Skip to main content
Omnissa

Senior Risk Manager - Information Security

RemoteUnited States only
Published
Role
Security
Experience
Senior
Employment
Full-time
$175k–$220k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Senior risk manager to run and mature enterprise risk management for a mid-to-large tech company. Needs 8+ years in risk/GRC (3+ yrs managing people), deep knowledge of COSO/ISO/NIST-style frameworks, and experience with GRC tooling. Remote role; US-style benefits listed (401k) suggest US hiring/compensation considerations.

Core skills

GRCenterprise risk management

Required skills

risk managementCOSO ERMISO 31000NIST RMFGRC platformsServiceNow GRCArcherOneTrustLogicGateKRIsrisk assessmentsrisk registersrisk taxonomypolicy managementvendor risk managementJiraAtlassian Cloud

Optional skills

CRISCCISMCGEITMBAMS Risk ManagementClaudeAnecdotesProcess Unity

What you'll do

  • Own and operate the enterprise risk management framework, including risk appetite statements, risk registers, and risk reporting cadences.
  • Lead periodic risk assessments across business functions, identifying emerging threats and evaluating the effectiveness of existing controls.
  • Maintain and evolve risk taxonomy, scoring methodologies, and heat maps aligned to industry best practices (e.g., COSO ERM, ISO 31000).
  • Drive integration of risk management into strategic planning, product development, and change management processes.
  • Prepare and present risk reports for senior leadership, the Board, and audit/risk committees, translating complex risk data into actionable insights.
  • Establish and track key risk indicators (KRIs) and ensure timely escalation of critical risk events.
  • Maintain risk management policies, standards, and procedures; drive policy review cycles and updates.
  • Serve as a trusted advisor to business unit leaders on risk-related matters, helping embed a risk-aware culture.
  • Collaborate with IT Security, Legal, Privacy, and Internal Audit teams on integrated risk and control activities.
  • Support third-party and vendor risk management activities in coordination with Procurement and IT.
  • Lead, mentor, and develop a team of risk analysts and specialists within the GRC function.
  • Drive process automation and tooling improvements to enhance risk program efficiency and scalability.
  • Coordinate risk management contributions to internal and external audits, regulatory examinations, and compliance assessments.
  • Monitor the evolving regulatory landscape and assess implications for the organization's risk profile.

What they require

  • 8+ years of experience in risk management, GRC, or a closely related field
  • 3+ years in a people management role
  • Deep knowledge of risk management frameworks (COSO ERM, ISO 31000, NIST RMF, or equivalent)
  • Demonstrated experience operating an enterprise risk program in a mid-to-large organization
  • Strong analytical and communication skills; able to present risk information clearly to technical and non-technical audiences, including executives
  • Proven ability to influence and build relationships across organizational levels without direct authority
  • Bachelor’s degree in business, Finance, Information Systems, or a related field
  • Professional certification such as CRISC, CISM, CGEIT, or equivalent
  • Experience in regulated industries (financial services, healthcare, technology)
  • Familiarity with GRC platforms (e.g., ServiceNow GRC, Archer, OneTrust, LogicGate)
  • Master's degree (MBA, MS Risk Management, or related discipline) — listed as an additional qualification

Benefits

  • Employee ownership
  • Health insurance
  • 401k with matching contributions
  • Disability insurance
  • Paid-time off
  • Growth opportunities
  • Participation in a corporate bonus program

formerly EUC division of VMware, sold by Broadcom to KKR

Enterprise SoftwareStartupomnissa.com/
$175k–$220k/yr