Governance, Risk & Compliance (GRC) Manager

Northwood Space
United States
Workplace: OnsiteFull timeFunction: Legal, Risk & ComplianceExperience: 5+ yearsSkills: ["Communication","Leadership","Problem-solving","Collaboration","Influencing"]

Lead and own the company’s GRC program, including CMMC Level 2, FedRAMP, SOC 2 Type II, and ITAR across on-premises, AWS GovCloud, GCC, and corporate systems. Translate regulatory requirements into actionable controls, collaborate with security, engineering, and product teams, and drive audit readiness and executive reporting.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Northwood Space
Northwood Space
3 months ago

Governance, Risk & Compliance (GRC) Manager

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 3 hours agoStatus: Live

Job Summary

Lead and own the company’s GRC program, including CMMC Level 2, FedRAMP, SOC 2 Type II, and ITAR across on-premises, AWS GovCloud, GCC, and corporate systems. Translate regulatory requirements into actionable controls, collaborate with security, engineering, and product teams, and drive audit readiness and executive reporting.
Location: United States
Workplace: Onsite
Employment Type: Full time
Job Function: Legal, Risk & Compliance
Seniority: Manager level

Key Responsibilities

  • •Own Northwood's compliance program across CMMC Level 2, FedRAMP, SOC 2 Type II, and ITAR, including control mapping, gap assessment, remediation tracking, and audit preparation.
  • •Maintain SSP, POA&M, and compliance documentation aligned with NIST 800-171 and other frameworks.
  • •Coordinate third-party assessments (C3PAO, FedRAMP 3PAO, SOC 2 audits) as primary assessor liaison.
  • •Monitor regulatory changes to CMMC, FedRAMP, DFARS, and ITAR and assess impact on compliance posture.
  • •Build and maintain enterprise risk management program with risk registers and executive reporting.
  • •Conduct risk assessments across security domains with cross-functional input.
  • •Identify and drive remediation of compliance gaps and control deficiencies with technical teams.
  • •Develop risk acceptance processes, exception management, and compensating controls.
  • •Develop and enforce security policy library covering AUP, access control, incident response, data classification, and CUI handling.
  • •Map control environments across NIST 800-171/800-53, SOC 2, FedRAMP to maximize control reuse and reduce duplicative effort.
  • •Define and maintain control evidence collection program for continuous audit readiness.
  • •Collaborate with Security Engineering, Security Operations, and Product Security to align technical controls with policies.
  • •Own ITAR & CUI program management including data classification and employee training.
  • •Maintain ITAR compliance program documentation and ITAR boundary enforcement across infrastructure.
  • •Ensure network segmentation and access controls enforce CUI/ITAR boundaries with security and network teams.
  • •Serve as compliance contact for government customers and contractors, handling security questionnaires and audit requests.
  • •Maintain year-round audit readiness and timely evidence collection.
  • •Brief executives on compliance status and risk items; deliver security awareness and compliance training to staff.

Key Requirements

  • •5+ years in governance, risk, and compliance with enterprise programs in regulated environments
  • •Deep working knowledge of CMMC Level 2 and NIST SP 800-171 including SSP/POA&M and C3PAO prep
  • •Experience managing FedRAMP authorization processes and 3PAO coordination
  • •Hands-on SOC 2 Type II audits, including control mapping and evidence collection
  • •Familiarity with ITAR compliance, including data handling and CUI program management
Experience:5+ yearsSpaceGovernmentDefense
Skills:CommunicationLeadershipProblem-solvingCollaborationInfluencing
Certifications:CISSPCISMCISACCSK
Languages:English
Tech Stack:AWS GovCloudNIST 800-171SOC 2FedRAMPCMMCSSPPOA&MITAR

Eligibility

Nationality:US National
Security Clearance:TS/SCI

Company Brief

Northwood Space
Builds modern, scalable ground infrastructure and phased-array antenna systems to improve satellite-to-Earth communications, providing rapidly deployable ground stations and networking for commercial and government space missions.
Industry: Space Technology
Company Size: Medium (51 to 250 employees)
Growth: Growth Stage Startup
Funding: Series B
Headquarters: Los Angeles, United States
Founded: 2023
Glassdoor
Glassdoor: 3.3
WebsiteLinkedInGlassdoor