Senior Governance, Risk & Compliance (GRC) Officer
Apex Systems is seeking a Senior Governance, Risk & Compliance (GRC) Officer to join a growing Security & Compliance organization. This individual will independently manage critical governance, risk, and compliance initiatives while partnering closely with technical teams, auditors, and business stakeholders. The ideal candidate will possess deep experience supporting regulatory and compliance frameworks, maintaining compliance documentation, coordinating audits, and driving risk management programs in cloud-based or regulated environments.
This is a highly hands-on position requiring ownership of compliance workstreams from planning through assessment, remediation, and continuous monitoring.
Key Responsibilities
- Independently manage governance and compliance workstreams across frameworks including FedRAMP, CMMC Level 2, SOC 2 Type 2, ISO 27001, TX-RAMP Level 2, and CJIS.
- Lead development, maintenance, and quality review of compliance documentation including System Security Plans (SSPs), Plans of Action & Milestones (POA&Ms), policies, procedures, control narratives, and readiness artifacts.
- Serve as a primary point of contact for auditors, assessors, consultants, and internal control owners throughout audit and assessment activities.
- Coordinate implementation and validation of NIST SP 800-53 and CMMC security requirements across engineering, cloud, IT, and product teams.
- Develop and maintain evidence repositories and continuous monitoring programs.
- Manage risk management processes, vendor risk assessments, policy governance activities, access reviews, and exception management.
- Support vulnerability management efforts through prioritization, remediation tracking, escalation, and validation activities.
- Plan and support external audits, assessments, certifications, and compliance initiatives.
- Respond to customer security questionnaires, RFIs, RFPs, and regulatory inquiries.
- Conduct internal compliance assessments and gap analyses, recommending and validating corrective actions.
- Monitor and communicate compliance status, remediation progress, risks, and blockers to leadership and stakeholders.
- Provide risk-based security and compliance guidance for new business, operational, and technology initiatives.
Required Qualifications
- 5+ years of experience in Governance, Risk & Compliance (GRC), Information Security, Risk Management, or related fields.
- Hands-on experience supporting or managing FedRAMP compliance workstreams, including: SSP development, POA&M management, control implementation, evidence collection, assessment preparation, remediation tracking.
- Strong knowledge of NIST SP 800-53 security controls.
- Experience conducting risk assessments, internal audits, and compliance gap analyses.
- Proven ability to independently manage multiple compliance or certification initiatives simultaneously.
- Experience working with auditors, assessors, consultants, and cross-functional stakeholders.
- Strong documentation skills with experience developing policies, procedures, compliance artifacts, and evidence repositories.
- Excellent written and verbal communication skills with the ability to communicate effectively with both technical and non-technical audiences.
- Demonstrated ability to prioritize competing initiatives and drive projects to completion with minimal supervision.
- Experience coordinating vulnerability remediation activities and tracking corrective actions.
- U.S. Citizenship required.
Preferred Qualifications
- Experience supporting CMMC Level 2, SOC 2 Type 2, ISO 27001, TX-RAMP, and/or CJIS compliance frameworks.
- Prior experience in security operations, vulnerability management, or cloud security.
- Familiarity with AWS and/or Azure security controls.
- Experience utilizing GRC platforms and compliance automation tools.
- Experience responding to customer security questionnaires, RFIs, and RFPs.
- Professional certifications such as: CISSP, CISM, CISA, CRISC, CCSP, PMP, CAP, CMMC-related certifications.
Why Apply?
This opportunity offers the ability to make a significant impact within a growing compliance and security organization while owning key regulatory and risk management initiatives. The role provides exposure to multiple compliance frameworks and the opportunity to work closely with technical, operational, and executive stakeholders in a highly collaborative environment.
Everforth Apex is a world-class IT services company that serves thousands of clients across the globe. When you join Everforth Apex, you become part of a team that values innovation, collaboration, and continuous learning. We offer quality career resources, training, certifications, development opportunities, and a comprehensive benefits package. Our commitment to excellence is reflected in many awards, including ClearlyRateds Best of Staffing in Talent Satisfaction in the United States and Great Place to Work in the United Kingdom and Mexico.