Manager, Governance, Risk & Compliance
ACM Global Laboratories
Manager, Governance, Risk & Compliance at ACM Global Laboratories is a full time role based in Remote · United States (remote). The listing states pay of $115k–$140k. It was published on 5 August 2026 and was open at last check.
| Role | Manager, Governance, Risk & Compliance |
|---|---|
| Company | ACM Global Laboratories |
| Location | Remote · United States (remote) |
| Employment type | Full Time |
| Pay (as listed) | $115k–$140k |
| Published | 5 August 2026 |
| Status | Open at last check |
Job Title:Governance Risk & Compliance Manager
Department:Information Security
Location:Remote, United States
Schedule:Days, Monday - Friday
SUMMARY
The Governance, Risk & Compliance [GRC] Manager at ACM Global Laboratories translates strategic direction into actionable workflows, coordinates cross-functional teams, supports evidence lifecycle management, maps frameworks to control implementation, leads readiness activities, and ensures all ACM GRC processes operate smoothly and efficiently.
RESPONSIBILITIES
- Leads the GRC program activities and a team of professionals related to third-party risk, security internal audit, security compliance, and ISMS program management.
- Develop, document, and implement internal policies and procedures to ensure compliance with industry standards and legal requirements.
- Facilitate regular risk assessments against security frameworks such as SOC 2, ISO 27001, and PCI-DSS, maintain a risk register, and collaborate on mitigation strategies for identified threats. Manage CAPAs for non-compliance.
- Define specific, assignable actions to mitigate the identified risks or exploit the opportunities.
- Evaluate how to embed the planned actions directly into daily operational processes.
- Manage security responses to client questions and questionnaires, including RFPs, RFIs, annual risk reviews, and ad-hoc communication requests.
- Manage and update business continuity and disaster recovery documentation, including BIAs, plan revisions, team rosters, and dependencies. Plan, coordinate, and document annual exercises, such as tests, tabletops, and other exercises.
- Build and manage a security metrics (KPI’s) program.
- Develop relationships with cross-functional teams, understanding their needs in relation to security standards, to drive risk-informed decision-making and build a culture of compliance.
- Provide expert guidance and support in navigating complex regulatory environments in relation to the management of alignment to ISO-27001 and other applicable security frameworks.
- Stay updated on applicable industry trends and regulations to ensure ISMS compliance.
- Monitor and analyze GRC processes and systems, making recommendations for improvement.
- Document risk reduction plan. Annually, document “Opportunities” (potential positive improvements like adopting some technology for improved efficiency).
- Other duties as assigned.
REQUIRED QUALIFICATIONS
- Minimum of 5 years of experience leading Governance, Risk, and Compliance (GRC) programs.
- Proficiency in ISO 27001
PREFERRED QUALIFICATIONS
- GRC certifications (e.g. CGRC, CRISC, etc)
- A bachelor’s degree in IT, cybersecurity, business, or law is preferred, or strong demonstrable background in GRC Management.
- Previous experience in GRC, risk management, or internal audit, often with a mid-level leadership background.
- Proficiency in frameworks like SOC2, NIST CSF, and HIPAA regulations.
- Strong ability to analyze risk data and translate complex regulations into actionable controls.
- Excellent communication skills to interact with stakeholders and lead team efforts.
- Experience with 3rd party/vendor risk management processes.
- Experience in working with sales teams to complete Requests for Proposals and security questionnaires.
- Understanding of GRC processes such as policy management, risk assessment, and IT audits.
- Exceptional verbal and written communication skills.
EDUCATION:
LICENSES / CERTIFICATIONS:
PHYSICAL REQUIREMENTS:
For disease specific care programs refer to the program specific requirements of the department for further specifications on experience and educational expectations, including continuing education requirements.
Any physical requirements reported by a prospective employee and/or employee’s physician or delegate will be considered for accommodations.
PAY RANGE:
CITY:
POSTAL CODE:
The listed base pay range is a good faith representation of current potential base pay for a successful full time applicant. It may be modified in the future and eligible for additional pay components. Pay is determined by factors including experience, relevant qualifications, specialty, internal equity, location, and contracts.
Rochester Regional Health is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, creed, religion, sex (including pregnancy, childbirth, and related medical conditions), sexual orientation, gender identity or expression, national origin, age, disability, predisposing genetic characteristics, marital or familial status, military or veteran status, citizenship or immigration status, or any other characteristic protected by federal, state, or local law.
Originally posted on Himalayas
Create your free OnJob profile to apply — we'll take you to ACM Global Laboratories's application after sign-up. · Posted 5 Aug 2026.
Manager, Governance, Risk & Compliance at ACM Global Laboratories — questions answered
What does the Manager, Governance, Risk & Compliance role at ACM Global Laboratories pay?
The Manager, Governance, Risk & Compliance at ACM Global Laboratories listing states pay of $115k–$140k for the Remote · United States (remote) position. That figure is taken directly from the employer's own posting as published, not estimated or averaged from other roles.
Is the Manager, Governance, Risk & Compliance role at ACM Global Laboratories remote?
Yes — ACM Global Laboratories advertises this Manager, Governance, Risk & Compliance role as remote, tied to Remote · United States, and it is listed as full time work. Remote terms come from the employer's own posting, so confirm the expected working hours, timezone and any on-site days with ACM Global Laboratories before you apply.
Is the Manager, Governance, Risk & Compliance role at ACM Global Laboratories still open?
The Manager, Governance, Risk & Compliance posting at ACM Global Laboratories was open at OnJob's last check of the employer's careers page, having been published on 5 August 2026. OnJob re-checks source listings on each build and marks a role closed once it disappears, but listings can close without notice, so the employer's own page is the final word.
How do you apply for the Manager, Governance, Risk & Compliance role at ACM Global Laboratories?
Apply to the Manager, Governance, Risk & Compliance at ACM Global Laboratories role through OnJob with a free profile: OnJob scores your fit against the listing, shows the skills lowering that score, and submits an ATS-ready profile to ACM Global Laboratories's own application page. Creating a profile is free and needs no card.
Explore more on OnJob
Hiring for a role like this?
Post a job on OnJob and reach AI-matched candidates.