Senior Information Security Manager – GRC & Risk Register
ASSYST, Inc.
Applying takes a free account: you'll come right back to this job to finish with your profile.
Need a reasonable accommodation to apply or interview? Contact us.
JobMinglr uses automated technology to recommend jobs based on profile information and job preferences. Match Score does not determine eligibility for a position, prevent a user from viewing or applying to a job, or make hiring decisions on behalf of an employer.
Description
ASSYST is seeking a Senior Information Security Manager – GRC & Risk Register to design, build, and operationalize an end-to-end Enterprise Cybersecurity Risk Register for our client in Austin, Texas (Fully Remote role).
This position is ideal for a hands-on risk strategist who has personally architected and implemented enterprise risk frameworks from scratch rather than simply maintaining pre-existing GRC programs.The ideal candidate will drive the end-to-end governance lifecycle, establish clear risk ownership, and lead cross-functional stakeholder engagement across business, technology, and security functions to ensure long-term sustainability and audit readiness.
Key Responsibilities & Deliverables:
- Governance & Workflow Design: Define end-to-end governance workflows covering risk identification/intake, review/validation, risk acceptance/mitigation/transfer, ongoing reassessments, and defined escalation pathways.
- Enterprise Risk Register Framework: Design and deliver a standardized risk register template, data taxonomy, structure, and data definitions.
- Risk Scoring & Prioritization Model: Build and document a custom scoring model featuring defined likelihood and impact scales alongside prioritization logic.
- Risk Governance Model & Decision Authorities: Establish explicit roles and responsibilities for risk owners, reviewers, and governance bodies, packaged into a formal governance model and RACI matrix.
- Stakeholder Facilitation & Alignment: Engage key business, technology, and security leaders through interactive workshops to validate requirements and socialize governance processes.
- Initial Risk Register Population: Support the initial intake and onboarding of risks to deliver a baseline document reflecting the current organizational cybersecurity and technology risk posture.
- Final Documentation & Knowledge Transfer: Deliver a consolidated package of audit-ready standard operating procedures (SOPs) and execute structured knowledge transfer to internal security teams to ensure post-contract sustainability.
Experience Requirements:
- 8+ years of experience with Risk Register Design and Framework development.
- 8+ years designing Risk Scoring Models and Prioritization logic.
- 8+ years establishing Governance Processes, Workflows, and Escalation structures.
- 8+ years leading Stakeholder Engagement, Workshops, and Business Alignment.
- 8+ years creating Audit-Ready Documentation and executing structured Knowledge Transfers.
ASSYST is an Equal Opportunity Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, disability, military status, national origin or any other characteristic protected under federal, state, or applicable local law
Pay for this role
The employer didn't post a pay range for this role. That usually means pay is set in negotiation, which favors whoever arrives with numbers. Check ranges on comparable Senior Information Security Manager – GRC & Risk Register postings in Austin, and analyze any offer before you accept it.
Before you apply, worth reading
How JobMinglr reads this job
Every listing here is scored against your profile before you apply: skills overlap, experience level, location and work arrangement, each weighted and explained. You see the score and the reasons, not just a list. How the matching works.