GRC Lead

Posted Yesterday
Be an Early Applicant
Houston, TX, USA
In-Office
Mid level
Industrial
The Role
Lead and mature the organization's governance, risk, and compliance program, including CMMC, GDPR, audits, policy governance, control implementation, third-party vendor risk, privacy assessments, remediation, and executive reporting. Partner with Legal, Privacy, Procurement, IT, Information Security, and business stakeholders while serving as the primary contact for auditors, assessors, vendors, customers, and internal teams. Mentor GRC personnel and drive cross-functional compliance initiatives.
Summary Generated by Built In
Position Summary

TIC Solutions are seeking an experienced, strategic, and hands-on GRC Lead to lead the organization’s governance, risk, and compliance program. This role will own and mature key compliance, risk-management, policy-governance, audit, and third-party vendor management processes, while partnering across business units and executive leadership.The GRC Lead will manage compliance initiatives including CMMC, GDPR, and other applicable regulatory, contractual, and customer assurance requirements. The ideal candidate combines strong knowledge of security and privacy frameworks with practical program-management, communication, and leadership skills.Position Details:

  • Monday-Friday, full time position
  • Hybrid (Defined as 4 days a week in office)
  • Office location is Houston, TX (Galleria) 
 Responsibilities

• Lead and mature the organization’s GRC program, including CMMC, GDPR, and other applicable regulatory, contractual, and customer requirements.• Translate requirements into controls, policies, procedures, compliance roadmaps, and evidence-collection processes.• Coordinate internal and external audits, assessments, certifications, customer questionnaires, remediation plans, and compliance reporting.• Build and manage a third-party vendor-risk program, including vendor due diligence, risk assessments, security and privacy reviews, ongoing monitoring, and remediation tracking.• Own the lifecycle of security, privacy, and compliance policies, including review, approval, publication, employee acknowledgment, training, and exception management.• Develop executive dashboards and reports covering compliance posture, audit readiness, control effectiveness, vendor risk, and remediation progress.• Partner with Legal, Privacy, Procurement, IT, Information Security, and business stakeholders to integrate GRC requirements into organizational processes.• Support related programs such as security awareness, business continuity, incident-response governance, data protection, and customer security reviews.• Lead or mentor GRC personnel and serve as the primary contact for auditors, assessors, vendors, customers, and internal stakeholders.

Requirements

• Professional certifications such as CISA, CRISC, CISSP, CISM, ISO 27001 Lead Implementer or Lead Auditor, CDPSE, CIPM, CIPP/US, CIPP/E, or similar.• Experience supporting CMMC assessments or implementing controls aligned with NIST SP 800-171.• Experience with privacy-impact assessments, data-protection impact assessments, or GDPR compliance programs.• Familiarity with GRC, audit-management, vendor-risk-management, and workflow tools.• Experience in a regulated industry, government contracting environment, SaaS organization, or other security-sensitive business environment.• Experience leading or mentoring GRC analysts or cross-functional working groups.• Bachelor’s degree in cybersecurity, information systems, business, risk management, law, or a related field; equivalent relevant experience considered.• Three years of experience in governance, risk, compliance, information security, audit, privacy, or third-party risk management.• Demonstrated experience leading compliance programs, audits, risk assessments, or control implementation efforts.• Working knowledge of CMMC, GDPR, and common security or privacy frameworks such as NIST CSF, NIST SP 800-171, NIST SP 800-53, ISO 27001, SOC 2, CIS Controls, PCI DSS, HIPAA, or similar standards as applicable.• Experience designing or operating a third-party risk-management program.• Experience managing policies, control documentation, audit evidence, and remediation activities.• Strong project-management skills, including the ability to prioritize competing compliance initiatives and drive cross-functional accountability.• Exceptional written, verbal, and stakeholder-management skills.• Ability to communicate risk and compliance requirements effectively to both technical and non-technical audiences.• High degree of integrity, judgment, discretion, and attention to detail.

Company Overview

At TIC Solutions, we do work that matters. As a leading provider of critical asset integrity and engineering solutions, we help keep essential industries operating safely, reliably, and efficiently across North America and beyond. From infrastructure and energy to industrials and renewables, our work supports the communities where we live and work every day.


With more than 11,000 employees across 200+ locations, TIC Solutions combines global scale with local expertise, creating opportunities for employees to build meaningful careers while making a real impact. Our teams are driven by safety, innovation, collaboration, and technical excellence, and we are committed to investing in our people through growth opportunities, hands-on experience, and a strong culture of support and accountability.


Whether you are in the field, in operations, or supporting the business behind the scenes, you will be part of a team focused on solving complex challenges and delivering high-quality solutions for our customers.


Skills Required

  • Professional certification such as CISA, CRISC, CISSP, CISM, ISO 27001 Lead Implementer or Lead Auditor, CDPSE, CIPM, CIPP/US, CIPP/E, or similar
  • Experience supporting CMMC assessments or implementing controls aligned with NIST SP 800-171
  • Experience with privacy-impact assessments, data-protection impact assessments, or GDPR compliance programs
  • Familiarity with GRC, audit-management, vendor-risk-management, and workflow tools
  • Experience in a regulated industry, government contracting environment, SaaS organization, or other security-sensitive business environment
  • Experience leading or mentoring GRC analysts or cross-functional working groups
  • Bachelor's degree in cybersecurity, information systems, business, risk management, law, or a related field; equivalent relevant experience considered
  • Three years of experience in governance, risk, compliance, information security, audit, privacy, or third-party risk management
  • Experience leading compliance programs, audits, risk assessments, or control implementation efforts
  • Working knowledge of CMMC, GDPR, and common security or privacy frameworks such as NIST CSF, NIST SP 800-171, NIST SP 800-53, ISO 27001, SOC 2, CIS Controls, PCI DSS, HIPAA, or similar standards
  • Experience designing or operating a third-party risk-management program
  • Experience managing policies, control documentation, audit evidence, and remediation activities
  • Strong project-management skills and ability to drive cross-functional accountability
  • Exceptional written, verbal, and stakeholder-management skills
  • Ability to communicate risk and compliance requirements to technical and non-technical audiences
  • High degree of integrity, judgment, discretion, and attention to detail

Acuren Inspection, Inc. Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Acuren Inspection, Inc. and has not been reviewed or approved by Acuren Inspection, Inc..

  • Career-Linked Recognition & Rewards Feedback suggests specialized certifications (e.g., API, advanced UT/CWI) materially lift hourly totals and open access to higher-rate assignments. Certain inspector roles also show strong posted ranges and overtime-driven earnings during busy periods.
  • Fair & Transparent Compensation Pay is considered accurate and on time in some offices, with competitive rates reported on certain teams when work is steady. Feedback suggests payroll and rate consistency are stronger where assignments are stable.
  • Leave & Time Off Breadth PTO and holidays are described as standard and covering the basics. Feedback suggests the number of holidays is good in some contexts, aligning to a conventional leave setup.

Acuren Inspection, Inc. Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Sherwood Park
3,658 Employees

What We Do

Since its inception in 1974, Acuren has been a trusted, single source provider of technology-enabled asset protection solutions used to evaluate the structural integrity of critical energy, industrial and public infrastructures. Committed to delivering a Higher Level of Reliability, Acuren provides an unrivaled spectrum of capabilities, including inspection, traditional and advanced NDE/NDT, failure analysis, rope access, materials engineering, reliability engineering and condition based monitoring services. Our work is critical to the integrity and safety of industrial firms, including petroleum refinery, pipeline, power generation, wind, pulp & paper, pharmaceutical, aerospace and automotive industries. Acuren employs more than 4,000 dedicated professionals, dispatched from more than 90 locations across the continent, supporting the mechanical integrity and inspection programs of the world’s largest industrial segments. We are the only N285 certified NDT company in Canada which allows us to perform nuclear scopes of work directly as an EPC rather than subcontracting to another EPC firm. Acuren is a market leader. Our formula for success is straightforward: be capable locally, with certified and well-equipped personnel supported by trained, experienced leaders. Local competence is further supported by a corporate commitment to exceptional service, with subject-matter experts, management systems, and best-available technology to assure that the efforts provided locally also represent best practices globally. Continuing to build on a strong heritage of safety, quality and professionalism, Acuren strives to maintain incident free work environments, pursues advanced technical developments, and supports reliability programs that are valued by clients and employees. We strive to demonstrate that we have an opportunity to earn our customer’s business every day and that we understand the need to deliver more value in the future.

Similar Jobs

Integrity Marketing Group, LLC Logo Integrity Marketing Group, LLC

Senior GRC Analyst, GRC Technology Lead

Insurance • Professional Services • Software • Financial Services
In-Office
Dallas, TX, USA
29757 Employees
In-Office
Dallas, TX, USA
170 Employees

Ultra Clean Technology Logo Ultra Clean Technology

Lead GRC Analyst (IT/Security)

Semiconductor • Industrial • Manufacturing
In-Office
Manor, TX, USA
2611 Employees

Similar Companies Hiring

WorkWhile Thumbnail
Artificial Intelligence • HR Tech • Information Technology • Machine Learning • Software • App development • Industrial
San Francisco, CA
100 Employees
Arch Systems Inc. Thumbnail
Software • Manufacturing • Machine Learning • Internet of Things • Industrial • Artificial Intelligence • Analytics
US
85 Employees
Amalgamated Sugar Thumbnail
Food • Greentech • Agriculture • Industrial • Manufacturing
Boise, Idaho
768 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account