Senior Information Security Manager – GRC & Risk Register
ASSYST is seeking a Senior Information Security Manager – GRC & Risk Register to design, build, and operationalize an end-to-end Enterprise Cybersecurity Risk Register for our client in Austin, Texas (Fully Remote role).
This position is ideal for a hands-on risk strategist who has personally architected and implemented enterprise risk frameworks from scratch rather than simply maintaining pre-existing GRC programs.The ideal candidate will drive the end-to-end governance lifecycle, establish clear risk ownership, and lead cross-functional stakeholder engagement across business, technology, and security functions to ensure long-term sustainability and audit readiness.
Key Responsibilities & Deliverables:
- Governance & Workflow Design: Define end-to-end governance workflows covering risk identification/intake, review/validation, risk acceptance/mitigation/transfer, ongoing reassessments, and defined escalation pathways.
- Enterprise Risk Register Framework: Design and deliver a standardized risk register template, data taxonomy, structure, and data definitions.
- Risk Scoring & Prioritization Model: Build and document a custom scoring model featuring defined likelihood and impact scales alongside prioritization logic.
- Risk Governance Model & Decision Authorities: Establish explicit roles and responsibilities for risk owners, reviewers, and governance bodies, packaged into a formal governance model and RACI matrix.
- Stakeholder Facilitation & Alignment: Engage key business, technology, and security leaders through interactive workshops to validate requirements and socialize governance processes.
- Initial Risk Register Population: Support the initial intake and onboarding of risks to deliver a baseline document reflecting the current organizational cybersecurity and technology risk posture.
- Final Documentation & Knowledge Transfer: Deliver a consolidated package of audit-ready standard operating procedures (SOPs) and execute structured knowledge transfer to internal security teams to ensure post-contract sustainability.
Experience Requirements:
- 8+ years of experience with Risk Register Design and Framework development.
- 8+ years designing Risk Scoring Models and Prioritization logic.
- 8+ years establishing Governance Processes, Workflows, and Escalation structures.
- 8+ years leading Stakeholder Engagement, Workshops, and Business Alignment.
- 8+ years creating Audit-Ready Documentation and executing structured Knowledge Transfers.
ASSYST is an Equal Opportunity Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, disability, military status, national origin or any other characteristic protected under federal, state, or applicable local law
Apply for this job
*
indicates a required field

