineering hubs.

Key Facts About Seattle Tech

  • Number of Tech Workers: 287,000; 13% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Amazon, Microsoft, Meta, Google
  • Key Industries: Artificial intelligence, cloud computing, software, biotechnology, game development
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Madrona, Fuse, Tola, Maveron
  • Research Centers and Universities: University of Washington, Seattle University, Seattle Pacific University, Allen Institute for Brain Science, Bill & Melinda Gates Foundation, Seattle Children’s Research Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account