×
Register Here to Apply for Jobs or Post Jobs. X

GRC Lead; IT​/OT

Job in Danbury, Fairfield County, Connecticut, 06813, USA
Listing for: Glocomms
Part Time position
Listed on 2026-03-01
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security, IT Business Analyst
Salary/Wage Range or Industry Benchmark: 80000 - 100000 USD Yearly USD 80000.00 100000.00 YEAR
Job Description & How to Apply Below
Position: GRC Lead (IT/OT)

Glocomms is partnered with an American energy company dedicated to reliable, clean power and sustainable development to identify a GRC Lead (IT/OT) who will drive governance, risk, and compliance strategies across both IT and operational technology environments. This is a high‑visibility, hybrid role (2-3 days/week onsite in Danbury, CT) supporting secure‑by‑design engineering, regulatory readiness, and enterprise risk management for a highly regulated critical‑infrastructure organization.

Key Responsibilities

As the GRC Lead (IT/OT), you will design, implement, and mature governance programs that strengthen cyber resilience across industrial control systems (ICS), OT networks, and corporate IT environments. You will be responsible for aligning the organization with leading security frameworks (e.g., NIST CSF, IEC 62443) and ensuring ongoing compliance with regulatory, security, and audit requirements.

You will partner closely with engineering, security operations, risk, compliance, and technology leadership to embed governance processes, monitor control effectiveness, and steward audit readiness across the enterprise.

Governance, Frameworks & Policy
  • Lead the development, maintenance, and communication of IT/OT security policies, standards, and operational procedures.
  • Build and mature enterprise control frameworks, including control mapping, compensating controls, and change governance.
  • Implement and maintain RACI/RASIC structures for governance clarity and cross‑functional execution.
  • Drive continuous improvement, KPI tracking, and governance program design across both IT and OT.
Risk Management & Compliance
  • Oversee enterprise risk management, including the risk register, risk acceptance processes, and business‑risk reporting.
  • Conduct control self‑assessments, internal assurance testing, and independent verification of control effectiveness.
  • Identify and manage non‑compliance gaps, develop remediation plans and CAPA actions, and ensure timely closure.
  • Manage and enhance third‑party risk management (TPRM), evaluating vendor security posture and compliance controls.
Audit Readiness & Evidence Management
  • Lead mock audits, audit evidence preparation, and SOX / ITGC / ITAC readiness activities.
  • Maintain and govern evidence repositories, automate evidence collection through GRC platforms, and manage audit evidence packages.
  • Coordinate cross‑functional groups to achieve successful regulatory inspections, external audits, and internal audits.
Technical Integration Across IT & OT
  • Collaborate with engineering teams to embed secure‑by‑design principles, threat modeling, and segmentation governance.
  • Oversee OT asset inventory, network zoning, conduits, and control architecture alignment with IEC 62443.
  • Integrate GRC processes into incident response, root cause analysis, and operational risk reviews.
  • Ensure alignment of technical security standards, control requirements, and engineering processes.
Programs, Tools & Stakeholder Engagement
  • Manage and optimize GRC software platforms, evidence automation workflows, and compliance metrics reporting.
  • Lead security awareness training, role‑based training programs, and cross‑functional education initiatives.
  • Facilitate discussions between technical and non‑technical stakeholders; drive conflict resolution and alignment across teams.
  • Maintain updated regulatory policy interpretations and guide business units through applicability and compliance requirements.
Qualifications
  • 7+ years of experience in GRC, cybersecurity, IT/OT risk, or compliance roles within critical infrastructure or highly regulated industries.
  • Strong understanding of NIST CSF, IEC 62443, IT/OT controls, and regulatory standards.
  • Experience with audit lifecycle management, evidence governance, ITGC/ITAC/SOX, and assurance testing.
  • Technical fluency across IT and OT domains: network segmentation, IC… etc.
  • Demonstrated ability to influence senior stakeholders and lead cross‑functional teams.
  • Experience with GRC platforms, dashboarding, metrics, and workflow automation.

This position is ideal for a technically strong, strategically minded GRC leader who thrives in complex environments and can influence engineering, operations, cybersecurity, and executive stakeholders.

#J-18808-Ljbffr
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)

Job Posting Language
Employment Category
Education (minimum level)
Filters
Education Level
Experience Level (years)
Posted in last:
Salary