
Governance, Risk & Compliance Analyst
CHAOS Industries
Visa & sponsorship
- The posting offers relocation assistance.
Job description
-
Own and mature the CHAOS Industries cybersecurity GRC program by establishing governance structure, policies, standards, expectations, and accountability across CHAOS businesses
-
You’ll report to the IT/Cybersecurity Program Director and work daily with IT, Cybersecurity, Physical Security, and Manufacturing – teams with different priorities and vocabulary; therefore, you’ll spend real time translating broad requirements into controls people adopt
-
Build and manage cybersecurity risk processes, including risk registers, findings, vulnerabilities, remediation plans, ownership, escalation, and business acceptance
-
If you enjoy designing frameworks that fit the organization rather than forcing the organization to fit a template, and you want direct input into how a defense company governs risk, this is the seat
-
Own risk assessments across several departments and maintain the centralized risk register
-
Design and maintain a unified, original control framework tailored to CHAOS Industries’ operating environment, including a security-by-design approach to systems development and defined: Maximum Tolerable Downtime (MTD), Recovery Point Objective (RPO), and Recovery Time Objective (RTO) for critical systems
-
Write and maintain policy that goes beyond minimum mandatory compliance, building genuine security maturity rather than satisfying the floor of any one requirement
-
Manage GRC tooling and related workflows to support risk assessments, control monitoring, and reporting
-
Prepare for, coordinate, and help run third-party and certification audits, including evidence collection, gap assessments, and auditor liaison
-
Act as the connective tissue between different department to then develop security and compliance requirements for partner teams and drive them to execution
-
Report regularly to the Program Director and executive stakeholders on risk posture, audit status, and program maturity
-
Onsite presence required 4 days per week
-
Travel: up to 25%, primarily to support Manufacturing and Physical Security control validation across company sites
-
Physical demands: occasional access to manufacturing floor environments, including required PPE and periods of standing or walking during facility walkthroughs
-
Support customer, vendor, supplier, and subcontractor cybersecurity risk management, including questionnaires, contract reviews, security expectations, and customer-facing services
-
Coordinate cybersecurity audits, assessments, evidence requests, customer reviews, and remediation tracking in partnership with Legal, Compliance, commercial teams, IT, and business leaders
Benefits
-
Generous pre-IPO stock option grants, relocation assistance + (coming soon!) annual bonuses
-
Free daily lunch, ‘No meeting Fridays’, unlimited PTO (for exempt employees), casual dress code
-
Life, FSA, HSA, 401k (+ Company match), and more
-
Medical, dental and vision benefits will be 100% paid for by the company- Minimum of 5 years hands-on GRC or compliance experience combined with prior experience in a DoD environment or military service
-
Familiarity with OT/ICS security concepts
-
Deep knowledge of NIST CSF, NIST RMF, the ISO/IEC 27000 series, UK Cyber Essentials, CMMC/NIST 800-171, NIST 800-53
-
Has directly supported a third-party or certification audit from evidence collection through closure
-
Exposure to widely recognized governance, risk, and compliance frameworks spanning security, privacy, and quality management domains
-
Bachelor’s degree or equivalent experience in computer science, cybersecurity, information security, Information Technology, Information Assurance, or a related field, or equivalent practical experience
-
Has performed or directly supported a formal risk assessment (identification, scoring, and treatment) using a defined methodology
-
Can apply recognized governance, risk, and compliance frameworks well enough to design real, working controls tailored to a specific organization, not just describe them generically
-
Experience selecting, implementing, or administering GRC tooling and workflows
-
Experience supporting third-party audits in a cloud-centric environment
-
Has built or materially contributed to a risk register, control framework, or compliance program, not only operated within one already established elsewhere
-
Has written policy or procedure documentation that a non-security audience could follow and act on