CHAOS Industries logo

Governance, Risk & Compliance Analyst

CHAOS Industries

HybridEl Segundo, CAsenior$120k–$150kPosted 11h ago

Visa & sponsorship

  • The posting offers relocation assistance.

Job description

  • Own and mature the CHAOS Industries cybersecurity GRC program by establishing governance structure, policies, standards, expectations, and accountability across CHAOS businesses

  • You’ll report to the IT/Cybersecurity Program Director and work daily with IT, Cybersecurity, Physical Security, and Manufacturing – teams with different priorities and vocabulary; therefore, you’ll spend real time translating broad requirements into controls people adopt

  • Build and manage cybersecurity risk processes, including risk registers, findings, vulnerabilities, remediation plans, ownership, escalation, and business acceptance

  • If you enjoy designing frameworks that fit the organization rather than forcing the organization to fit a template, and you want direct input into how a defense company governs risk, this is the seat

  • Own risk assessments across several departments and maintain the centralized risk register

  • Design and maintain a unified, original control framework tailored to CHAOS Industries’ operating environment, including a security-by-design approach to systems development and defined: Maximum Tolerable Downtime (MTD), Recovery Point Objective (RPO), and Recovery Time Objective (RTO) for critical systems

  • Write and maintain policy that goes beyond minimum mandatory compliance, building genuine security maturity rather than satisfying the floor of any one requirement

  • Manage GRC tooling and related workflows to support risk assessments, control monitoring, and reporting

  • Prepare for, coordinate, and help run third-party and certification audits, including evidence collection, gap assessments, and auditor liaison

  • Act as the connective tissue between different department to then develop security and compliance requirements for partner teams and drive them to execution

  • Report regularly to the Program Director and executive stakeholders on risk posture, audit status, and program maturity

  • Onsite presence required 4 days per week

  • Travel: up to 25%, primarily to support Manufacturing and Physical Security control validation across company sites

  • Physical demands: occasional access to manufacturing floor environments, including required PPE and periods of standing or walking during facility walkthroughs

  • Support customer, vendor, supplier, and subcontractor cybersecurity risk management, including questionnaires, contract reviews, security expectations, and customer-facing services

  • Coordinate cybersecurity audits, assessments, evidence requests, customer reviews, and remediation tracking in partnership with Legal, Compliance, commercial teams, IT, and business leaders

Benefits

  • Generous pre-IPO stock option grants, relocation assistance + (coming soon!) annual bonuses

  • Free daily lunch, ‘No meeting Fridays’, unlimited PTO (for exempt employees), casual dress code

  • Life, FSA, HSA, 401k (+ Company match), and more

  • Medical, dental and vision benefits will be 100% paid for by the company- Minimum of 5 years hands-on GRC or compliance experience combined with prior experience in a DoD environment or military service

  • Familiarity with OT/ICS security concepts

  • Deep knowledge of NIST CSF, NIST RMF, the ISO/IEC 27000 series, UK Cyber Essentials, CMMC/NIST 800-171, NIST 800-53

  • Has directly supported a third-party or certification audit from evidence collection through closure

  • Exposure to widely recognized governance, risk, and compliance frameworks spanning security, privacy, and quality management domains

  • Bachelor’s degree or equivalent experience in computer science, cybersecurity, information security, Information Technology, Information Assurance, or a related field, or equivalent practical experience

  • Has performed or directly supported a formal risk assessment (identification, scoring, and treatment) using a defined methodology

  • Can apply recognized governance, risk, and compliance frameworks well enough to design real, working controls tailored to a specific organization, not just describe them generically

  • Experience selecting, implementing, or administering GRC tooling and workflows

  • Experience supporting third-party audits in a cloud-centric environment

  • Has built or materially contributed to a risk register, control framework, or compliance program, not only operated within one already established elsewhere

  • Has written policy or procedure documentation that a non-security audience could follow and act on