Enter a job title or keyword

Technical Program Manager, GRC


Job Location:

Chicago, IL - USA

Monthly Salary: Not provided by the employer
Posted: 18 September 2026 (Yesterday)
Application Deadline: 16 December 2026
Vacancies: 1 Vacancy

Job Summary

Title:Technical Program Manager GRC

# of Openings:1
Position Type:Contract to Hire
Locations:Louisville
Additional Details:


6monthsCTH
100%Remote(CandidatesonlyfromCST&ESTzones)


Description:

Summary:

The Technical Program Manager Governance Risk and Compliance establishes and runs the program structure that converts cybersecurity governance risk audit and compliance priorities into coordinated delivery tied to strategic outcomes and measurable risk reduction. This role manages intake maintains integrated roadmaps and delivery cadence tracks dependencies and remediation commitments and gives leaders reliable visibility into capacity progress risk to plan tradeoffs and decisions required.

You will join an evolving GRC control plane. Working closely with the Senior Manager GRC and accountable control owners across Information Security Technology Internal Audit and the business you will establish repeatable operating mechanisms and remain accountable for program coordination delivery transparency and follow-through without absorbing functional ownership. The Senior Manager GRC retains accountability for GRC strategy prioritization risk decisions policy standards control frameworks third-party risk oversight and formal audit or control conclusions. Control owners and GRC practitioners retain responsibility for control execution testing and evidence production.

Responsibilities:
  • Establish and operate the GRC program cadence including working sessions remediation reviews leadership reporting decision forums and action follow-through.
  • Manage intake and demand for work entering the GRC function maintain a transparent view of capacity and competing commitments and prepare prioritization recommendations for decision by the Senior Manager GRC.
  • Build and maintain integrated plans milestones dependencies decision logs role definitions and handoffs so the operating model is repeatable and durable.
  • Build and maintain an integrated GRC program roadmap that connects prioritized risk and compliance outcomes to initiatives milestones dependencies capacity assumptions and measurable results.
  • Protect functional capacity by identifying unplanned demand surfacing tradeoffs and routing prioritization decisions to the accountable leader.
  • Maintain the authoritative remediation and commitment backlog for internal audit observations compliance obligations and approved corrective actions.
  • Confirm accountable owners target dates dependencies closure criteria and escalation paths; challenge stale or unsupported status.
  • Coordinate evidence requests and readiness checkpoints across control owners without creating testing or approving the evidence on their behalf.
  • Coordinate schedule inputs for SOX PCI DSS regulatory and disclosure-related cycles as directed by the Senior Manager GRC.
  • Coordinate remediation reporting and supporting materials for review by the Senior Manager GRC who owns formal communication and relationship management with Internal Audit and external auditors.
  • Coordinate commitments across GRC Identity and Access Management Cyber Defense and Incident Response Security Architecture Infrastructure application teams and business process owners.
  • Manage dependencies between security commitments and technology delivery plans escalating ownership gaps or constraints that put outcomes at risk.
  • Facilitate decision forums prepare decision records document accountable owners and track resulting actions to closure.
  • Maintain clear boundaries between program coordination and functional accountability so GRC leaders and control owners retain their decision and execution responsibilities.
  • Configure and maintain enterprise work-management workflows fields queries and views needed to make status reliable without parallel manual trackers.
  • Produce portfolio reporting that connects GRC priorities commitments owners delivery status aging dependencies capacity risk to plan expected risk-reduction outcomes tradeoffs and decisions required.
  • Measure and report program outcomes including cycle time remediation closure rate aging throughput commitment reliability capacity constraints and evidence of risk reduction or improved audit readiness.
  • Track GRC capability maturity against the defined operating model identify structural or process gaps and coordinate improvement actions with the Senior Manager GRC and fractional leadership.
  • Translate complex delivery issues into concise decision-oriented reporting for senior leaders.
Requirements:
  • Success in this role depends on disciplined coordination transparent reporting and the ability to move work across organizational boundaries without positional authority.
  • Partner with the Senior Manager GRC who owns enterprise risk governance policy direction control frameworks compliance oversight third-party risk oversight and formal assessment conclusions.
  • Partner with the Senior Analyst GRC and control owners who perform assessments administer GRC processes produce evidence and execute control activities.
  • Make ownership explicit by documenting who decides who executes what is due and where escalation goes.
  • Protect the separation between governance program coordination and control execution. Do not author policy approve risk render control-effectiveness conclusions administer OneTrust vendor reviews or become the default producer of missing evidence.
  • Use established enterprise work-management tooling as the system of record and drive a single transparent view of commitments rather than creating disconnected trackers.
  • Escalate with evidence and preserve the working relationships needed for sustained cross-functional delivery.
Required Skills:
  • Seven or more years managing technical or cybersecurity programs including experience in a regulated environment with audit SOX PCI DSS or comparable compliance obligations.
  • Demonstrated ownership of cross-functional programs in which accountable delivery resources report elsewhere in the organization.
  • Hands-on experience configuring and operating an enterprise work-management platform such as Jira or ServiceNow including workflows fields queries dashboards and reporting controls.
  • Experience managing remediation audit compliance risk or control commitments from intake through validated closure.
  • Ability to hold owners accountable surface tradeoffs and escalate missed commitments without relying on positional authority.
  • Strong written visual and verbal communication skills including concise executive reporting and decision-oriented facilitation.
  • Working knowledge of recognized cybersecurity and control frameworks such as CIS Controls v8 NIST Cybersecurity Framework SOX IT general controls or PCI DSS.
  • Ability to prioritize competing demands and deliver independently in a remote environment.
Preferred Skills:
  • Experience standing up a program operating model intake process governance cadence or remediation portfolio rather than only operating an established one.
  • Experience supporting SOX or securities-reporting obligations in a publicly traded company.
  • Experience integrating audit and risk commitments into delivery tooling already used by Technology teams.
  • Experience in a distributed franchise retail hospitality or other high-transaction environment.
  • Experience working within a fractional outsourced or matrixed security leadership model.
Benefits:

Details regarding benefits will be provided during the hiring process.


Required Skills:

GRCSOXPCI DSS