Skip to content

Open nowPosted 12 hours ago

Director; Governance, Risk & Compliance

Cosm33 open roles

Where
Los Angeles, CA, USA
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowDirector; Governance, Risk & ComplianceCosm · Los Angeles, CA, USA
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Cosm's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.1% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.7%1 day
  2. 3.6%3 days
  3. 8.1%7 days
  4. 15.0%14 days
  5. 34.0%30 days
This job: posted 12 hours ago

The posting

Summary:               Cosm is seeking a seasoned Governance, Risk, and Compliance (GRC) professional to help lead and evolve our enterprise-wide security governance and risk management programs. Reporting to the Information Security Officer (ISO), you will define and operationalize GRC frameworks that ensure alignment with industry standards such as NIST CSF 2.0, SOX ITGC, and the Trusted Partner Network (TPN) content-security standard. You will operate and mature our enterprise risk register, oversee regulatory compliance, provide independent assurance over the controls that protect Cosm's platforms and creative content, and drive the policy development that strengthens our security posture and supports business growth, including our path toward IPO readiness. As an early member of a growing InfoSec team, you will have the opportunity to shape the GRC function from the ground up, with room to grow as the team and program mature. This role is expected to build and lead the GRC function as the program scales, including hiring and developing the team that supports it. The ideal candidate brings a strong background in IT controls, audit readiness, and cross-functional collaboration, along with a passion for fostering a culture of accountability, security, and continuous improvement. Responsibilities:  Risk Management

Operate and mature the enterprise cyber risk register, from initial population to a sustained program, including the inherent and residual scoring methodology Conduct business impact analyses to identify critical assets, systems, and processes and their tolerance for disruption, and use the results to inform asset criticality and risk prioritization Facilitate the executive risk review cycle: surface residual risks that exceed appetite, coordinate treatment versus acceptance decisions, and track risk owners and treatment plans to closure Maintain the risk appetite framework so that scoring, escalation thresholds, and exceeds-appetite triggers stay aligned to what the Audit Committee has approved, and support its annual review

Independent Assurance and Control Verification

Provide independent verification of control design and operating effectiveness for controls implemented and operated by Engineering, Security Engineering, and IT, maintaining separation between those who build and operate controls and those who assure them Audit technical standards authored by Security Engineering, such as firewall and hardening baselines, against policy and framework requirements Own the control evidence program: ensure each control has an assigned owner and defined evidence, that collection happens on the required cadence, and that evidence remains current and audit ready Monitor evidence coverage and freshness across the control catalog, and drive remediation of missing, stale, or failing evidence ahead of audits Track control deficiencies to remediation and report residual exposure to leadership

Compliance and Audit Readiness

Track and ensure compliance with NIST CSF 2.0, SOX ITGC, TPN, and other applicable regulatory and contractual frameworks Plan and execute internal audits and reviews, and perform and document control testing Support external assessments and lead customer and partner security due diligence engagements

Third-Party and Vendor Risk

Own the third-party security risk program end to end: intake, security review, risk rating, and ongoing monitoring across the vendor lifecycle Collect and review vendor and datacenter security attestations, tracking coverage and expiration Partner with Legal and Procurement to embed security requirements into vendor onboarding and contracts

Policy and Control Framework

Author and maintain IT and security policies, and drive them through review, ratification, distribution, and tracked acknowledgment where they bind individuals, including contractors before access is granted Review technical standards authored by Security Engineering for policy alignment Manage the control catalog that maps Cosm's controls to its frameworks, and coordinate control ownership across the organization Monitor and report on the coverage and health of the control framework as risks, business needs, and regulatory requirements evolve

Training and Awareness

Own the security awareness and role-based training program end to end: content, cadence, delivery, phishing simulation, and completion tracking Deliver role-specific training for administrators, privileged users, and developers Promote a culture of security and compliance across the organization

Metrics, Reporting, and Board Governance

Design and maintain the cybersecurity metrics framework: KPIs that show whether controls are achieving their objectives, and KRIs that provide forward-looking risk exposure, each tied to risk appetite rather than activity volume Define and operate the escalation triggers that force an off-cycle report to the Audit Committee, such as a critical vulnerability unremediated beyond its SLA or a control failure in a high-criticality area Produce the quarterly Audit Committee reporting package: maturity movement with rationale, top gaps with owner and remediation date, incidents mapped to previously identified gaps, and resourcing needs tied to closing specific gaps Present risk and compliance reporting to senior leadership, the Cybersecurity Executive Steering Committee, and the Audit Committee Communicate risk and compliance issues clearly to both technical and non-technical stakeholders

Incident Support

Provide risk, control, and impact context to the decision-makers assessing whether an incident is material Own the control and maturity findings arising from post-incident review

Team and Function Development

Build and lead the GRC function as the program scales, including hiring and developing the team that supports it

Experience:

8 to 12 years in IT governance, risk, and compliance, including leading GRC programs or major initiatives in enterprise environments Hands-on experience operating and maturing risk registers, running risk assessments, gap analyses, and business impact analyses, and driving treatment decisions to closure Independent control testing experience supporting SOX ITGC or pre-IPO audit readiness Experience planning and executing internal audits Experience owning a third-party risk program, including review of vendor security attestations Experience running continuous-compliance and evidence collection in a GRC platform. We use Vanta Expertise authoring IT and security policies that meet regulatory requirements, and running them through review, ratification, and acknowledgment Track record producing board or audit-committee-level reporting on maturity, risk posture, and remediation, and designing metrics tied to risk appetite Experience building training and awareness programs Deep working knowledge of NIST CSF 2.0 and 800-53; familiarity with SOC 2, ISO 27001, COBIT, and CIS Controls Ability to explain complex risk to non-technical senior stakeholders and influence decisions Bachelor's degree in a related field, or equivalent experience

The annualized salary range for this position in California is $210,000 to $225,000. The base pay offered will factor in internal equity and may also vary depending on the candidate's geographic region, job-related knowledge, skills, and relevant experience, among other factors

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Cosm's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Cosm's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Cosm's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.