ASSYST logo

Senior Information Security Manager – GRC & Risk Register

ASSYST

  • Austin, Texas
  • 4 days ago
  • Remote

    Highlights

    The ideal candidate will drive the end-to-end governance lifecycle, establish clear risk ownership, and lead cross-functional stakeholder engagement across business, technology, and security functions to ensure long-term sustainability and audit readiness. Governance & Workflow Design: Define end-to-end governance workflows covering risk identification/intake, review/validation, risk acceptance/mitigation/transfer, ongoing reassessments, and defined escalation pathways.

    Numbers & Facts

    LocationAustin, Texas (
    Remote
    )
    IndustryComputer/IT Services
    Company Size100 to 499 employees
    Year Founded1993
    Websitehttps://www.assyst.net/

    Description

    ASSYST is seeking a Senior Information Security Manager – GRC & Risk Register to design, build, and operationalize an end-to-end Enterprise Cybersecurity Risk Register for our client in Austin, Texas (Fully Remote role). 

    This position is ideal for a hands-on risk strategist who has personally architected and implemented enterprise risk frameworks from scratch rather than simply maintaining pre-existing GRC programs.The ideal candidate will drive the end-to-end governance lifecycle, establish clear risk ownership, and lead cross-functional stakeholder engagement across business, technology, and security functions to ensure long-term sustainability and audit readiness.

    Key Responsibilities & Deliverables:

    • Governance & Workflow Design: Define end-to-end governance workflows covering risk identification/intake, review/validation, risk acceptance/mitigation/transfer, ongoing reassessments, and defined escalation pathways.  
    • Enterprise Risk Register Framework: Design and deliver a standardized risk register template, data taxonomy, structure, and data definitions.  
    • Risk Scoring & Prioritization Model: Build and document a custom scoring model featuring defined likelihood and impact scales alongside prioritization logic.  
    • Risk Governance Model & Decision Authorities: Establish explicit roles and responsibilities for risk owners, reviewers, and governance bodies, packaged into a formal governance model and RACI matrix.  
    • Stakeholder Facilitation & Alignment: Engage key business, technology, and security leaders through interactive workshops to validate requirements and socialize governance processes.  
    • Initial Risk Register Population: Support the initial intake and onboarding of risks to deliver a baseline document reflecting the current organizational cybersecurity and technology risk posture.  
    • Final Documentation & Knowledge Transfer: Deliver a consolidated package of audit-ready standard operating procedures (SOPs) and execute structured knowledge transfer to internal security teams to ensure post-contract sustainability. 

    Experience Requirements:

    • 8+ years of experience with Risk Register Design and Framework development.  
    • 8+ years designing Risk Scoring Models and Prioritization logic.  
    • 8+ years establishing Governance Processes, Workflows, and Escalation structures.  
    • 8+ years leading Stakeholder Engagement, Workshops, and Business Alignment.  
    • 8+ years creating Audit-Ready Documentation and executing structured Knowledge Transfers.


    ASSYST is an Equal Opportunity Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, disability, military status, national origin or any other characteristic protected under federal, state, or applicable local law

    About Company

    ASSYST is an agile, CMMI Level 3 certified firm that excels at simplifying IT and business processes, removing unnecessary redundancy, and delivering targeted information for faster, smarter decisions to improve operations and productivity. We work closely with stakeholders, cross-functional teams, and other technology and services vendors to develop solutions utilizing rigorous adherence to the CMMI-based processes, Agile Framework (Scrum and SAFe), ITSM/ITIL services model, and ISO standards to achieve consistent process improvement. ASSYST represents a balanced approach to providing continuity of service while evoking innovation, fresh ideas, and practices to actualize modernization initiatives. We work collaboratively with customers and partners on human-centered design, leverage emerging technologies, apply innovation to deliver solution outcomes that improve productivity, user experience, and customer delight.

    Our specialties include: Big Data and Analytics, Enterprise Content Management, Information Assurance, Cloud Computing, Knowledge Management, Automation, DoD IT Services, Cybersecurity, Test Engineering, FHIR, HealthIT, Data Science, Azure, Agile, Digital Services, AWS GovCloud, ERP, and SAFe

    Similar Jobs

    See more jobs