SlipstreamJobsFresh Startup & VC-Backed Jobs

GRC Lead

Voyager Technologies - Remote - Remote - posted 2026-09-29

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 140,000 - 185,000 / annual

Voyager Technologies is a space, defense, and national security technology company seeking a GRC Lead to own and mature the Governance, Risk, and Compliance program, including CMMC. This role reports to the Senior Director of Cybersecurity and is part of the IT department. Key Responsibilities: - Own the end-to-end GRC program, including governance frameworks, risk management processes, and compliance activities across applicable regulatory and contractual requirements (CMMC, NIST 800-171, FAR/DFARS, and others) - Lead CMMC readiness efforts, including scoping, gap assessments, POA&M development, and coordination with the C3PAO through assessment - Manage the control framework by mapping controls to applicable standards, tracking control ownership, and driving remediation of gaps - Build and maintain the evidence library; define evidence collection processes and ensure artifacts are accurate, complete, and audit-ready - Plan and support internal and external audits, assessments, and third-party reviews; serve as the primary point of contact for auditors - Conduct and maintain the organizational risk register; facilitate risk assessments and track risk treatment decisions to closure - Partner with IT, engineering, legal, and operations to embed compliance requirements into processes, tools, and projects - Track the regulatory and compliance landscape for changes relevant to the business and advise leadership accordingly The role requires travel to Voyager facilities, operational sites, and partner locations. Participation in security exercises, incident response, or time-sensitive remediation activities may occasionally be required outside normal business hours. This position requires access to information governed by U.S. export-control laws and may require access to government-controlled systems or data. Requirements: - Bachelor's degree in information security or related field with 8 years of experience in GRC, information security compliance, or related field; OR Master's degree in information security or related field with 6 years of experience - Relevant certification such as CISSP, CISA, CRISC, CISM, or CompTIA Security+ - Direct, hands-on experience with CMMC (Level 2 or Level 3) or NIST SP 800-171 implementation and assessment preparation - Demonstrated ability to manage a control framework—mapping, ownership assignment, evidence collection, and gap remediation - Experience drafting and maintaining information security policies and procedures - Proven track record supporting audits or third-party assessments, including evidence preparation and auditor coordination - Ability to work independently, manage multiple workstreams, and drive cross-functional stakeholders without direct authority - Excellent written and verbal communication skills, including the ability to translate technical compliance requirements for non-technical audiences Preferred Qualifications: - CMMC assessor certification such as CCP, CCA, or LCCA - Prior experience building or maturing a GRC program from an early stage - Background coordinating with C3PAOs or DCSA assessors

Similar roles