Skip to content

Open nowPosted 3 days ago

Director, Cybersecurity GRC

Momentive Software40 open roles

Where
Remote (US Only)
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowDirector, Cybersecurity GRCMomentive Software · Remote (US Only)
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Momentive Software's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.2% of postings close within 7 days. Measured by our own scanner across the market. Momentive Software postings stay open a median of 29 days.

Share of postings closed within
  1. 1.8%1 day
  2. 3.6%3 days
  3. 8.2%7 days
  4. 15.2%14 days
  5. 34.0%30 days
This job: posted 3 days ago

Momentive Software median: 29 days open

The posting

Job Description

POSITION OVERVIEW

The Director, Cybersecurity GRC manages the people, processes, and technology related to Momentive Software's Cybersecurity GRC group — overseeing governance, risk, and compliance activities including client audit support, RFP response, internal IT audit, and contract review. This role carries out GRC activities in alignment with the Firm's business objectives, regulatory requirements, and strategic goals, with a focus on recognized cybersecurity frameworks and contractual compliance.

The Director serves as the process owner for all IS GRC-related projects and activities and assists the CISO in planning, developing, and overseeing the cybersecurity program. The role integrates across Cybersecurity, Information Technology, new business development, the Office of General Counsel, and the professional responsibility function. In addition to ongoing governance and operational oversight, this position supports strategic alignment with the business, cybersecurity outreach, and expert guidance to internal and external stakeholders. As a strategic partner to the business, this role helps Momentive win and retain enterprise clients, support growth and M&A readiness, and position the GRC program as a business enabler — not just a compliance function.

KEY RESPONSIBILITIES

GRC Program Leadership

  • Maintain direct responsibility for all aspects of IS GRC, including governance, risk assessment, compliance, and audit support.
  • Ensure continual improvement of the cybersecurity program through effective application of technology, systems, processes, personnel development, and leadership.
  • Provide cybersecurity services that meet or exceed the Firm's professional, contractual, regulatory, and certification requirements.
  • Manage the Firm's IS GRC people, processes, and technology infrastructure, including creation and review of IS GRC standards, guidelines, and operating procedures.
  • Serve as the business owner for IS GRC toolsets, platforms, and processes.
  • Manage the IS GRC team budget.
  • Consult with Legal regarding acceptable contract terms and conditions related to cybersecurity.

ISMS & System Governance

  • Lead the System Governance Virtual Team, promoting continual ISMS improvement across the Firm.
  • Provide direction on risk assessment requirements and assistance evaluating risk treatment plans.
  • Provide input on the selection and design of IS controls.
  • Provide input on metrics developed to monitor and test the effectiveness of the Firm's IS controls.
  • Define documentation requirements to ensure compliance with ISMS requirements.
  • Advise the team on client contractual requirements and Firm commitments relative to GRC practices.
  • Assist the team in developing systems and processes that ensure ISMS compliance and continual improvement.
  • Maintain the Firm's Cybersecurity Management System (ISMS), including the creation and review of policies, standards, and procedures.
  • Enforce, monitor, and report on compliance with the Firm's ISMS.
  • Partner with the Director, AI Governance to co-develop and align AI policies, assess AI-related risks, and integrate AI governance practices into the ISMS framework.

Cybersecurity Operations & Engineering Integration

  • Work closely with Cybersecurity Operations and Engineering teams to define, develop, and facilitate efficient and effective service delivery.
  • Oversee integrated vendor and other risk assessment activities in coordination with technical teams.
  • Liaise with system and business owners to ensure new platforms comply with Firm cybersecurity requirements.
  • Serve within the Firm's Computer Cybersecurity Incident Response Team (CSIRT).

Compliance & Audit

  • Oversee cybersecurity risk assessments and provide audit mechanisms for the cybersecurity process.
  • Meet published SLAs for the provisioning and support of cybersecurity GRC operations and activities.
  • Provide evidence and expert support for client audits, RFP responses, and regulatory reviews.
  • Track compliance with applicable regulatory schemes and monitor changes in legislation and accreditation standards.

Cybersecurity Awareness & Culture

  • Manage the cybersecurity awareness program, including phishing simulation and constituent outreach initiatives.
  • Initiate, facilitate, and promote activities that foster cybersecurity awareness across the organization.
  • Maintain and contribute to the Firm's cybersecurity-related information repositories.

Leadership & People Management

  • Mentor and lead members of the Cybersecurity GRC group through effective performance reviews, development opportunities, and a culture of performance excellence.
  • Direct reports include TPRM Advisors, who manage third-party risk management activities across the organization; this role carries full people management accountability for that team.
  • Transform executive priorities into operational GRC initiatives with clear vision, support, and expectation-setting.
  • Provide status reports and relevant metrics to the CISO.
  • Serve in a proactive, consultative role to other business units and constituents.
  • Provide exemplary service to internal and external stakeholders, demonstrating empathy, respect, professionalism, and expertise.

Strategic Planning & Roadmap

  • Maintain situational and environmental awareness; implement appropriate tactics and strategies to protect the organization and support roadmap development.
  • Strike an appropriate balance between strategic leadership and operational contribution, using a hands-on approach to solving problems and meeting deliverables.
  • Participate in defining the Firm's DR/BCP practices as required.
  • Provide innovation within the cybersecurity realm.

SKILLS & EXPERIENCE

Required

  • 10-12+ years of experience in cybersecurity, with 3-5 years in a leadership or program management role.
  • Thorough knowledge of professional management practices including supervisory techniques, leadership principles, and employment practices.
  • Excellent verbal and written communication skills, including public speaking and the ability to convey complex cybersecurity concepts to non-technical stakeholders.
  • Ability to think and communicate strategically about the role of cybersecurity in a global organization.
  • Ability to quickly assess an organization's capability-maturity level and apply that knowledge to RFPs, audits, contract reviews, and internal operations.
  • Proficiency in at least one major EGRC/ITGRC platform (e.g., ServiceNow GRC, Archer, OneTrust, LogicGate).
  • Comprehensive understanding of major cybersecurity frameworks: NIST CSF, CIS Controls, SOC2T2, and COBIT.
  • Familiarity with common regulatory schemes including GDPR, PCI-DSS, GLBA, FISMA, HIPAA, and ITAR.
  • Advanced understanding of technical controls, how they address risk, and how they map to framework and regulatory requirements.
  • Broad understanding of TCP/IP, DNS, common network services, and foundational infrastructure concepts.
  • Knowledge of server, workstation, and Active Directory technologies as they relate to cybersecurity controls.
  • Familiarity with common cybersecurity monitoring technologies: SIEM, IDS, log management, and vulnerability assessment.
  • Ability to gather and analyze facts, define problems, draw conclusions, and recommend solutions.
  • Ability to maintain objectivity and composure under pressure.
  • Ability to set priorities independently given broad executive requirements.
  • Demonstrated flexibility in response to the ever-changing priorities of a service provider organization.
  • Rigorous and disciplined approach to operational oversight.

Preferred

  • One or more relevant certifications required or preferred: CISSP, CISM, or CRISC. ISO 27001 Lead Implementer or Lead Auditor is a plus.

About Us

Momentive Software amplifies the impact of over 20,000 purpose-driven organizations in over 30 countries, with over $11 billion raised and 55 million members served to date. Mission-driven nonprofits and associations rely on Momentive’s cloud-based software and services to address their most pressing challenges – from engaging their communities to simplifying operations and growing revenue. Designed to help organizations connect more, manage more, and ultimately expect more, Momentive's solutions are built with reliability at the core and strategically focus on fundraising, learning, events, careers, volunteering, accounting, and association management. Momentive partners with organizations that believe "good enough" is never enough – so they can bring on better outcomes for everyone they serve. Learn more at momentivesoftware.com.

Why Work Here?

At Momentive Software, we’re a team of passionate problem-solvers, innovators, and volunteers who believe in using technology to make a real difference. We dream big, support each other, and take pride in creating solutions that help our customers drive meaningful change. If you’re looking for a place where your work matters and your ideas are valued, you’ll find it here.

Medical, Dental & Vision Benefits

401(k) Savings Plan with Company Match

Flexible Planned Paid Time Off

Generous Sick Leave

Inclusive & Welcoming Environment

Purpose-Driven Culture

Work-Life Balance

Commitment to Community Involvement

Employer-Paid Parental Leave

Employer-Paid Short-Term Disability

Remote Work Flexibility

Momentive Software actively embraces diversity and equal opportunity in a meaningful way. We are committed to building a team that represents a variety of backgrounds, perspectives, and skills. The more inclusive we are, the better our work will be, which is why we do not discriminate based on race, color, religion, marital status, age, national origin, ancestry, physical or mental disability, medical condition, pregnancy, genetic information, gender, sexual orientation, gender identity or expression, veteran status, or any other status protected under federal, state, or local law.

All persons hired will be required to verify identity, minimum age of 18, eligibility to work in the United States (without sponsorship), and to complete the required employment eligibility verification form upon hire.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Momentive Software's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Momentive Software's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Momentive Software's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.