The posting
Summary: Cosm is seeking a seasoned Governance, Risk, and Compliance (GRC) professional to help lead and evolve our enterprise-wide security governance and risk management programs. Reporting to the Information Security Officer (ISO), you will define and operationalize GRC frameworks that ensure alignment with industry standards such as NIST CSF 2.0, SOX ITGC, and the Trusted Partner Network (TPN) content-security standard. You will operate and mature our enterprise risk register, oversee regulatory compliance, provide independent assurance over the controls that protect Cosm's platforms and creative content, and drive the policy development that strengthens our security posture and supports business growth, including our path toward IPO readiness. As an early member of a growing InfoSec team, you will have the opportunity to shape the GRC function from the ground up, with room to grow as the team and program mature. This role is expected to build and lead the GRC function as the program scales, including hiring and developing the team that supports it. The ideal candidate brings a strong background in IT controls, audit readiness, and cross-functional collaboration, along with a passion for fostering a culture of accountability, security, and continuous improvement. Responsibilities: Risk Management
Operate and mature the enterprise cyber risk register, from initial population to a sustained program, including the inherent and residual scoring methodology Conduct business impact analyses to identify critical assets, systems, and processes and their tolerance for disruption, and use the results to inform asset criticality and risk prioritization Facilitate the executive risk review cycle: surface residual risks that exceed appetite, coordinate treatment versus acceptance decisions, and track risk owners and treatment plans to closure Maintain the risk appetite framework so that scoring, escalation thresholds, and exceeds-appetite triggers stay aligned to what the Audit Committee has approved, and support its annual review
Independent Assurance and Control Verification
Provide independent verification of control design and operating effectiveness for controls implemented and operated by Engineering, Security Engineering, and IT, maintaining separation between those who build and operate controls and those who assure them Audit technical standards authored by Security Engineering, such as firewall and hardening baselines, against policy and framework requirements Own the control evidence program: ensure each control has an assigned owner and defined evidence, that collection happens on the required cadence, and that evidence remains current and audit ready Monitor evidence coverage and freshness across the control catalog, and drive remediation of missing, stale, or failing evidence ahead of audits Track control deficiencies to remediation and report residual exposure to leadership
Compliance and Audit Readiness
Track and ensure compliance with NIST CSF 2.0, SOX ITGC, TPN, and other applicable regulatory and contractual frameworks Plan and execute internal audits and reviews, and perform and document control testing Support external assessments and lead customer and partner security due diligence engagements
Third-Party and Vendor Risk
Own the third-party security risk program end to end: intake, security review, risk rating, and ongoing monitoring across the vendor lifecycle Collect and review vendor and datacenter security attestations, tracking coverage and expiration Partner with Legal and Procurement to embed security requirements into vendor onboarding and contracts
Policy and Control Framework
Author and maintain IT and security policies, and drive them through review, ratification, distribution, and tracked acknowledgment where they bind individuals, including contractors before access is granted Review technical standards authored by Security Engineering for policy alignment Manage the control catalog that maps Cosm's controls to its frameworks, and coordinate control ownership across the organization Monitor and report on the coverage and health of the control framework as risks, business needs, and regulatory requirements evolve
Training and Awareness
Own the security awareness and role-based training program end to end: content, cadence, delivery, phishing simulation, and completion tracking Deliver role-specific training for administrators, privileged users, and developers Promote a culture of security and compliance across the organization
Metrics, Reporting, and Board Governance
Design and maintain the cybersecurity metrics framework: KPIs that show whether controls are achieving their objectives, and KRIs that provide forward-looking risk exposure, each tied to risk appetite rather than activity volume Define and operate the escalation triggers that force an off-cycle report to the Audit Committee, such as a critical vulnerability unremediated beyond its SLA or a control failure in a high-criticality area Produce the quarterly Audit Committee reporting package: maturity movement with rationale, top gaps with owner and remediation date, incidents mapped to previously identified gaps, and resourcing needs tied to closing specific gaps Present risk and compliance reporting to senior leadership, the Cybersecurity Executive Steering Committee, and the Audit Committee Communicate risk and compliance issues clearly to both technical and non-technical stakeholders
Incident Support
Provide risk, control, and impact context to the decision-makers assessing whether an incident is material Own the control and maturity findings arising from post-incident review
Team and Function Development
Build and lead the GRC function as the program scales, including hiring and developing the team that supports it
Experience:
8 to 12 years in IT governance, risk, and compliance, including leading GRC programs or major initiatives in enterprise environments Hands-on experience operating and maturing risk registers, running risk assessments, gap analyses, and business impact analyses, and driving treatment decisions to closure Independent control testing experience supporting SOX ITGC or pre-IPO audit readiness Experience planning and executing internal audits Experience owning a third-party risk program, including review of vendor security attestations Experience running continuous-compliance and evidence collection in a GRC platform. We use Vanta Expertise authoring IT and security policies that meet regulatory requirements, and running them through review, ratification, and acknowledgment Track record producing board or audit-committee-level reporting on maturity, risk posture, and remediation, and designing metrics tied to risk appetite Experience building training and awareness programs Deep working knowledge of NIST CSF 2.0 and 800-53; familiarity with SOC 2, ISO 27001, COBIT, and CIS Controls Ability to explain complex risk to non-technical senior stakeholders and influence decisions Bachelor's degree in a related field, or equivalent experience
The annualized salary range for this position in California is $210,000 to $225,000. The base pay offered will factor in internal equity and may also vary depending on the candidate's geographic region, job-related knowledge, skills, and relevant experience, among other factors



