Charlotte, NC

Salary
Posted
Jul 23, 2026
Location
Charlotte, NC
Last confirmed open
Jul 25, 2026

What this job asks for AI summary

This is a senior leadership role heading the Cybersecurity Governance, Risk & Compliance function at an insurance wholesale brokerage. The position owns a broad GRC program covering cyber and IT risk, regulatory compliance (including CFIUS and NYDFS obligations), third-party vendor risk, AI governance, policy and standards, and disaster recovery governance. It suits an experienced GRC leader with a background in heavily regulated industries who is comfortable working hands-on while engaging senior stakeholders across the enterprise.

Senior level · Full-time

Must have (3)
GRC platforms, AuditBoard, Archer, Servicenow Irm, Metricstream, Logicgate or OnetrustNISTregulatory compliance
Nice to have (3)
NYDFSCFIUSCISM, CISSP, Crisc, Cisa or Gslc

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

What won't set you apart
NIST40%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (8)

The job title is 'Head of Cybersecurity GRC,' which carries people-management and program-ownership signals (leading a hybrid team, managing stakeholders, owning a function). This puts the role on the boundary between 15-1212 Information Security Analysts and 11-3021 Computer and Information Systems Managers; it was classified as 15-1212 because the primary day-to-day work described is hands-on GRC analysis, risk assessment, and compliance — not headcount/budget management of a large org.

No work location is specified in the posting beyond 'United States of America' shift reference; CBSA and state fields are left blank.

No total years of experience figure is stated — the JD lists qualitative experience areas only, so the overall years minimum is not set.

GRC platform experience (AuditBoard/Optro, Archer, ServiceNow IRM/GRC, MetricStream, LogicGate, OneTrust, or similar) is listed under the Requirements section and is treated as a hard gate; the specific tools are interchangeable alternatives.

NYDFS experience is called out as 'strongly preferred' and CFIUS as 'highly valuable' in a dedicated Preferred Attributes section — both are marked preferred accordingly.

Certifications (CISM, CISSP, CRISC, CISA, GSLC) are explicitly stated as preferred in the posting.

No compensation figures are provided in the posting.

Ignored 3 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): IT risk management, third-party risk management, AI governance.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗