Governance, Risk & Compliance (GRC) Manager

Posted Yesterday
Be an Early Applicant
Torrance, CA, USA
In-Office
Senior level
Aerospace • Hardware • Software • Database • Defense • Industrial
Northwood is a modern space infrastructure company focused on the ground segment.
The Role
Lead Northwood's GRC program for CMMC Level 2, FedRAMP, SOC 2 Type II, and ITAR. Maintain SSPs/POA&Ms, manage third-party assessments, run enterprise risk management, develop policy and evidence frameworks, own CUI/ITAR controls and training, and serve as primary compliance liaison to government customers and assessors. Work closely with security engineering, network, and product teams to operationalize controls and ensure year-round audit readiness.
Summary Generated by Built In

Northwood is a modern space infrastructure company bringing the benefits of space to the masses through advanced communications technology. We are building a global network of phased array ground stations that enable real-time, reliable communication for satellite missions such as national security, global connectivity, and disaster response. With a vertically integrated approach, Northwood designs, builds, and rapidly deploys scalable systems that power the next generation of space missions. If you like solving complex challenges and seeing your work deployed around the world with real impact, Northwood is the place to do it.

Role Overview

As Governance, Risk & Compliance (GRC) Lead, you will own Northwood's compliance program across CMMC, FedRAMP, SOC 2, and ITAR — building the policies, processes, and evidence frameworks that enable the company to operate as a trusted dual-use space communications provider. This is a senior individual contributor role for a practitioner who combines deep regulatory knowledge with the technical fluency to work directly with security engineering, network, and product teams to translate compliance requirements into operational reality.

You will serve as the primary point of contact for government customers, third-party assessors, and internal stakeholders on all matters related to compliance posture, risk management, and audit readiness. You will work across Northwood's full security stack — spanning on-premises infrastructure, AWS GovCloud, GCC, and corporate systems — to ensure controls are implemented, documented, and defensible. This role reports to the Head of Security.

Responsibilities

Compliance Program Ownership

  • Own Northwood's compliance program across CMMC Level 2, FedRAMP, SOC 2 Type II, and ITAR, including control mapping, gap assessment, remediation tracking, and audit preparation.

  • Maintain Northwood's System Security Plan (SSP), Plan of Action and Milestones (POA&M), and associated compliance documentation in alignment with NIST 800-171 and applicable frameworks.

  • Coordinate and manage third-party assessments, including C3PAO engagements for CMMC, FedRAMP 3PAO assessments, and SOC 2 audits, serving as the primary assessor liaison.

  • Monitor the regulatory environment for changes to CMMC, FedRAMP, DFARS, and ITAR requirements and assess impact on Northwood's compliance posture.

Risk Management

  • Build and maintain Northwood's enterprise risk management program, including risk register development, risk scoring methodology, and executive-level risk reporting.

  • Conduct and facilitate periodic risk assessments across security domains, incorporating input from security engineering, network, product, and operations teams.

  • Identify, track, and drive remediation of compliance gaps and security control deficiencies, working directly with technical teams to ensure timely closure.

  • Develop and maintain risk acceptance processes, exception management workflows, and compensating control documentation.

Policy & Control Framework

  • Develop, maintain, and enforce Northwood's security policy library, including acceptable use, access control, incident response, data classification, and CUI handling policies.

  • Map Northwood's control environment across overlapping frameworks — NIST 800-171, NIST 800-53, SOC 2 Trust Services Criteria, and FedRAMP — to reduce duplicative compliance effort and maximize control reuse.

  • Define and maintain the control evidence collection program, ensuring audit artifacts are continuously gathered, organized, and accessible for assessment cycles.

  • Partner with the Security Engineering Lead, Security Operations Lead, and Product Security Lead to validate that technical controls are implemented in alignment with documented policies and compliance requirements.

ITAR & CUI Program Management

  • Own Northwood's CUI program, including data classification guidance, CUI handling procedures, marking standards, and employee training.

  • Maintain ITAR compliance program documentation, including technology control plans, export authorization tracking, and coordination with Northwood's legal counsel on regulatory obligations.

  • Ensure network segmentation, access controls, and data handling practices across Northwood's infrastructure appropriately enforce CUI and ITAR boundaries in coordination with security and network engineering teams.

Audit Readiness & Stakeholder Engagement

  • Serve as the primary compliance point of contact for government customers, prime contractors, and subcontractors, including responding to security questionnaires, flow-down requirement reviews, and customer audit requests.

  • Build and maintain audit readiness posture year-round, ensuring evidence collection, control testing, and documentation currency do not become point-in-time exercises.

  • Brief executive leadership and the Head of Security on compliance status, upcoming assessment milestones, and material risk items requiring business-level decisions.

  • Develop and deliver security awareness and compliance training programs for Northwood employees, with targeted content for personnel handling CUI or operating in ITAR-controlled environments.

Basic Qualifications

  • 5+ years in a governance, risk, and compliance role with demonstrated ownership of enterprise compliance programs in a regulated environment.

  • Deep working knowledge of CMMC Level 2 and NIST SP 800-171, including SSP development, POA&M management, and C3PAO assessment preparation.

  • Experience managing FedRAMP authorization processes, including boundary definition, control implementation documentation, and 3PAO coordination.

  • Hands-on experience with SOC 2 Type II audits, including control mapping, evidence collection, and auditor engagement.

  • Familiarity with ITAR compliance requirements, including technology control plans, export authorization processes, and CUI program management.

  • Demonstrated ability to translate technical security controls into compliance documentation and audit evidence across multiple overlapping frameworks.

  • Experience conducting risk assessments and maintaining enterprise risk registers with executive-level reporting.

  • Strong technical fluency — this role works directly with security engineering and infrastructure teams and requires the ability to evaluate technical control implementations against compliance requirements.

  • Ability to obtain and maintain a TS/SCI clearance.

  • U.S. citizenship or status as a lawful permanent resident required to conform with ITAR export regulations.

Preferred Qualifications

  • Active TS clearance or higher.

  • Experience working within the Defense Industrial Base, including prime or subcontractor compliance environments with DFARS flow-down obligations.

  • Familiarity with eMASS or similar government assessment and authorization management tools.

  • Experience with GRC platforms for control tracking, evidence management, and audit workflow automation.

  • Knowledge of Northwood's core infrastructure environment, including AWS GovCloud, Microsoft GCC, and on-premises security tooling, and how these map to FedRAMP and CMMC control boundaries.

  • Experience developing and delivering security awareness and CUI handling training programs.

  • Familiarity with DFARS 252.204-7012 incident reporting obligations and coordination with DIBCAC or DCSA.

  • Professional certifications such as CISSP, CISM, CISA, CCSK, or equivalent GRC credentials.

  • CMMC Registered Practitioner (RP) or Certified Professional (CP) designation.

Additional Requirements:

  • This position requires successfully obtaining and maintaining a Top Secret Security Clearance as a condition of employment. While the clearance may not be immediately necessary upon hire, we encourage you to initiate the application process promptly upon accepting this offer. Your ability to secure the necessary clearance is essential for fulfilling key responsibilities of the role. Should you be unable to obtain it, Northwood Space reserves the right to modify or terminate your employment to align with optional needs.

Additional Information:

If you need a reasonable accommodation as part of your application for employment or interviews with us, please let us know.

To conform to U.S. Government space technology export regulations, including the International Traffic in Arms Regulations (ITAR) you must be a U.S. citizen, lawful permanent resident of the U.S., protected individual as defined by 8 U.S.C. 1324b(a)(3), or eligible to obtain the required authorizations from the U.S. Department of State.

Northwood Space is an Equal Opportunity Employer; employment with Northwood Space is governed on the basis of merit, competence and qualifications and will not be influenced in any manner by race, color, religion, gender, national origin/ethnicity, veteran status, disability status, age, sexual orientation, gender identity, marital status, mental or physical disability or any other legally protected status.

Skills Required

  • 5+ years in a governance, risk, and compliance role owning enterprise compliance programs in a regulated environment
  • Deep working knowledge of CMMC Level 2 and NIST SP 800-171 including SSP development and POA&M management
  • Experience managing FedRAMP authorization processes, including boundary definition and 3PAO coordination
  • Hands-on experience with SOC 2 Type II audits including control mapping and evidence collection
  • Familiarity with ITAR compliance requirements, technology control plans, export authorization, and CUI program management
  • Ability to translate technical security controls into compliance documentation and audit evidence across frameworks
  • Experience conducting risk assessments and maintaining enterprise risk registers with executive-level reporting
  • Strong technical fluency to evaluate technical control implementations with security and infrastructure teams
  • Ability to obtain and maintain a TS/SCI clearance (Top Secret/SCI eligibility required)
  • U.S. citizenship or lawful permanent resident status required to conform with ITAR export regulations
  • Active TS clearance or higher
  • Experience working within the Defense Industrial Base and DFARS flow-down obligations
  • Familiarity with eMASS or similar government assessment and authorization management tools
  • Experience with GRC platforms for control tracking, evidence management, and audit workflow automation
  • Knowledge of AWS GovCloud, Microsoft GCC, and on-premises security tooling as they map to FedRAMP and CMMC boundaries
  • Experience developing and delivering security awareness and CUI handling training programs
  • Familiarity with DFARS 252.204-7012 incident reporting and coordination with DIBCAC or DCSA
  • Professional certifications such as CISSP, CISM, CISA, CCSK, or equivalent
  • CMMC Registered Practitioner (RP) or Certified Professional (CP) designation

Northwood Space Corp Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Northwood Space Corp and has not been reviewed or approved by Northwood Space Corp.

  • Healthcare Strength Job postings consistently cite “comprehensive” or “platinum” medical, dental, and vision coverage, with some roles indicating employer-covered premiums at little to no cost. Several listings explicitly reference fully covered plans.
  • Equity Value & Accessibility Multiple listings consistently mention equity or stock options alongside base pay, with some noting potential performance bonuses. Equity is presented as a standard component across many roles.
  • Leave & Time Off Breadth Listings cite flexible or unlimited PTO, and some specify a defined paid holiday calendar (e.g., about 10 holidays). Time-off provisions are repeatedly referenced across postings.

Northwood Space Corp Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Torrance, CA
40 Employees

What We Do

The space segment has become critical infrastructure. It powers everything from GPS and climate monitoring to missile warning and global broadband. But the ground segment hasn’t kept up. Most ground networks today were designed for science missions, not for the scale, urgency, or diversity of today’s space economy. At Northwood, we’re building a global, software-defined ground network from the ground up — designed to scale as fast as the missions it supports.

Why Work With Us

Just like cloud infrastructure transformed software development, we believe shared ground infrastructure will transform space operations. We’re making it possible for any operator to move space-based data quickly, securely, and reliably back to Earth.

Similar Jobs

Sigma Computing Logo Sigma Computing

Governance, Risk & Compliance (GRC) Manager

Cloud • Information Technology • Analytics
In-Office
San Francisco, CA, USA
329 Employees
190K-215K Annually

TigerConnect Logo TigerConnect

Governance, Risk, and Compliance (GRC) Manager

Cloud • Enterprise Web • Healthtech • Mobile • Software
Remote or Hybrid
2 Locations
329 Employees
120K-140K Annually

Toast Logo Toast

Senior Analyst, Product & Pricing (Finance & Strategy)

Cloud • Fintech • Food • Information Technology • Software • Hospitality
In-Office
San Francisco, CA, USA
5000 Employees
102K-163K Annually

Toast Logo Toast

Data Analyst

Cloud • Fintech • Food • Information Technology • Software • Hospitality
In-Office
San Francisco, CA, USA
5000 Employees
125K-200K Annually

Similar Companies Hiring

Outpost Space Thumbnail
Aerospace • Defense
US
24 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account