Compliance & Risk Officer
Employment Type: Full Time
Location: Santa Monica, CA (On-site)
Salary: $90,000 - $110,000 Annually
Reports To: COO or CEO (preferred for independence)
Works Closely With: CISO, Legal, HR, IT
Benefits: Full Comprehensive Health Insurance
PTO: Flexible
Position Summary
The Compliance & Risk Officer is responsible for enterprise risk management, regulatory compliance oversight, and internal control validation. This role ensures adherence to CMMC, ISO 27001, NIST 800-171, and other regulatory frameworks, while maintaining independence from operational security functions.
Key Responsibilities
Governance & Risk
- Maintain enterprise risk register
- Conduct annual and quarterly risk assessments
- Perform risk analysis (likelihood × impact scoring)
- Present risk posture to executive leadership
Compliance Management
- Own CMMC/ISO 27001 certification lifecycle
- Maintain control mappings and documentation
- Conduct internal control testing
- Coordinate external audits and assessments
- Track corrective action plans
Policy & Documentation
- Develop and maintain policies and procedures
- Ensure documentation meets auditor standards
- Oversee third-party/vendor risk assessments
Oversight
- Validate security control effectiveness (not implement)
- Ensure separation of duties in security functions
- Identify compliance gaps and remediation plans
Qualifications
- 5+ years in risk management, compliance, or audit
- Experience with CMMC Level 2 and/or ISO 27001
- Familiarity with NIST 800-171 / 800-53
- Strong documentation and audit experience
- CRISC, CISA, ISO Lead Auditor, or similar preferred
Success Metrics
- Zero major audit findings
- Timely remediation of identified risks
- Accurate and current risk register
- Successful certification maintenance
Requirements
- Must be commuting distance of Santa Monica, CA.
- Must be comfortable workin on site.
- Must be a US Citizen or valid green card holder.