Senior GRC Officer

Posted Yesterday
Be an Early Applicant
Lincoln, NE, USA
Hybrid
Senior level
Software
The Role
Own and manage U.S. governance, risk, and compliance workstreams across FedRAMP, CMMC, SOC 2, ISO 27001, TX-RAMP, and CJIS. Lead documentation, evidence collection, audits, risk assessments, vulnerability remediation, policy governance, vendor risk, and continuous monitoring. Coordinate with assessors, technical teams, control owners, and business stakeholders while tracking remediation and reporting risks. The role requires hands-on compliance leadership, strong NIST SP 800-53 knowledge, and independent management of multiple concurrent workstreams.
Summary Generated by Built In
Description

Penlink is a technology company bringing clarity to complex data for people who need it now. We partner with law enforcement agencies across the United States, offering a software solution to manage data and aid investigators solving crimes. It sounds like a lot of data and analytics, but really, it’s about improving the world and keeping safe the places we call home. 

We focus on creating products that positively impact our communities and being "in the mission" and less about the laidback culture and amazing benefits – even though we offer those too. With our get it done attitude and focused mission we are growing at an unprecedented rate and are therefore seeking a Senior GRC Officer to join our global Security and Compliance team. This role will independently manage substantial portions of Penlink's U.S. governance, risk, and compliance program, initially as our sole dedicated U.S.-based GRC professional while remaining fully integrated into the global Security and Compliance team. You'll personally drive the work rather than operate solely in an oversight capacity, taking hands-on, day-to-day ownership of assigned FedRAMP, CMMC, and other compliance workstreams — coordinating with technical teams, auditors, and business stakeholders from planning through evidence collection, assessment, remediation, and ongoing monitoring. 

YOUR RESPONSIBILITIES 

  • Independently manage assigned governance and compliance workstreams across FedRAMP, CMMC Level 2, SOC 2 Type 2, ISO 27001, TX-RAMP Level 2, and CJIS, including full FedRAMP workstreams from readiness through Agency ATO. 
  • Lead development and quality review of core compliance documentation (SSP, POA&M, control narratives, policies, procedures, and readiness artifacts) and serve as the primary day-to-day contact for 3PAO/C3PAO assessors, consultants, and control owners. 
  • Coordinate implementation and validation of NIST SP 800-53 and CMMC security requirements across engineering, cloud, IT, and product teams; build and maintain organized evidence repositories and continuous monitoring processes. 
  • Own risk management, vendor risk assessment, policy governance, access review, and exception management, including leading the Cloud Vulnerability Task Force. 
  • Plan and support external audits, assessments, and certification programs, and prepare responses to customer security questionnaires, RFIs/RFPs, and regulatory inquiries. 
  • Prioritize multiple concurrent workstreams, track remediation progress, identify blockers, escalate risks, and provide clear status reporting to management and stakeholders.  
  • Conduct internal compliance assessments and gap analyses, recommending and validating remediation actions. 
  • Serve as a trusted security and compliance point of review, providing guidance and risk-based approval recommendations for business, technology, and operational processes to ensure security requirements, risks, and control expectations are considered before implementation. 
Requirements

YOUR COMPETENCIES & EXPERIENCE 

  • 5+ years of hands-on experience in governance, risk, compliance, or information security within a SaaS, cloud, technology, or regulated environment. 
  • Direct practical experience supporting or managing substantial FedRAMP workstreams (SSP development, POA&M management, control implementation, evidence collection, assessment preparation, and remediation tracking). 
  • Strong working knowledge of NIST SP 800-53 security controls and the ability to interpret requirements for both technical and business stakeholders. 
  • Proven ability to independently manage compliance, audit, or certification workstreams with limited day-to-day supervision, including conducting risk assessments and internal compliance gap analyses. 
  • Experience coordinating with external assessors, auditors, consultants, control owners, and senior business stakeholders. 
  • Strong experience developing, maintaining, and quality-reviewing compliance documentation, policies, procedures, and evidence repositories. 
  • Experience managing multiple concurrent workstreams, prioritizing competing requirements, identifying blockers, escalating risks, and providing clear status reporting to stakeholders. 
  • Strong written and verbal communication skills, including the ability to explain complex security and compliance requirements clearly to both technical and non-technical audiences. 
  • A proactive, hands-on, and delivery-focused working style, with demonstrated ability to identify required next steps, take ownership, follow through on commitments, and maintain momentum without continuous direction. 
  • Ability to work effectively as part of a global team while initially operating as the sole dedicated GRC professional based in the United States. 
  • Experience coordinating vulnerability remediation activities, including prioritization, assignment, tracking, escalation, and validation of remediation evidence.  
  • U.S. citizenship required. 
  • Experience with CMMC Level 2, SOC 2 Type 2, ISO 27001, TX-RAMP, or CJIS frameworks is nice to have. 
  • Prior security operations or vulnerability management experience, including familiarity with AWS or Azure cloud security controls is preferred. 
  • Experience with GRC platforms, compliance automation tools, and responding to customer security questionnaires or RFIs/RFPs. 
  • Relevant certifications such as CISSP, CISM, CISA, CRISC, CCSP, PMP, CAP, or CMMC-related credentials is preferred but not required 

This position currently follows a hybrid schedule requiring two days per week in our Lincoln, Nebraska office. Onsite requirements may be adjusted based on business needs and company or departmental policy.

Skills Required

  • 5+ years of hands-on experience in governance, risk, compliance, or information security within a SaaS, cloud, technology, or regulated environment
  • Direct practical experience supporting or managing substantial FedRAMP workstreams, including SSP development, POA&M management, control implementation, evidence collection, assessment preparation, and remediation tracking
  • Strong working knowledge of NIST SP 800-53 security controls
  • Ability to independently manage compliance, audit, or certification workstreams with limited supervision
  • Experience conducting risk assessments and internal compliance gap analyses
  • Experience coordinating with external assessors, auditors, consultants, control owners, and senior business stakeholders
  • Experience developing, maintaining, and quality-reviewing compliance documentation, policies, procedures, and evidence repositories
  • Experience managing multiple concurrent workstreams, prioritizing requirements, escalating risks, and reporting status
  • Strong written and verbal communication skills for technical and non-technical audiences
  • Proactive, hands-on, delivery-focused working style with demonstrated ownership and follow-through
  • Ability to work effectively as part of a global team while operating as the sole dedicated U.S.-based GRC professional
  • Experience coordinating vulnerability remediation activities, including prioritization, tracking, escalation, and evidence validation
  • U.S. citizenship
  • Experience with CMMC Level 2, SOC 2 Type 2, ISO 27001, TX-RAMP, or CJIS frameworks
  • Prior security operations or vulnerability management experience
  • Familiarity with AWS or Azure cloud security controls
  • Experience with GRC platforms, compliance automation tools, and customer security questionnaires or RFIs/RFPs
  • Relevant certifications such as CISSP, CISM, CISA, CRISC, CCSP, PMP, CAP, or CMMC-related credentials
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Lincoln, NE

What We Do

For us, it’s more than just showing up to a job; it’s about being part of something big. PenLink is a technology company that brings clarity to complex data for people who need impactful answers now. It is a lot of data and analytics but also so much more-it’s about improving the world and keeping safe the places we call home.

Similar Jobs

Eve Logo Eve

Enterprise Account Executive

Legal Tech • Software • Generative AI
Easy Apply
Remote or Hybrid
United States
180 Employees
300K-310K Annually

Nasuni Logo Nasuni

Operations Manager

Artificial Intelligence • Big Data • Cloud • Security • Software • Cybersecurity • Infrastructure as a Service (IaaS)
Easy Apply
Remote or Hybrid
United States
550 Employees

MongoDB Logo MongoDB

Senior Manager, HR Compliance - Americas

Big Data • Cloud • Software • Database
Easy Apply
Remote or Hybrid
United States
5550 Employees
81K-160K Annually

UL Solutions Logo UL Solutions

Senior Laboratory Technician

Automotive • Professional Services • Software • Consulting • Energy • Chemical • Renewable Energy
Remote or Hybrid
United States
15000 Employees

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account