Haystack
← Back to Jobs
Remote
Operations & Project Management
UT

Technical Program Manager, GRC

UNICOM TECHNOLOGIES INCUnited States🇺🇸United StatesPosted Sep 17, 2026

Quick Overview

Seniority
Mid Senior
Work mode
Remote
Location
United States
Posted
Yesterday
Jira

Job Description

Title: Technical Program Manager, GRC

Start Date: 09/15/2026

End Date:

# of Openings: 1

Position Type: Contract to Hire

Locations: Louisville,

Additional Details:

6 months CTH

100% Remote (Candidates only from CST & EST zones)



Description:

Summary:

The Technical Program Manager, Governance, Risk and Compliance establishes and runs the program structure that converts cybersecurity governance, risk, audit, and compliance priorities into coordinated delivery tied to strategic outcomes and measurable risk reduction. This role manages intake, maintains integrated roadmaps and delivery cadence, tracks dependencies and remediation commitments, and gives leaders reliable visibility into capacity, progress, risk to plan, tradeoffs, and decisions required.

You will join an evolving GRC control plane. Working closely with the Senior Manager, GRC and accountable control owners across Information Security, Technology, Internal Audit, and the business, you will establish repeatable operating mechanisms and remain accountable for program coordination, delivery transparency, and follow-through without absorbing functional ownership. The Senior Manager, GRC retains accountability for GRC strategy, prioritization, risk decisions, policy, standards, control frameworks, third-party risk oversight, and formal audit or control conclusions. Control owners and GRC practitioners retain responsibility for control execution, testing, and evidence production.

Responsibilities:

  • Establish and operate the GRC program cadence, including working sessions, remediation reviews, leadership reporting, decision forums, and action follow-through.
  • Manage intake and demand for work entering the GRC function, maintain a transparent view of capacity and competing commitments, and prepare prioritization recommendations for decision by the Senior Manager, GRC.
  • Build and maintain integrated plans, milestones, dependencies, decision logs, role definitions, and handoffs so the operating model is repeatable and durable.
  • Build and maintain an integrated GRC program roadmap that connects prioritized risk and compliance outcomes to initiatives, milestones, dependencies, capacity assumptions, and measurable results.
  • Protect functional capacity by identifying unplanned demand, surfacing tradeoffs, and routing prioritization decisions to the accountable leader.
  • Maintain the authoritative remediation and commitment backlog for internal audit observations, compliance obligations, and approved corrective actions.
  • Confirm accountable owners, target dates, dependencies, closure criteria, and escalation paths; challenge stale or unsupported status.
  • Coordinate evidence requests and readiness checkpoints across control owners without creating, testing, or approving the evidence on their behalf.
  • Coordinate schedule inputs for SOX, PCI DSS, regulatory, and disclosure-related cycles as directed by the Senior Manager, GRC.
  • Coordinate remediation reporting and supporting materials for review by the Senior Manager, GRC, who owns formal communication and relationship management with Internal Audit and external auditors.
  • Coordinate commitments across GRC, Identity and Access Management, Cyber Defense and Incident Response, Security Architecture, Infrastructure, application teams, and business process owners.
  • Manage dependencies between security commitments and technology delivery plans, escalating ownership gaps or constraints that put outcomes at risk.
  • Facilitate decision forums, prepare decision records, document accountable owners, and track resulting actions to closure.
  • Maintain clear boundaries between program coordination and functional accountability so GRC leaders and control owners retain their decision and execution responsibilities.
  • Configure and maintain enterprise work-management workflows, fields, queries, and views needed to make status reliable without parallel manual trackers.
  • Produce portfolio reporting that connects GRC priorities, commitments, owners, delivery status, aging, dependencies, capacity, risk to plan, expected risk-reduction outcomes, tradeoffs, and decisions required.
  • Measure and report program outcomes, including cycle time, remediation closure rate, aging, throughput, commitment reliability, capacity constraints, and evidence of risk reduction or improved audit readiness.
  • Track GRC capability maturity against the defined operating model, identify structural or process gaps, and coordinate improvement actions with the Senior Manager, GRC and fractional leadership.
  • Translate complex delivery issues into concise, decision-oriented reporting for senior leaders.

Requirements:

  • Success in this role depends on disciplined coordination, transparent reporting, and the ability to move work across organizational boundaries without positional authority.
  • Partner with the Senior Manager, GRC, who owns enterprise risk governance, policy direction, control frameworks, compliance oversight, third-party risk oversight, and formal assessment conclusions.
  • Partner with the Senior Analyst, GRC and control owners who perform assessments, administer GRC processes, produce evidence, and execute control activities.
  • Make ownership explicit by documenting who decides, who executes, what is due, and where escalation goes.
  • Protect the separation between governance, program coordination, and control execution. Do not author policy, approve risk, render control-effectiveness conclusions, administer OneTrust vendor reviews, or become the default producer of missing evidence.
  • Use established enterprise work-management tooling as the system of record and drive a single, transparent view of commitments rather than creating disconnected trackers.
  • Escalate with evidence and preserve the working relationships needed for sustained cross-functional delivery.

Required Skills:

  • Seven or more years managing technical or cybersecurity programs, including experience in a regulated environment with audit, SOX, PCI DSS, or comparable compliance obligations.
  • Demonstrated ownership of cross-functional programs in which accountable delivery resources report elsewhere in the organization.
  • Hands-on experience configuring and operating an enterprise work-management platform such as Jira or ServiceNow, including workflows, fields, queries, dashboards, and reporting controls.
  • Experience managing remediation, audit, compliance, risk, or control commitments from intake through validated closure.
  • Ability to hold owners accountable, surface tradeoffs, and escalate missed commitments without relying on positional authority.
  • Strong written, visual, and verbal communication skills, including concise executive reporting and decision-oriented facilitation.
  • Working knowledge of recognized cybersecurity and control frameworks such as CIS Controls v8, NIST Cybersecurity Framework, SOX IT general controls, or PCI DSS.
  • Ability to prioritize competing demands and deliver independently in a remote environment.

Preferred Skills:

  • Experience standing up a program operating model, intake process, governance cadence, or remediation portfolio rather than only operating an established one.
  • Experience supporting SOX or securities-reporting obligations in a publicly traded company.
  • Experience integrating audit and risk commitments into delivery tooling already used by Technology teams.
  • Experience in a distributed, franchise, retail, hospitality, or other high-transaction environment.
  • Experience working within a fractional, outsourced, or matrixed security leadership model.

Benefits:

Details regarding benefits will be provided during the hiring process.

Similar jobs