Haystack
← Back to Jobs
Operations & Project Management
PR

W2 12+ GRC/Risk & Compliance Project Manager

ProhiresNew York, NY🇺🇸United StatesPosted 28 Aug 2026

Quick Overview

Seniority
Mid Senior
Work mode
On Site
Location
New York, NY, United States
Posted
19 hours ago
AgileStakeholder ManagementWaterfall

Job Description

GRC/Risk & Compliance Project Manager

Location: New York

Experience: 12+

Day 1 onsite

 

Responsibilities:

  • Lead the development and implementation of GRC frameworks and policies to ensure compliance with relevant regulations and standards.
  • Conduct risk assessments to identify vulnerabilities and threats to information security, and develop strategies to mitigate these risks.
  • Collaborate with cross-functional teams to integrate risk management practices into business processes and decision-making.
  • Monitor and report on compliance status, risk exposure, and the effectiveness of risk management strategies to senior management.
  • Facilitate training and awareness programs to promote a culture of compliance and risk management across the organization.
  • Stay updated on industry trends, regulatory changes, and best practices in GRC and information security.
  • Manage relationships with external auditors and regulatory bodies to ensure compliance and address any findings or recommendations.
  • Develop and maintain documentation related to risk management processes, compliance activities, and audit trails.

Job Role Overview

  • Title options: Risk Program Manager, Business Risk & Controls Manager, Operational Risk Program Officer
  • Department: Enterprise Risk Management, Compliance, or First/Second Line of Defense Business Unit Control
  • Core Goal: Align business execution with bank risk appetite and regulatory standards

Key Responsibilities

  • Project & Program Management of significant Change Initiatives i.e. SS&A, Compass, BVA, etc.
  • Roadmap Management, Dependency Management, Cross Product Management, Status Reporting and Release Coordination
  • Program execution: Drive cross-functional risk and control projects from design to implementation.
  • Control testing: Validate that operational and financial controls are designed well and work effectively.
  • Issue remediation: Track self-identified audit issues, corrective actions, and overdue milestones.
  • Risk reporting: Build dashboards, key risk indicators (KRIs), and executive committee presentations.
  • Stakeholder management: Partner with business line leaders, legal, audit, and external examiners

Mandatory Skills:

  • Strong knowledge of Risk Management principles, particularly in Information Security.
  • Proficiency in GRC tools and frameworks, including ISO 27001, NIST, and COBIT.
  • Experience in conducting risk assessments and developing risk mitigation strategies.
  • Excellent analytical and problem-solving skills, with the ability to interpret complex data and make informed decisions.
  • Strong communication and interpersonal skills, capable of engaging with stakeholders at all levels.

Preferred Skills:

  • Familiarity with data privacy regulations such as GDPR and CCPA.
  • Experience in project management methodologies (e.g., Agile, Waterfall).
  • Certifications in Risk Management or Information Security (e.g., CRISC, CISM, CISSP).
  • Knowledge of security technologies and practices, including firewalls, intrusion detection systems, and encryption.

Qualifications:

  • Bachelor's degree in Information Technology, Cybersecurity, Business Administration, or a related field.
  • Demonstrated expertise in GRC, Risk Management, and Information Security.
  • Proven track record of managing compliance projects and initiatives.
 

Similar jobs