GRC Lead

Voyager — Remote - United States

Apply on employer website
Voyager is an innovative space, defense, and national security technology company committed to advancing and delivering transformative, mission-critical solutions. We tackle the most complex challenges to unlock new frontiers for human progress, fortify national security, and protect critical assets to lead in the race for technological and operational superiority from ground to space. ; ; Forge the Future: Join Voyager Technologies ; ; The future belongs to those who build it. At Voyager Technologies, we’re building technologies that protect lives, expand frontiers and prepare us for what’s next. And we’re doing that with people who are wired to solve, build, adapt and lead. These roles are not for the faint of heart.  ; ; You’ll help lay the foundation for humanity's future. Join a culture where innovation thrives, curiosity is rewarded, and impact is real. We’re a company of doers, thinkers and builders, united by purpose and grounded in reality. ; ; If you want to put your skills to work where the stakes are real and the mission is bigger than any one person, forge the future with Voyager. ; ; The GRC Lead for cybersecurity is responsible for owning and maturing our Governance, Risk, and Compliance program, including CMMC. ; The position reports to the Senior Director of Cybersecurity and is part of the IT department. This role is remote. ; In this role, the essential functions are: Own the end-to-end GRC program, including governance frameworks, risk management processes, and compliance activities across applicable regulatory and contractual requirements (CMMC, NIST 800-171, FAR/DFARS, and others as applicable) Lead CMMC readiness efforts — including scoping, gap assessments, POA&M development, and coordination with the C3PAO through assessment Manage the control framework — mapping controls to applicable standards, tracking control ownership, and driving remediation of gaps Build and maintain the evidence library; define evidence collection processes and ensure artifacts are accurate, complete, and audit-ready Plan and support internal and external audits, assessments, and third-party reviews; serve as the primary point of contact for auditors Conduct and maintain the organizational risk register; facilitate risk assessments and track risk treatment decisions to closure Partner with IT, engineering, legal, and operations to embed compliance requirements into processes, tools, and projects Track the regulatory and compliance land..




Looking for a job?

Visit Careersaas to find millions of new and unfilled roles, including thousands of remote and hybrid positions.